#ViewState
Okay this is the #SwiftUI I like. A clear defined ViewState, and some extension to deal with network and data.
November 24, 2024 at 8:41 PM
If you are using YSoSerial .Net, we have accepted a few PRs and patched several bugs & improved the ViewState plugin!

Merry Christmas 🎅

github.com/pwntester/ys...
December 24, 2024 at 11:54 AM
Over 3,000 ASP .NET machine keys exposed—attackers are using them for ViewState code injection and RCE

Microsoft threat intel put out some good detection and mitigation steps. Here’s what you need to know and how to protect your apps: 👇

🔗 www.vulnu.com/p/thousands-...
Thousands of ASP.NET Sites at Risk from Publicly Exposed Machine Keys
Microsoft warns that over 3,000 publicly disclosed ASP.NET machine keys could enable ViewState code injection attacks, leading to remote code execution.
www.vulnu.com
February 6, 2025 at 8:45 PM
Microsoft warns that attackers are injecting malware into ViewState, which manages state in ASP.NET web forms, using static machine keys found online (Sergiu Gatlan/BleepingComputer)

Main Link | Techmeme Permalink
February 7, 2025 at 1:01 PM
Some enterprising young threat actor read the Sitecore docs, which is significantly less surprising than literally anyone else reading docs cloud.google.com/blog/topics/...
ViewState Deserialization Zero-Day Vulnerability in Sitecore Products (CVE-2025-53690) | Google Cloud Blog
An active ViewState deserialization attack affecting Sitecore products, where attackers achieved remote code execution.
cloud.google.com
September 3, 2025 at 10:34 PM
Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online. #codeinjection #CyberAlerts www.bleepingcomputer.com/news/securit...
Microsoft says attackers use exposed ASP.NET keys to deploy malware
Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online.
www.bleepingcomputer.com
February 6, 2025 at 11:12 PM
Attackers used a public ASP.NET machine to conduct ViewState code injection attacks
Attackers used a public ASP.NET machine to conduct ViewState code injection attacks
Microsoft researchers warn that threat actors are delivering the Godzilla framework using a static ASP.NET machine.
securityaffairs.com
February 7, 2025 at 10:05 AM
Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online.
Microsoft says attackers use exposed ASP.NET keys to deploy malware
Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online.
www.bleepingcomputer.com
February 6, 2025 at 8:59 PM
Yea I kinda figured viewstate was sus.
February 7, 2025 at 8:16 AM
We are sharing ScreenConnect instances likely vulnerable to CVE-2025-3935 (CVSS 8.1, versions 25.2.3 & earlier may be susceptible to a ViewState code injection).

Patch info: connectwise.com/company/trus...

685 instances still unpatched (2025-05-07):
dashboard.shadowserver.org/statistics/c...
May 8, 2025 at 10:42 AM
The Cybersecurity and Infrastructure Security Agency, or CISA, warned that hackers are exploiting the ConnectWise ScreenConnect vulnerability, which could allow a ViewState code injection attack.

Details, incl. what a ViewState code injection attack is, @crndotcom.bsky.social

tinyurl.com/yury6wmw
ConnectWise ScreenConnect Vulnerability Exploited: CISA
CISA warned that the ConnectWise ScreenConnect vulnerability is being exploited by threat actors to perform ViewState code injection attacks.
tinyurl.com
June 3, 2025 at 7:07 PM
ZAP Blog: June Updates
www.zaproxy.org/blog/2026-07...
More PTK integration, lots of Client Spider improvements, and much more..
#zaproxy #appsec
ZAP Updates - June 2026
In June the OWASP PTK add-on graduated to beta with its integration now properly matching ZAP’s architecture, a security advisory was issued and patched for the Viewstate add-on, and the Client Spider...
www.zaproxy.org
July 1, 2026 at 12:01 PM
May 25, 2026 at 6:13 AM
May 25, 2026 at 6:13 AM
CVE-2025-3935 - ScreenConnect ASP.NET ViewState Code Injection Vulnerability
CVE ID : CVE-2025-3935

Published : April 25, 2025, 7:15 p.m. | 2 hours, 59 minutes ago

Description : ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code inj...
CVE-2025-3935 - ScreenConnect ASP.NET ViewState Code Injection Vulnerability
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It is important to note that to obtain these machine keys, privileged system level access …
cvefeed.io
April 25, 2025 at 10:19 PM
An Insecure Java Deserialization vulnerability has been reported in a ZAP add-on via Neo by ProjectDiscovery.

Update your ZAP add-ons now, and definitely update from older versions of ZAP.

For more details see: www.zaproxy.org/blog/2026-06...
Java Deserialization Vulnerability in ZAP Viewstate Add-on
A Java Deserialization Vulnerability has been found in the ZAP Viewstate Add-on. Update your ZAP add-ons now, and if you are on an older version of ZAP then update that ASAP.
www.zaproxy.org
June 24, 2026 at 2:52 PM
Nation-state hackers targeted ConnectWise, affecting few ScreenConnect customers. A ViewState vulnerability (CVE-2025-3935) may have been exploited, granting remote access. Mandiant investigates; affected users notified. Breach: August 2024, discovered May 2025.#ConnectWiseHack
May 30, 2025 at 12:19 PM
Over 3,000 exposed ASP.NET machine keys enable attackers to inject malicious ViewState code, leading to remote code execution and malware (e.g., Godzilla). Microsoft urges secure key generation, avoiding public keys, and using AMSI. Reinstallation may be needed for compromised servers.
February 6, 2025 at 9:07 PM
TIL! Did he invent ViewState?

If so, I'd like A Word...
June 4, 2025 at 5:56 PM
Was cutting edge at the time, then we all learned about viewstate 🫠
December 6, 2024 at 10:42 PM
Sitecore — a cloud-based marketing platform with AI features — is under active 0-day attack via .NET ViewState deserialization.
Root cause: a sample “machine key” in Sitecore’s docs was actually valid.

Details: buff.ly/XzHxq0O 🧵1/4
ViewState Deserialization Zero-Day Vulnerability in Sitecore Products (CVE-2025-53690) | Google Cloud Blog
An active ViewState deserialization attack affecting Sitecore products, where attackers achieved remote code execution.
cloud.google.com
September 10, 2025 at 9:08 PM
Microsoft says attackers use exposed ASP.NET keys to deploy malware
Microsoft says attackers use exposed ASP.NET keys to deploy malware
Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online.
www.bleepingcomputer.com
February 6, 2025 at 9:15 PM
Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks thehackernews.com/2025/02/micr...
Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks
Microsoft warns of 3,000+ publicly disclosed ASP.NET machine keys that enable ViewState code injection attacks, leading to remote code execution risks
thehackernews.com
February 9, 2025 at 2:46 PM
Microsoft has warned of #ViewState code injection attacks using exposed ASP.NET machine keys. Organizations are urged to enhance security measures to mitigate potential risks. Stay protected and review your systems. #cybersecurity #threat
Microsoft Warns of ViewState Code Injection Attacks
Microsoft has issued a warning about ViewState code injection attacks that exploit publicly disclosed ASP.NET machine keys, urging organizations to adopt security measures to mitigate associated risks.
decrypt.lol
February 7, 2025 at 1:35 PM