
Seems that the "Actor" has stuff around from a previous campaign with the CVE-2023-36025 .url shortcut exploits Funny enough it was showing LiteLLM installation (anyone? :D ) https://gist.github.com/N3mes1s/b5b0b96782b9f832819d2db7c6684f84#appendix-b-live-infrastructure--earlier-campaign-analysis https://t.co/bYZSj4FoPC
Post summary
The tweet indicates that an adversary is actively exploiting CVE-2023-36025 using URL shortcut exploits, with evidence of LiteLLM installation; however, it provides no specific exploit code, patches, or detailed technical information.

