Clandestine[verified]@akaclandestineExploit
A GitHub repository offers exploitation tools for multiple ActiveMQ CVEs, indicating available code for exploitation but no evidence of active attacks, patches, or debunking.
📕「マルウエアの教科書」著者 | 吉川孝志 | 増補改訂版🌟発売中[verified]@MalwareBibleJPActive Exploitation
The report details a real‑world exploitation of CVE‑2023‑46604 in Apache ActiveMQ, leading to credential theft, lateral movement, and LockBit ransomware deployment, highlighting the active use of the vulnerability in the wild.
Yusuf Can Çakır[verified]@YusufcancakiirExploit
The author revealed an exposed server containing multiple exploitable CVEs, including Tomcat and ActiveMQ, with functional exploit code shared and no mention of patches or active attacks.
SOCRadar®[verified]@socradarActive Exploitation
The post reports that the North Korean group Andariel is actively exploiting CVE-2023-46604 and CVE-2023-42793 using tools such as Ladon and AnyDesk.
rootsecdev[verified]@rootsecdevPoC
The user references a modified exploit PoC for CVE-2023-46604 and provides a GitHub link, but no further technical details or exploitation claims are given.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
HelloKitty ransomware used CVE-2023-46604 for initial access, deploying Chisel for lateral movement and Rclone for exfiltration, but no PoC, patch, or detailed vulnerability information is disclosed.
Lyrie.ai[verified]@lyrie_aiDisclosure
The text announces CVE-2023-46604, an Apache ActiveMQ OpenWire deserialization RCE affecting versions below 5.18.3 or 10.0, but provides no PoC, exploitation code, or patch details.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
CVE‑2023‑46604 is an ActiveMQ RCE flaw that has been exploited in HelloKitty ransomware attacks and is mitigated by the 5.18.3 patch.