ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Initial access broker pleads guilty to selling access to 50 corporate networks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-42321
Authenticated RCE via Insecure Deserialization in Microsoft Exchange Server

CVE-2021-42321 is an insecure deserialization remote code execution flaw in on-premises Microsoft Exchange Server, tied to insufficient validation by Exchange's ChainedSerializationBinder. Per the CVSS vector, it is triggered over the network by an authenticated user with low privileges and no user interaction, by submitting crafted serialized data that Exchange fails to safely deserialize. A successful attacker gains arbitrary code execution on the Exchange server with high impact to confidentiality, integrity, and availability, giving a foothold in the mail environment. Organizations running affected on-premises Exchange deployments are in scope. The flaw was actively exploited before patches shipped in November 2021, has public PoC exploits, was added to CISA's KEV on 2021-11-17 with known ransomware use, and carries an EPSS of 91.7% (99.9+ percentile).

Do: Apply the November 2021 Microsoft Exchange Server security updates per vendor instructions to affected on-premises Exchange 2016/2019 deployments. Given confirmed in-the-wild exploitation and known ransomware use, check Exchange servers for signs of compromise, verify backups, and review accounts holding privileged Exchange roles, since exploitation requires authenticated access — enforce MFA and audit impersonation/admin role assignments while patching.

8.892% KEV ransomware PoC ×2
  • microsoft exchange server
masshundreds of thousands of internet-facing on-premises Exchange servers (on the order of 10^5 endpoints, supporting millions of mailbox users)
CVE-2022-26134
Unauthenticated OGNL Injection RCE in Atlassian Confluence Server/Data Center

Atlassian Confluence Server and Data Center contain an unauthenticated remote code execution flaw caused by improper neutralization of expression-language (OGNL) input (CWE-917): an attacker with network access to the application can submit a crafted request that is evaluated as an expression and executed by the server. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code with the privileges of the Confluence process, without any credentials. All organizations running self-managed Confluence Server or Data Center are affected, particularly instances exposed to the internet; Confluence Cloud is not listed among the affected products. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-02 with ransomware use marked as known, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile). CVSS has not yet been scored in this data, but the KEV listing and known ransomware use make unpatched, internet-facing instances a top-priority patching target.

Do: Immediately upgrade to the patched Confluence release specified in Atlassian's 2022-06-02 security advisory, and until patched follow the CISA required action to block all internet traffic to and from affected instances. Because in-the-wild exploitation and ransomware use are confirmed, also hunt for compromise indicators on both patched and unpatched hosts, such as webshells, unexpected child processes of the Confluence service, and unusual outbound connections.

9.8100% KEV ransomware PoC ×2
  • Atlassian Confluence Server
  • Atlassian Confluence Data Center
largetens of thousands of internet-exposed instances (public scan counts of roughly 60,000-90,000 Confluence Server/Data Center hosts around the June 2022…
Full article618 words · extracted from helpnetsecurity.com · click to collapse

A 40-year-old Jordanian man has admitted to selling unauthorized access to computer networks of at least 50 companies, the US Attorney’s Office of the District of New Jersey has announced.

Feras Khalil Ahmad Albashiti has pleaded guilty last Thursday to fraud and related activity in connection with access devices.

initial access broker guilty

“In May 2023, law enforcement officers were investigating an online forum where malware and malicious code was being offered for sale. Albashiti controlled an online moniker named ‘r1z’ and used it in the online forum,” the press release says.

“On May 19, 2023, Albashiti sold to an undercover law enforcement officer unauthorized access to the networks of at least 50 victim companies in exchange for cryptocurrency.”

The court documents don’t mention the name of the undergound forum, but older reports by a number of cybersecurity companies show that r1z was a “credible” threat actor that advertised on the notorious Russian-language XSS Forum, which was taken down in July 2025 when its suspected administrator was arrested in Ukraine.

The threat actor was spotted offering 30 SonicVPN and 50 Microsoft Exchange accesses with a ‘working exploit’ on XXS Forum in June 2022, according to Kela threat researchers.

“Interestingly, three months before, r1z claimed that they can sell ‘the implementation of CVE-2021-42321’, which is known as Microsoft Exchange security vulnerability. Therefore, it is possible that r1z had a working custom exploit for this CVE that was later used by [r1z] for gaining access,” the researchers noted.

“The same month, r1z was observed selling access to 50 American companies through ‘Confluence’. The actor also offered to sell a list of 10,000 vulnerable machines. As seen on a screenshot shared by the actor, the hacker was able to gain access to servers using a critical RCE vulnerability tracked as CVE-2022-26134 that affects Confluence Server and Data Center. The list offered for sale probably included machines that could be exploited through the same flaw.”

CloudSEK reported that in February 2023, they spotted the r1z promoting EDR/AVs malware that could also act as a persistent backdoor, credential harvester, malware dropper, and event log remover.

OpSec failures revealed r1z’s identity

According to a signed FBI affidavit, in 2023 r1z also offered for sale access to the computer networks of approximately 50 victim companies through the exploitation of two commercial firewall products, and an unauthorized software modification of a commercial penetration testing tool.

Contacted by an undercover FBI employee, r1z first sold them access to the above mentioned 50 victim companies, and later an exploit that would bypass a specific EDR solution. Unfortunately for him, he (unknowingly) demonstrated its effectiveness on a server operated and monitored by the FBI.

This allowed the FBI to discovered r1z’s (uncloaked) IP address, which was later connected to a ransomware attack against a US manufacturing company that resulted in $50+ million of damages.

Finally, the records obtained following the seizure of the defunct XSS Forum revealed that the Gmail address associated with r1z’s account was also used in 2016 by Albashiti to apply for a US visa with the US State Department, and that this email account is linked to a Google Pay Account and credit cards in the names of “Firas K. Bashiti” and “Firas Bashiti.”

At the time of his arrest, Albashiti was residing in the Republic of Georgia. He was extradited to the US in July 2024.

His sentencing is scheduled for May 11, 2026, when he could receive a maximum sentence of 10 years in prison and a maximum fine of $250,000, “or twice the gross amount of gains or losses resulting from the offense.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/01/20/initial-access-broker-pleads-guilty/