Hackers are actively exploiting Oracle WebLogic servers that have not been patched against CVE-2020-14882 to deploy Cobalt Strike beacons that allow continuous remote access to compromised devices.
Cobalt Strike is a legitimate penetration testing tool used by hackers in post-breach tasks and for deploying so-called beacons that allow them to gain continuous remote access.
This later allows them to access the compromised servers to collect data and deploy malware payloads.

Incoming ransomware attacks
The CVE-2020-14882 remote code execution (RCE) flaw was patched by Oracle during last month's Critical Patch Update and was used by attackers to scan for exposed WebLogic servers a week later.
Since then, a related unauthenticated RCE vulnerability reported as CVE-2020-14750 – which also allows unauthorized takeover of unpatched instances – was addressed by a security update issued last weekend.
This latest series of attacks targeting vulnerable WebLogic instances began over the weekend, SANS ISC operator Renato Marinho revealed in an advisory.
Attackers use a chain of Powershell to download and install Cobalt Strike payloads on unpatched Oracle WebLogic servers.

Administrators were motivated to fix the systems immediately
Since both CVE-2020-14882 and CVE-2020-14750 can be easily exploited by unauthorized attackers to take over vulnerable WebLogic servers, Oracle advises companies to apply the security updates to block the attacks.
“Due to the severity of this vulnerability, Oracle recommends that customers apply the updates provided by this Security Alert as soon as possible after applying the October 2020 Critical Patch Update,” the company said in the weekend advisory.
CISA also urged administrators to apply the security as soon as possible to address the two critical vulnerabilities.
Information source: bleepingcomputer.com
