#LDAPNightmare
Someone is using a fake PoC for the LDAPNightmare exploit to infect researchers and threat actors with an infostealer

www.trendmicro.com/en_us/resear...
January 9, 2025 at 10:05 AM
LDAPNightmare: SafeBreach Labs Publishes First Proof-of-Concept Exploit for
CVE-2024-49112
www.safebreach.com/blog/ldapnig...
LDAPNightmare: SafeBreach Publishes First PoC Exploit (CVE-2024-49113)
See how SafeBreach researchers developed a zero-click PoC exploit for LDAPNightmare (CVE-2024-49113) that crashes unpatched Windows Servers.
www.safebreach.com
January 3, 2025 at 5:26 PM
Critical Flaws in LDAP Exploited!

A new proof-of-concept exploit, LDAPNightmare, crashes unpatched Windows Servers with one crafted request.

Even worse? RCE attacks are possible with minor tweaks. thehackernews.com/2025/01/ldap...
LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers
LDAPNightmare PoC exploit crashes Windows Servers via CVE-2024-49113. Patch or monitor CLDAP responses to prevent DoS.
thehackernews.com
January 3, 2025 at 8:44 PM
A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka "LDAPNightmare") on #GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server. #Malware #CyberSecurity www.bleepingcomputer.com/news/securit...
Fake LDAPNightmware exploit on GitHub spreads infostealer malware
A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka "LDAPNightmare") on GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server.
www.bleepingcomputer.com
January 12, 2025 at 10:27 PM
LDAPNightmare : First Proof-of-Concept Exploit for CVE-2024-49112 : www.safebreach.com/blog/ldapnig... credits @oryair1999 @ShahakMo

LdapNightmare : a PoC tool that tests a vulnerable Windows Server against CVE-2024-49112 : github.com/SafeBreach-L...
January 2, 2025 at 3:15 PM
LDAPNightmare, a PoC exploit targets Windows LDAP flaw CVE-2024-49113
LDAPNightmare, a PoC exploit targets Windows LDAP flaw CVE-2024-49113
Experts warn of a new PoC exploit, LDAPNightmare, that targets a Windows LDAP flaw (CVE-2024-49113), causing crashes & reboots.
securityaffairs.com
January 3, 2025 at 10:42 AM
Detect CVE-2024-49113 (aka #LDAPNightmare) – Windows LDAP denial-of-service vulnerability exploited via a publicly available PoC – using a set of #Sigma rules in the SOC Prime Platform.

socprime.com/blog/cve-202...
CVE-2024-49113 Detection: Windows LDAP Denial-of-Service Vulnerability aka LDAPNightmare Exploited via a Publicly Available PoC - SOC Prime
Detect CVE-2024-49113 aka LDAPNightmare exploitation attempts enabling attackers to gain DoS with Sigma rules from SOC Prime Platform.
socprime.com
January 17, 2025 at 3:56 PM
LDAPNightmare, a PoC exploit targets Windows LDAP flaw CVE-2024-49113 https://buff.ly/4gYUw3v
LDAPNightmare, a PoC exploit targets Windows LDAP flaw CVE-2024-49113
Experts warn of a new PoC exploit, LDAPNightmare, that targets a Windows LDAP flaw (CVE-2024-49113), causing crashes & reboots.
buff.ly
January 5, 2025 at 2:12 AM
Hundreds of CVE.
Vast majority of companies uses Linux in the background (fileserver and so on) but MS infrastructure (AD and so on).
And that's usually the weak point.
Old enough to remember LDAPNightmare? (CVE-2024-49113)
Or the bypass security checks by update? (CVE-2024-43491)
March 12, 2025 at 5:34 AM
Fake LDAPNightmware exploit on GitHub spreads infostealer malware
Fake LDAPNightmware exploit on GitHub spreads infostealer malware
A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka "LDAPNightmare") on GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server.
www.bleepingcomputer.com
January 11, 2025 at 4:11 PM
LDAPNightmare: SafeBreach Publishes First PoC Exploit (CVE-2024-49113)
LDAPNightmare: SafeBreach Publishes First PoC Exploit (CVE-2024-49113)
www.safebreach.com
January 11, 2025 at 6:39 PM
LDAPNightmare: exploit para falla que afecta al protocolo LDAP de Windows
LDAPNightmare: exploit para falla que afecta al protocolo LDAP de Windows
blog.segu-info.com.ar
January 10, 2025 at 3:07 AM
LDAPNightmare PoC exploits patched CVE-2024-49113, crashing LSASS (reboot). It can also lead to RCE (CVE-2024-49112). Apply Microsoft's December 2024 patches now!#PatchNowCVE20244911249113
January 3, 2025 at 9:02 AM
Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit
Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit
Our blog entry discusses a fake PoC exploit for LDAPNightmare (CVE-2024-49113) that is being used to distribute information-stealing malware.
buff.ly
January 9, 2025 at 2:30 PM
A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka "LDAPNightmare") on GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server.

www.bleepingcomputer.com/news/securit...
Fake LDAPNightmware exploit on GitHub spreads infostealer malware
A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka "LDAPNightmare") on GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server.
www.bleepingcomputer.com
January 11, 2025 at 4:38 PM
A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka "LDAPNightmare") on GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server.
Fake LDAPNightmware exploit on GitHub spreads infostealer malware
www.bleepingcomputer.com
January 13, 2025 at 5:10 AM
Notícia da SecurityOnline

"Fake LDAPNightmare PoC Oculta Malware Rouba Informações" #bolhasec
Fake LDAPNightmare PoC Exploit Conceals Information-Stealing Malware
Trend Micro researchers have uncovered a dangerous fake proof-of-concept (PoC) exploit masquerading as an exploit for CVE-2024-49113, a The post Fake LDAPNightmare PoC Exploit Conceals Information-Stealing Malware appeared first on Cybersecurity News.
securityonline.info
January 10, 2025 at 10:31 AM
LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
January 3, 2025 at 8:42 AM
Next blog post ideas:
Elastic evasion with CobaltStrike
Hacking firmware on Netgear router
CET bypass in legacy Edge browser
Breakdown in LDAPnightmare
January 13, 2025 at 5:10 AM