ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Data Breaches

ColdFusion Zero-Day allows hackers to steal Customer Data

Paul by Paul
April 17, 2013
in Data Breaches, Security
Reading Time: 2 mins read
cf marquee family
Share on FacebookShare on Twitter

A vulnerability in the ColdFusion Web server platform, reported by Adobe less than a week ago, has apparently been in the wild for almost a month and has allowed the hacking of at least one company website, exposing customer data. Yesterday, it was revealed that the virtual server hosting company Linode had been the victim of a multi-day breach that allowed hackers to gain access to customer records.

The breach was made possible by a vulnerability in Adobe’s ColdFusion server platform that could, according to Adobe, “be exploited to impersonate an authenticated user.” A patch had been issued for the vulnerability on April 9 and was rated as priority “2” and “important.” Those ratings placed it at a step down from the most critical, indicating that there were no known exploits at the time the patch was issued but that data was at risk. Adobe credited “an anonymous security researcher,” with discovering the vulnerability.

But according to IRC conversation including one of the alleged hackers of the site, Linode’s site had been compromised for weeks before its discovery. That revelation leaves open the possibility that other ColdFusion sites have been compromised as hackers sought out targets to use the exploit on.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

How Hackers Still Manage to Compromise MFA

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

ColdFusion is a Java-based Web server platform that interprets its own proprietary markup language in page code to access server-side application components and data. It has had a large installed base in the government sector and other markets, but its market share has been in decline for some time, and the technology has seen little change since 2009. In 2011, Adobe announced it was moving the whole of ColdFusion development to India.

The element attacked is its user authentication component, cflogin. In March, a ColdFusion user reported encountering errors in cflogin he believed were because of attempted hack attacks. “I’ve now seen cflogin throw an error twice now with bad input at—I believe—the cookie level,” he reported to Adobe’s bug tracker.

By exploiting the login vulnerability, the hackers were able to gain access to the Linode server itself and to the site’s code. Through the code, they were able to obtain the login credentials to Linode’s database and stole customer data that included hashed passwords, encrypted credit card data, and the unencrypted last four digits of credit cards used for verification purposes. Customer keys for Linode’s deployment and management APIs were also exposed.

Linode has expired those keys and is re-issuing them. Linode representatives said in a blog post that it has “no evidence decrypted credit card numbers were obtained” and added that the encryption key for credit card data was not stored on the server and was “not guessable, sufficiently long and complex, not based on dictionary words, and not stored anywhere but in our heads.”

Article originally appeared on Arstechnica.com

Tags: 0dayColdfusionhackwebsite
Previous Post

“Watering hole” websites latest attack threat

Next Post

47 Fixes in Java’s Latest Patch

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

February 22, 2026

Panera Bread Hacked – Exposes 5.1 Million Customer Records

February 8, 2026

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
Please login to join discussion

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.