// THREAT INTELLIGENCE REPORT: VECTOR 9
// STATUS: ACTIVE EXPLOITATION
A new zero-click Remote Code Execution (RCE) vulnerability has been detected targeting older versions of Nginx and lighttpd web servers commonly embedded in consumer NAS devices.
Threat actors are actively scanning for exposed ports 8080 and 8443. The payload installs a stealth miner (XMR-Rig variant) and establishes a permanent backdoor.
IMMEDIATE ACTION REQUIRED:
1. Block all inbound traffic on non-essential ports.
2. Verify integrity of system logs for "wget" or "curl" commands to unknown IPs.
3. Isolate backup units immediately.