Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 27 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Samsung MagicINFO Server Flaw Now Actively Exploited – Huntress Uncovers Real-World Attacks

by The Gurus
May 7, 2025
in Featured
Samsung MagicINFO Server Flaw Now Actively Exploited – Huntress Uncovers Real-World Attacks
Share on FacebookShare on Twitter

Cybersecurity researchers at Huntress have issued a warning after confirming active exploitation of a critical remote code execution (RCE) vulnerability in Samsung’s MagicINFO 9 digital signage software.

The flaw, tracked as CVE-2024-34515, allows unauthenticated attackers to execute arbitrary code on vulnerable servers by sending a malicious HTTP request. Tens of thousands of MagicINFO instances, many with default configurations, are exposed to the Internet, which means the attack surface is significant.

In their latest blog post, Huntress provides a technical deep dive into how attackers are abusing the flaw, complete with packet captures, payload analysis, and post-exploitation behaviour. Their research follows the public disclosure of the vulnerability last week, and critically, confirms that attackers are now leveraging it in real-world campaigns.

“We’ve already observed activity in the wild, including one IP attempting to execute commands via the vulnerability. This is no longer a theoretical risk,” the Huntress team warned.

Attack Analysis

The flaw stems from how MagicINFO handles deserialisation of Java objects in HTTP requests. Huntress found that attackers use URL-encoded Java payloads to deliver malicious commands, including a base64-encoded reverse shell. Once a foothold is established, attackers appear to be running enumeration scripts and laying the groundwork for further compromise. One observed payload included a shell command that downloaded and executed a remote script from an attacker-controlled domain, with the intent of opening persistent backdoor access.

Detection and Mitigation

Huntress offers actionable defence strategies, including:

  • Searching server logs for suspicious POST requests to the vulnerable /magicInfo/j_spring_security_check endpoint

  • Inspecting for commands involving tools like curl, wget, or bash

  • Looking for unusual outbound connections that may indicate data exfiltration or reverse shells

The blog includes detection techniques and Indicators of Compromise (IOCs) to help defenders assess exposure and respond effectively.

Samsung has since issued a patch and is urging customers to update immediately. However, as Huntress points out, many organisations running MagicINFO may not have traditional IT or patching workflows in place, especially in environments like retail, hospitality, or education, where digital signage systems are often overlooked from a security perspective.

“Organisations should treat this as a priority. Even if MagicINFO isn’t a core business app, it can become an attacker’s beachhead if left exposed,” Huntress warned.

Read the full Huntress analysis here: https://www.huntress.com/blog/rapid-response-samsung-magicinfo9-server-flaw

 

ShareTweet
Previous Post

MIWIC25: Kiranjit Kaur Shergill, Developer at Barclays

Next Post

How To Secure Digital Wallets from Phishing Attacks

Recent News

Keeper Security launches Microsoft Teams integration for privileged access management

Keeper Security launches Microsoft Teams integration for privileged access management

June 26, 2026
UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

UK Museums Are a Cyber Incident Waiting to Happen and the Government Knows It

June 25, 2026
pqc

New Forescout Data Reveals Slow Progress Toward Quantum-Safe Security

June 24, 2026
AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete

June 24, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol