CISA says 'patch now' to 7-year-old Oracle WebLogic bug
Briefly

Water Sigbin's activities involving the exploitation of CVE-2017-3506 and CVE-2023-21839 underscore the adaptability of modern threat actors.
The use of sophisticated obfuscation techniques by Water Sigbin demonstrates its ability to conceal malicious code, posing challenges for security teams in detection and prevention.
CVE-2017-3506 was used in conjunction with three other WebLogic bugs to breach Superion's Click2Gov's servers in 2017, highlighting its attractiveness to attackers for data theft.
Read at Theregister
[
|
]