TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Bleeping Computer

Weaver E-cology critical bug exploited in attacks since March

Bill Toulas · 2 days ago · Read original ↗

ATT&CK techniques detected

4 predictions
T1059.001PowerShell
98%
“pass crafted values that are ultimately executed as system commands on the server, effectively turning the endpoint into a remote command execution interface. according to vega, the attackers first checked for remote code execution ( rce ) capabilities by triggering ping commands…”
T1190Exploit Public-Facing Application
97%
“weaver e - cology critical bug exploited in attacks since march hackers have been exploiting a critical vulnerability ( cve - 2026 - 22679 ) in the weaver e - cology office automation since mid - march to run discovery commands. the attacks started five days after the software ve…”
T1190Exploit Public-Facing Application
83%
“pass crafted values that are ultimately executed as system commands on the server, effectively turning the endpoint into a remote command execution interface. according to vega, the attackers first checked for remote code execution ( rce ) capabilities by triggering ping commands…”
T1059Command and Scripting Interpreter
80%
“pass crafted values that are ultimately executed as system commands on the server, effectively turning the endpoint into a remote command execution interface. according to vega, the attackers first checked for remote code execution ( rce ) capabilities by triggering ping commands…”

Summary

Hackers have been exploiting a critical vulnerability (CVE-2026-22679) in the Weaver E-cology office automation since mid-March to run discovery commands. [...]