Menace intelligence agency GreyNoise is warning of a “coordinated surge” within the exploitation of Server-Facet Request Forgery (SSRF) vulnerabilities spanning a number of platforms.
“Not less than 400 IPs have been seen actively exploiting a number of SSRF CVEs concurrently, with notable overlap between assault makes an attempt,” the corporate stated, including it noticed the exercise on March 9, 2025.
The international locations which have emerged because the goal of SSRF exploitation makes an attempt embrace the US, Germany, Singapore, India, Lithuania, and Japan. One other notable nation is Israel, which has witnessed a surge on March 11, 2025.
The record of SSRF vulnerabilities being exploited are listed beneath –
GreyNoise stated that most of the similar IP addresses are focusing on a number of SSRF flaws without delay quite than specializing in one explicit weak point, noting the sample of exercise suggests structured exploitation, automation, or pre-compromise intelligence gathering.
In gentle of lively exploitation makes an attempt, it is important that customers apply the most recent patches, restrict outbound connections to mandatory endpoints, and monitor for suspicious outbound requests.
“Many trendy cloud companies depend on inner metadata APIs, which SSRF can entry if exploited,” GreyNoise stated. “SSRF can be utilized to map inner networks, find susceptible companies, and steal cloud credentials.”