NEWS Mail, documents and HR processes are under threat. Hackers have already picked up an exploit to a critical vulnerability in the Weaver E-cology system

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,316
The attackers began to act long before the problem was officially announced.
1777964022652.png
Hackers began using a critical gap in Weaver E-cology just days after the correction is released. The attacks went covertly and did not look like a mass campaign, but the scenario shows how quickly the attackers check corporate systems for fresh weaknesses.

We are talking about CVE-2026-22679 – error of remote code execution in Weaver E-cology 10.0 in the assemblies until March 12, 2026. The platform is widely used for office automation, document management, HR processes and internal work scenarios of many organizations.

Weaver released a March 12 fix, but publicly disclosed the details later. According to the Vega team, the first attacks began about five days after the release of the update and two weeks before the official notification. The activity lasted about a week and took place in several stages.

The problem was related to an open debugging API. Such an interface without authorization passed the user settings to server RPC functions and did not check the input. As a result, the attackers could transmit specially prepared values, which the server performed as system commands. A similar vector – the absence of checking input without prior authorization – was used in October 2025 when attacked on WatchGuard devices.

At first, the attackers checked the possibility of remote code execution through the ping commands from the Java process to the callback address associated with Goby. Then came attempts to download PowerShell scenarios, but end-bodied protections blocked these actions.

After unsuccessful downloads, the attackers tried to launch the MSI installer “fanwei0324.msi”, selected for a specific target. The file did not work correctly, and Vega experts did not see further activity through this path.

Later, the attackers returned to a vulnerable RCE-interface and applied a osteocated PowerShell without writing files to the disk to re-receive deleted scripts. At all stages, intelligence teams were launched, including whoami, ipconfig and tasklist.

Vega clarifies that all noticed processes were launched from “java.exe”, that is, from the Java machine built into the Tomcat in the Weaver. There were no signs of prior authorization. Despite the ability to execute the code, the attackers did not gain a foothold on the attacked host and did not create a stable session.

The official bulletin does not specify the workaround. Users Weaver E-cology 10.0 are recommended to install the current build as soon as possible, since the version 20260312 completely removes the dangerous debugging interface.
 

BLACK VEIL

Well-known member
Member
Joined
Jul 29, 2026
Messages
56
Reaction score
30
Location
ABD
Website
www.shopier.com
The attackers began to act long before the problem was officially announced.
View attachment 152
Hackers began using a critical gap in Weaver E-cology just days after the correction is released. The attacks went covertly and did not look like a mass campaign, but the scenario shows how quickly the attackers check corporate systems for fresh weaknesses.

We are talking about CVE-2026-22679 – error of remote code execution in Weaver E-cology 10.0 in the assemblies until March 12, 2026. The platform is widely used for office automation, document management, HR processes and internal work scenarios of many organizations.

Weaver released a March 12 fix, but publicly disclosed the details later. According to the Vega team, the first attacks began about five days after the release of the update and two weeks before the official notification. The activity lasted about a week and took place in several stages.

The problem was related to an open debugging API. Such an interface without authorization passed the user settings to server RPC functions and did not check the input. As a result, the attackers could transmit specially prepared values, which the server performed as system commands. A similar vector – the absence of checking input without prior authorization – was used in October 2025 when attacked on WatchGuard devices.

At first, the attackers checked the possibility of remote code execution through the ping commands from the Java process to the callback address associated with Goby. Then came attempts to download PowerShell scenarios, but end-bodied protections blocked these actions.

After unsuccessful downloads, the attackers tried to launch the MSI installer “fanwei0324.msi”, selected for a specific target. The file did not work correctly, and Vega experts did not see further activity through this path.

Later, the attackers returned to a vulnerable RCE-interface and applied a osteocated PowerShell without writing files to the disk to re-receive deleted scripts. At all stages, intelligence teams were launched, including whoami, ipconfig and tasklist.

Vega clarifies that all noticed processes were launched from “java.exe”, that is, from the Java machine built into the Tomcat in the Weaver. There were no signs of prior authorization. Despite the ability to execute the code, the attackers did not gain a foothold on the attacked host and did not create a stable session.

The official bulletin does not specify the workaround. Users Weaver E-cology 10.0 are recommended to install the current build as soon as possible, since the version 20260312 completely removes the dangerous debugging interface.
⛧ BLACK VEIL // PRIVATE SERVICES ⛧

“Some requests are never made publicly.”

01 — THE FIXER
Coordination of private requests, connections, and sensitive agreements.
$1,000

02 — THE BROKER
Mediation of communication and negotiation between private parties.
$2,500

03 — THE HANDLER
Management of private files and task processes.
$5,000

04 — THE GHOST
Private agent whose identity and background are kept confidential.
$10,000

05 — THE CLEANER
Control of complex situations and crisis management.
$15,000

06 — THE SPYMASTER
Sensitive information, intelligence analysis, and private investigation services.
$25,000

07 — BLACK CONTRACT
Preparation of highly confidential private agreements.
$50,000

08 — OMEGA ACCESS
BLACK VEIL's highest level exclusive service package.
$100,000

---

⛧ PRIVATE CONTACT

SESSION
"050bbbee83794febed3c001a153cf99f2474b71f0952ba019fc62a1b206401a819"

TELEGRAM
"@Cipher5Network"

"PRIVATE CHANNEL" (https://reference-url-citation.invalid/0)

---

"NO PUBLIC LISTING"
"PRIVATE REQUESTS ONLY"
"ACCESS BY APPROVAL"
"BLACK VEIL // 2026"

STATUS: "ACTIVE"
ACCESS: "RESTRICTED"
CLIENTS: "UNKNOWN"

 
5,848Threads
77,105Messages
5,860Members
CYZXXLatest member
Top Bottom