Microsoft detects Spring4Shell attacks across its cloud services
Credit:
Bleeping Computer
Microsoft said that it's currently tracking a "low volume of exploit attempts" targeting the critical Spring4Shell (aka SpringShell) remote code execution (RCE) vulnerability across its cloud services.
The Spring4Shell vulnerability (tracked as CVE-2022-22965) impacts the Spring Framework, described as the "most widely used lightweight open-source framework for Java."
"Microsoft regularly monitors attacks against our cloud infrastructure and services to defend them better," the Microsoft 365 Defender Threat Intelligence Team said. "Since the Spring Core vulnerability was announced, we have been tracking a low volume of exploit attempts across our cloud services for Spring Cloud and Spring Core vulnerabilities."