Overview
Attackers exploited Apache Struts CVE-2017-5638 roughly two months after the patch was released.\nAn expired certificate meant traffic to an internal inspection appliance silently went uninspected for years.\nThe stolen data included names, Social Security numbers and dates of birth for nearly half the US population.\nIt remains the canonical case study in patch delay and certificate hygiene.
Indicators of Compromise
Signals that suggest this is present on a system.
- Struts endpoints reachable from the internet
- Expired certificates on security appliances
- Unexpected outbound traffic from a web tier