A company web server is initiating outbound traffic to a low-reputation public IP on a non-standard pat. The web server presents an unauthenticated page to clients who upload images the company. An analyst observes a suspicious process running on the server that was not created by the company development team. Which of the following is the most likely explanation for this security incident?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion