PHP Dev
damienseguy's profile
Damien seguy@damienseguy•Feb 01
33.3K
Exakat's profile
Post cover image

Laravel Sites Hacked: Public Folder Backdoors, Google-Only Redirects, and CPU Cryptomining (Likely via Livewire RCE)

From 5balloons.info•Jan 27•3m read time

Multiple Laravel sites were compromised through a likely Livewire RCE vulnerability (CVE-2025-54068, affecting versions 3.x < 3.6.4). Attackers exploited improper serialized data handling during component hydration to place PHP backdoors in the public/ directory, implement Google-only redirects for SEO cloaking, and deploy cryptominers. The attack bypasses Laravel's routing and middleware by executing files directly from the public folder. Immediate mitigation requires upgrading Livewire to 3.6.4+, securing APP_KEY, locking public/ directory permissions, hunting for compromised files, and potentially rebuilding affected servers.

1.1K Impressions
damienseguy's user avatar
Damien seguy
@damienseguy
Joined Oct 25. 2023
33.3K
Exakat's profile

Exakat

Verified

PHP developer passionate about deep language knowledge, testing, static analysis, and sustainable it

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard