CyberSecurity news

FlagThis

Sunny Yadav@eSecurity Planet //
Cybersecurity experts are warning of a coordinated surge in Server-Side Request Forgery (SSRF) exploitation attempts across multiple platforms. Threat intelligence firm GreyNoise reported on March 9, 2025, that approximately 400 unique IP addresses were actively involved in exploiting multiple SSRF vulnerabilities simultaneously. These attacks span several countries, including the United States, Germany, Singapore, India, Japan, and Lithuania, targeting critical systems in cloud environments and enterprise infrastructures.

This alarming trend highlights the persistent risks organizations face from evolving attack methods. The SSRF vulnerabilities being exploited include critical flaws in widely used software platforms like Zimbra Collaboration Suite (CVE-2020-7796), VMware products (CVE-2021-21973 and CVE-2021-22054), and multiple CVEs in GitLab's CE/EE versions, along with targets in DotNetNuke and Ivanti Connect Secure. GreyNoise also observed Grafana path traversal attempts preceding the SSRF surge, indicating attackers may be using Grafana as a foothold for deeper exploitation.

Defenders should identify and disrupt early-stage activity by monitoring for reconnaissance behaviors, such as path traversal attempts, which may provide early warning signs before full-scale exploitation occurs. Organizations should act now to patch vulnerable systems, restrict access where possible, and monitor for unexpected outbound requests that could indicate SSRF exploitation. The attacks reflect a shift from opportunistic scanning to more deliberate, coordinated campaigns that aim to breach internal systems and extract valuable data.
Original img attribution: https://assets.esecurityplanet.com/uploads/2025/03/esp_20250312-ssrf-exploitation-surge-evolving-threats.png
ImgSrc: assets.esecurit

Share: bluesky twitterx--v2 facebook--v1 threads


References :
  • securityaffairs.com: Experts warn of a coordinated surge in the exploitation attempts of SSRF vulnerabilities
  • eSecurity Planet: SSRF Exploitation Surge Highlights Evolving Cyberthreats
  • The GreyNoise Blog: Over 400 IPs Exploiting Multiple SSRF Vulnerabilities in Coordinated Cyber Attack
  • GreyNoise: řŸš¨ 400+ Malicious IPs Targeting SSRF Vulnerabilities. We have detected a coordinated surge in SSRF exploitation, with attackers systematically targeting multiple CVEs across different platforms.
  • Security Risk Advisors: Over 400 IPs Exploiting Multiple SSRF Vulnerabilities in Coordinated Cyber Attack
Classification:
  • HashTags: #SSRF #Cyberthreats #VulnerabilityExploitation
  • Target: Multiple Platforms
  • Feature: Exploitation
  • Malware: Multiple
  • Type: Vulnerability
  • Severity: Medium