Adobe ColdFusion servers under attack from APT group
Summary
A nation-state cyber-espionage group is actively hacking into Adobe ColdFusion servers and planting backdoors for future operations, Volexity researchers have told ZDNet.Matthew Meltzer, a security analyst for Volexity, has told ZDNet that the core issue at the heart of this vulnerability is that Adobe had replaced the technology behind the native ColdFusion WYSIWYG editor from FCKEditor to CKEditor.The researcher says that Volexity has also identified cases over the summer where a group of Indonesian hacktivists has been defacing websites hosted on ColdFusion servers.While Meltzer and Volexity have not had a chance to review logs and artifacts from the affected companies, they do believe that this group might have used the same vulnerability even before Adobe patched it."We have not observed abuse of this vulnerability outside of the APT activity and possibly related criminal web defacement," Meltzer told us, but this might change in the future.