#RediShell
📢🚨 RediShell, a 13 year old Redis vulnerability, leaves about 60,000 unauthenticated servers open to remote code execution.

Read more: hackread.com/13-year-old-...

#Cybersecurity #InfoSec #RediShell #Redis #Vulnerability #InfoSec
13-Year-Old RediShell Vulnerability Puts 60,000 Redis Servers at Risk
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
October 7, 2025 at 5:52 PM
RediShell security flaw in Redis:

-remotely exploitable
-CVSSv3 10/10
-impacts all versions released over the past 13 years
-impacts 75% of cloud instances

www.wiz.io/blog/wiz-res...

redis.io/blog/securit...
Wiz Finds Critical Redis RCE Vulnerability: CVE‑2025‑49844 | Wiz Blog
A 13‑year Redis flaw (CVE‑2025‑49844) allows attackers to escape Lua sandbox and run code on hosts. See Wiz Research’s analysis and mitigations.
www.wiz.io
October 7, 2025 at 10:29 AM
13-Year-Old RediShell Vulnerability Puts 60,000 Redis Servers at Risk
13-Year-Old RediShell Vulnerability Puts 60,000 Redis Servers at Risk
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
October 8, 2025 at 11:25 AM
Seems like redishell is being exploited now

seen in the wild.

196.251.70.)215
401120

#redishell #exploit #reverseshell
November 2, 2025 at 10:28 PM
Kritická chyba vystavuje 60 000 serverů Redis vzdálenému zneužití.
Critical Flaw Exposes 60,000 Redis Servers to Remote Exploitation
A critical Redis flaw, dubbed “RediShell,” has exposed 60,000 unprotected servers to exploitation
www.infosecurity-magazine.com
October 7, 2025 at 3:47 PM
#redishell päivityksiä kello 3 aamulla. Onneksi sen jölkeen voi mennä nukkumaan.
October 9, 2025 at 12:28 AM
Redishell: The Critical 13-Year-Old Redis Vulnerability Need to be Patched
Redishell: The Critical 13-Year-Old Redis Vulnerability Need to be Patched
In early October 2025, a devastating remote code execution (RCE) vulnerability in Redis—known as Redishell (CVE-2025-49844)—shook the cybersecurity community. Marked with a perfect CVSS score of 10…
thecyberthrone.in
October 7, 2025 at 5:15 PM
Critical Flaw Exposes 60,000 Redis Servers to Remote Exploitation - Infosecurity Magazine www.infosecurity-magazine.com/news/redis-s...
Critical Flaw Exposes 60,000 Redis Servers to Remote Exploitation
A critical Redis flaw, dubbed “RediShell,” has exposed 60,000 unprotected servers to exploitation
www.infosecurity-magazine.com
October 12, 2025 at 10:56 AM
🚨 Redis flaw RediShell (CVE-2025-49844) earns a CVSS 10.0
A 13-year-old Use-After-Free bug lets attackers escape Lua sandbox & execute code.

330K Redis instances exposed globally.
www.technadu.com/redishell-cr...

#Redis #CyberSecurity #RCE
October 7, 2025 at 1:39 PM
The #RediShell RCE #vulnerability, a critical cumulative flaw in Redis’s Lua scripting engine, was publicly disclosed in early October 2025. CVE-2025-49844 is a use-after-free vulnerability that can escape the Lua sandbox and enable host-level remote code execution.
www.criminalip.io/knowledge-hu...
RediShell RCE Alert: Over 8,000 Redis Instances — Immediate Update Recommended
This article summarizes the vulnerability principle and exploitation scenario of RediShell (CVE-2025-49844), and based on Criminal IP
www.criminalip.io
October 30, 2025 at 3:23 PM
Kritischer Exploit für Remote-Code-Execution bedroht Redis-Instanzen

#Cybersecurity #Cybersicherheit #LuaScripting #OpenSource #RediShell #Schwachstelle @Sysdig #ThreatIntelligence

netzpalaver.de/2025/...
October 15, 2025 at 11:55 AM
Redis patches critical “RediShell” RCE vulnerability, update ASAP! (CVE-2025-49844)
Redis patches critical "RediShell" RCE vulnerability, update ASAP! (CVE-2025-49844) - Help Net Security
Redis has released patches for a critical vulnerability (CVE-2025-49844) that may allow attackers full access to the underlying host system.
www.helpnetsecurity.com
October 7, 2025 at 5:10 PM
#Redis (Remote Dictionary Server) and its open source fork #Valkey share a scary flaw that can give an attacker full RCE. It’s been assigned a max CVSS score of 10.0—you don’t often see that.

#Redis shouldn’t normally be exposed to the internet, but it often is. In #SBBlogwatch, we descend a layer:
#RediShell: Redis/Valkey Get ‘Perfect 10’ Critical RCE Vuln
Redis hell: CVSS 10.0 vulnerability in ubiquitous cloud storage layer. PATCH NOW.
securityboulevard.com
October 8, 2025 at 12:57 PM
Grosse faille de sécurité dans #Redis qui porte le nom de #Redishell www.sysdig.com/blog/cve-202.... Corrigée dans #Debian packages.debian.org/bookworm/red... (et par conséquent dans #Yunohost). Faites vos mises à jour. Pour rappel, Redis est utilisé comme cache pour #Nextcloud par exemple.
Understanding CVE-2025-49844: “RediShell” Critical Remote Code Execution in Redis | Sysdig
CVE-2025-49844 (RediShell) is a critical Redis remote code execution vulnerability (CVSS 10.0) affecting all versions with Lua scripting. Discovered by Wiz and patched on October 3 2025, it allows aut...
www.sysdig.com
October 9, 2025 at 7:46 AM
さくらのクラウドからもRediShellの注意喚起。さくらのクラウドはパケットフィルタ機能の設定が結構難しく、きちんと設定できてないことがあるので特に要注意ではある。
【重要】Redis「RediShell(CVE-2025-49844)」に関する注意喚起
さくらのクラウドに関連するニュースをお届けします
cloud.sakura.ad.jp
October 12, 2025 at 5:47 AM
Redis patches critical “RediShell” RCE vulnerability, update ASAP! (CVE-2025-49844)

📖 Read more: www.helpnetsecurity.com/2025/10/07/r...

#cybersecurity #cybersecuritynews #vulnerability
Redis patches critical "RediShell" RCE vulnerability, update ASAP! (CVE-2025-49844) - Help Net Security
Redis has released patches for a critical vulnerability (CVE-2025-49844) that may allow attackers full access to the underlying host system.
www.helpnetsecurity.com
October 7, 2025 at 1:43 PM
Redis (Remote Dictionary Server) and its open-source fork, Valkey, share a severe flaw that can grant an attacker full remote code execution, writes @richi. It’s been assigned a maximum CVSS score of 10.0, which is something you don’t often see.
#RediShell: Redis/Valkey Get ‘Perfect 10’ Critical RCE Vuln
Redis hell: CVSS 10.0 vulnerability in ubiquitous cloud storage layer. PATCH NOW.
securityboulevard.com
October 7, 2025 at 10:00 PM
#Redis: A13-Year-Old Vulnerability CVE-2025-49844 dubbed #RediShell: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely (#RCE) in Redis versions used in 75% of Cloud environments!

Update your Redis Immediately!
13-Year-Old Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely
Redis fixes 13-year CVSS 10 flaw allowing Lua script-based remote code execution in all versions.
thehackernews.com
October 7, 2025 at 10:09 AM
Al voltant del 75% de tots els servidors al núvol executen alguna instància de Redis i moltes no estan ben configurades, així que cal esperar una onada d’incidents de seguretat vinculats a RediShell.

www.darkreading.com/cloud-securi...
Patch Now: 'RediShell' Threatens Cloud Via Redis RCE
A 13-year-old flaw with a CVSS score of 10 in the popular data storage service allows for full host takeover; more than 300k instances currently exposed.
www.darkreading.com
October 8, 2025 at 6:12 PM
The new remote code execution in Redis is fun (aka RediShell). Let's see what minifying the Redis container with DockerSlim and its auto-generates seccomp profile will do to mitigate the exploits 🙂
October 9, 2025 at 7:25 AM
RediShell: una RCE da score 10 vecchia di 13 anni è stata aggiornata in Redis

📌 Link all'articolo : www.redhotcyber.com/post/red...

#redhotcyber #hacking #cti #ai #online #it #cybercrime #cybersecurity #technology #news #cyberthreatintelligence #innovation #privacy
October 7, 2025 at 5:38 AM
📰 Redis Peringatkan Cacat Keamanan Kritis yang Dapat Dikendalikan dari Jarak Jauh

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2025/10/07/redis-cve-2025-49844-remote-code-execution/

#cve
-2#cve49844 #lua ##luah#patchs#rediss#redishellt#remote #codeu#executione#vulnerabilitya href="/hashtag/wiz" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#wiz
October 7, 2025 at 6:40 AM
RediShell: Critical remote code execution vulnerability in Redis | Discussion
Wiz Finds Critical Redis RCE Vulnerability: CVE‑2025‑49844 | Wiz Blog
A 13‑year Redis flaw (CVE‑2025‑49844) allows attackers to escape Lua sandbox and run code on hosts. See Wiz Research’s analysis and mitigations.
www.wiz.io
October 7, 2025 at 12:20 AM