RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet

RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet

RondoDox botnet is increasingly exploiting unpatched XWiki instances using a critical vulnerability (CVE-2025-24893) to deploy cryptocurrency miners and conduct DDoS attacks. The surge in exploitation attempts highlights the importance of timely patching and robust security practices. #RondoDox #CVE-2025-24893

Keypoints

  • The vulnerability CVE-2025-24893 affects unpatched XWiki systems and allows remote code execution.
  • Threat actors began exploiting the flaw in wild attacks as early as March, with a recent spike in activity in November 2025.
  • The RondoDox botnet quickly incorporated this vulnerability to expand its DDoS and malicious activities.
  • Attackers are using the flaw to deploy cryptocurrency miners, reverse shells, and conduct probing activities.
  • Authorities like CISA mandated necessary mitigations, emphasizing the importance of timely patching and security measures.

Read More: https://thehackernews.com/2025/11/rondodox-exploits-unpatched-xwiki.html