- Engineer — Act: A public exploit now makes unauthenticated code execution against vBulletin 6.2.1 and earlier trivially accessible to any attacker. Patch to the fixed release immediately; if no patch is available for your branch, take the instance offline or block external access until patched.
- SOC/IR — Plan: With a public exploit in the wild, opportunistic scanning and exploitation attempts are likely imminent. Build or tune web application attack detections for anomalous unauthenticated POST requests to vBulletin PHP endpoints and PHP child-process spawning indicative of eval() abuse.
- Leader — Skip