RondoDox botnet is increasingly exploiting unpatched XWiki instances using a critical vulnerability (CVE-2025-24893) to deploy cryptocurrency miners and conduct DDoS attacks. The surge in exploitation attempts highlights the importance of timely patching and robust security practices. #RondoDox #CVE-2025-24893
Keypoints
- The vulnerability CVE-2025-24893 affects unpatched XWiki systems and allows remote code execution.
- Threat actors began exploiting the flaw in wild attacks as early as March, with a recent spike in activity in November 2025.
- The RondoDox botnet quickly incorporated this vulnerability to expand its DDoS and malicious activities.
- Attackers are using the flaw to deploy cryptocurrency miners, reverse shells, and conduct probing activities.
- Authorities like CISA mandated necessary mitigations, emphasizing the importance of timely patching and security measures.
Read More: https://thehackernews.com/2025/11/rondodox-exploits-unpatched-xwiki.html