Majority of Internet-Accessible REDCap Servers Outdated

2026-06-18T19:24:07Z45b71a26fbecbc31f40fb275ea99ef8fdad966f21d82577ba9d110ef18486ad8
AI ToolkitAccentureAndroid banking trojanAtlassianCisco ISEDragosF5KodakNGINXNetRiseOT cybersecurityREDCapRokarollaShinyHuntersSplunkUNC6508backdoorcommand executiondata breachinitial accessoutdated serversremote code executionroot escalationrunZerothird‑party dependencies

What happened

Multiple SecurityWeek reports: a majority of internet-accessible REDCap instances are outdated and regularly targeted by China-linked UNC6508 for initial access and backdoor deployment. Major vendors patched serious flaws — Splunk fixed an OS command injection in its AI Toolkit, Atlassian remediated dozens of third‑party dependency issues, Cisco ISE received a patch for a critical command‑execution vulnerability enabling root access, and F5 addressed critical NGINX flaws that could cause restarts and potential arbitrary code execution. A new Android banking trojan (Rokarolla) targets ~200 apps

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
45b71a26fbecbc31f40fb275ea99ef8fdad966f21d82577ba9d110ef18486ad8
Enrichment time
2026-06-18T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.