< ciso
brief />
Tag Banner

All news with #web shell tag

48 articles

Cl0p affiliates exploit PTC Windchill and FlexPLM flaws

πŸ”’ Threat actors tied to the Cl0p group are exploiting internet-exposed PTC Windchill and FlexPLM deployments to achieve unauthenticated remote code execution and deploy JSP web shells. According to a coordinated advisory from Ransom-ISAC, eCrime.ch, and DEFUSED, attackers chain a FlexPLM WSDL information disclosure with a Windchill login servlet flaw (CVE-2026-12569) to stage data theft and double extortion. Targets include manufacturing, automotive, aerospace, and retail organizations, with multiple IoCs published by PTC.
read more β†’

Critical wp2shell WordPress flaws exploited widely

πŸ”’ Hackers are actively exploiting the wp2shell vulnerability chain (CVE-2026-63030 and CVE-2026-60137) in WordPress Core to install persistent webshells and malicious plugins. The exploit abuses the REST API batch-processing feature to achieve unauthenticated remote code execution. WordPress released emergency patches (7.0.2, 6.9.5, 6.8.6) and forced automatic updates while researchers report mass scanning, plugin abuse, and backdoor deployments.
read more β†’

Widespread wp2shell WordPress RCE and exploitation

πŸ›‘οΈ Attackers are actively exploiting two critical WordPress flaws, CVE-2026-63030 and CVE-2026-60137, together dubbed wp2shell, enabling unauthenticated remote code execution on default installations. Researchers report rapid abuse following public exploit release, extensive scanning, and post-exploitation activity including malicious plugin uploads, web shells, and creation of backdoor admin accounts. Organizations are urged to patch and inspect sites for indicators of compromise.
read more β†’

PhantomEnigma Abuses Brazilian Government Sites

πŸ›‘οΈ ANY.RUN uncovered an active PhantomEnigma campaign that hijacked over 20 Brazilian government websites to deliver malware. The operation used authenticated emails, compromised mailboxes, and trusted .gov.br hosts to redirect victims to malicious installers and a modular index.js backdoor. Researchers linked hundreds of sandbox sessions to reveal the campaign’s infrastructure, delivery chains, and detection guidance.
read more β†’

Weekly recap: ShareFile warning and broad threats

πŸ›‘οΈ Progress urged ShareFile customers to shut down Windows Storage Zone Controllers amid a credible external threat, temporarily disabling access while investigating; there are no signs of account or data compromise. Other top stories include a critical Zimbra XSS patch, a compromised Jscrambler npm package distributing a multi-platform Rust stealer, and Microsoft detailing the destructive GigaWiper backdoor. Large-scale web shell operations (SHELLSTORM), HalluSquatting attacks against AI assistants, and many actively exploited CVEs round out the week's threats.
read more β†’

Australia warns of widespread CMS exploitation

πŸ›‘οΈ The Australian Cyber Security Centre (ACSC) has warned of a large-scale campaign scanning and exploiting vulnerabilities in content management systems worldwide, impacting many SMBs in Australia. The actors deploy webshells via flaws allowing unauthenticated file upload, remote code execution, SSRF or deserialization, affecting products like WordPress, Joomla, Craft CMS and others. The ACSC advises inspecting servers for compromise, isolating and remediating infected hosts, patching vulnerable systems, and restoring from known-good backups.
read more β†’

Australia alerts on global CMS exploitation campaign

⚠️ The Australian Cyber Security Centre (ACSC) warned of a global campaign exploiting vulnerabilities in multiple content management systems and plugins, with many Australian small and medium businesses affected. Threat actors are deploying webshells to maintain persistence, steal credentials, and escalate access. The campaign targets several CMS platforms and specific plugins, and the ACSC cautions that AI may be used to accelerate attacks. Administrators are urged to apply patches, remove unused components, and tighten web-server protections.
read more β†’

Exposed server reveals mass WordPress backdoor campaign

πŸ” Researchers found a cybercrime crew's unsecured server containing tools, logs, and target lists that revealed a large-scale webshell access brokerage dubbed WP-SHELLSTORM. The exposed files showed automated scanners exploiting known WordPress and Joomla plugin flaws, notably the Breeze caching and Joomla JCE bugs, and included lists naming over 1.4 million domains. Two security teams analyzed the leaked repository and measured confirmed compromises in the thousands, while also tracing earlier credential-stealing activity against corporate Nacos instances. The leak underscores how public exploits and poor operator hygiene enabled mass compromise at scale.
read more β†’

Compromised JavaScript in Popular WordPress Plugins

πŸ›‘οΈ An attacker served tampered JavaScript used by PushEngage, OptinMonster, and TrustPulse, executing only when a logged-in WordPress administrator loaded the files. The malicious code created an attacker-controlled admin account, installed a hidden plugin backdoor providing remote code execution, and exfiltrated credentials to a fake tidio[.]cc domain. Sansec disclosed the campaign on June 13; PushEngage confirmed exposures that lasted longer than the brief windows seen for the other plugins. Site owners should treat any site that loaded the affected scripts during the window as compromised and perform server-side scans and credential rotations immediately.
read more β†’

KnowledgeDeliver zero-day enables web shell installs

πŸ›‘οΈ Mandiant found attackers exploited a critical unauthenticated deserialization flaw (CVE-2026-5426) in KnowledgeDeliver LMS to deliver the Godzilla web shell. The issue stemmed from a shared hardcoded ASP.NET machineKey across customer deployments, allowing signed malicious ViewState payloads and remote code execution. Compromised installations were used to push fake installers, deploy Cobalt Strike beacons, and modify site scripts to load attacker-controlled payloads.
read more β†’

KnowledgeDeliver LMS ViewState Flaw Enables Web Shell

πŸ›‘οΈ A high-severity ASP.NET ViewState deserialization flaw (CVE-2026-5426) in Digital Knowledge KnowledgeDeliver was exploited as a zero-day to deploy the Godzilla web shell and later Cobalt Strike Beacon. Google Mandiant and GTIG found attackers abused hard-coded machineKey values in vendor-supplied web.config files to craft malicious __VIEWSTATE payloads, gaining unauthenticated RCE on affected instances prior to February 24, 2026. The intrusion included file system escalation, tampering with site JavaScript to deliver a fake security plugin, and a targeted encrypted payload named for the victim organization.
read more β†’

Ongoing Exploitation of Cisco Catalyst SD-WAN Systems

πŸ”” Talos reports active, in-the-wild exploitation of multiple Cisco Catalyst SD‑WAN vulnerabilities, including CVE-2026-20182 and a chained set (CVE-2026-20133, CVE-2026-20128, CVE-2026-20122) that enable unauthorized access, persistent webshell deployment, and privilege escalation. The threat cluster UAT-8616 and other adversaries have deployed JSP webshells such as XenShell, Godzilla, and Behinder and have installed miners, C2 implants, and reconnaissance and tunneling tools post-compromise. Customers should urgently apply Cisco updates, follow Talos detection guidance and Snort/ClamAV signatures, and engage TAC for incident support and remediation.
read more β†’

cPanel Vulnerability Exposes Hosting Supply Chain Risks

πŸ”’ A recently disclosed cPanel vulnerability, tracked as CVE-2026-41940, is being exploited at scale to deploy backdoors, plant SSH keys, steal credentials, and compromise hosting systems. Researchers at XLab link much of the activity to a long-running group called Mr_Rot13, with automated scans from over 2,000 attacker IPs observed after the late-April disclosure. The incident highlights weak visibility into hosting control planes and urges organizations to treat exposed control panels as high-priority incidents: patch immediately, rotate credentials, hunt for webshells, and review logs for persistence.
read more β†’

China-Linked Hackers Target Asian Governments, Journalists

πŸ”’ Trend Micro disclosed a China-aligned espionage campaign tracked as SHADOW-EARTH-053 that exploited N-day flaws in internet-facing Microsoft Exchange and IIS servers to deploy web shells (including Godzilla) and persistently stage the ShadowPad backdoor via DLL sideloading and AnyDesk. Targets spanned Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan and one NATO member, Poland. Citizen Lab separately reported two phishing clusters, GLITTER CARP and SEQUIN CARP, impersonating journalists and tech/security alerts to harvest credentials and OAuth tokens. Researchers recommend urgent patching, virtual patching with WAF/IPS, and heightened monitoring for tunneling tools, web shells, and lateral-movement artifacts.
read more β†’

Popular WordPress Redirect Plugin Hid Dormant Backdoor

πŸ›‘οΈ The Quick Page/Post Redirect WordPress plugin, installed on more than 70,000 sites, contained a hidden backdoor introduced through a malicious self-update mechanism in versions 5.2.1 and 5.2.2. Researcher Austin Ginder discovered the issue after multiple infections on his Anchor hosting fleet led to a security alert; WordPress.org has temporarily pulled the plugin pending review. A tampered 5.2.3 build, delivered from an external anadnet[.]com server, added a passive backdoor that only triggers for logged-out users and appears to have been used for cloaked SEO spam. Impacted sites should uninstall the plugin and replace it with a clean copy of version 5.2.4 from WordPress.org when it is available.
read more β†’

Microsoft: Cookie-Controlled PHP Web Shells on Linux

πŸͺ Microsoft Defender Security Research Team warns that threat actors are increasingly using HTTP cookies as a covert control channel for PHP-based web shells on Linux servers. Instead of passing commands via URL parameters or request bodies, attackers gate execution and convey instructions through values accessible in the PHP $_COOKIE superglobal. This technique keeps malicious code dormant during normal application activity and activates only when specific cookie values are present, reducing observable indicators. Microsoft observed multiple obfuscated loaders and a cron-driven 'self-healing' persistence model that recreates loaders and minimizes forensic visibility.
read more β†’

Cookie-Controlled PHP Webshell Tradecraft for Linux Hosting

πŸ”’ Threat actors are increasingly abusing HTTP cookies as a stealthy control channel for PHP webshells on Linux hosting platforms. By gating execution on specific cookie values, attackers keep loaders dormant during normal traffic and activate functionality only when exact cookie conditions are met. Variants range from multi-stage loaders that reconstruct functions at runtime to single-file interactive shells, often using base64 reconstruction and layered obfuscation to evade detection. Review Microsoft Defender guidance to detect, hunt, and mitigate these threats.
read more β†’

CL-UNK-1068 Targets Critical Sectors Across Asia Region

πŸ›‘οΈ Unit 42 details CL-UNK-1068, a cluster observed since 2020 that targets aviation, energy, government, law enforcement, pharmaceutical, technology and telecommunications organizations across South, Southeast and East Asia. The actor deploys web shells (GodZilla, an AntSword variant), performs DLL side-loading with legitimate python binaries, and uses custom scanners and tunneling tools such as FRP. Exfiltration focuses on web configuration files, databases and credentials; defenders should prioritize detections for behavioral anomalies over static IOCs.
read more β†’

Over 900 FreePBX Instances Remain Infected with Web Shells

⚠ The Shadowserver Foundation reports that more than 900 FreePBX instances remain infected with web shells after exploitation of the CVE-2025-64328 post-auth command injection flaw. The vulnerability (CVSS 8.6) affects versions >=17.0.2.36 and was fixed in 17.0.3; recommended mitigations include restricting access to the Administration Control Panel, updating the filestore module, and applying available updates. Fortinet links active exploitation since December 2025 to the INJ3CTOR3 actor delivering an EncystPHP web shell that enables arbitrary shell execution as the asterisk user and can initiate outbound call activity via compromised PBX instances.
read more β†’

Critical BeyondTrust Flaw Used to Deploy Web Shells

πŸ”’ Palo Alto Networks Unit 42 reports active exploitation of a critical sanitization bug in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA), tracked as CVE-2026-1731 (CVSS 9.9), that allows OS command execution via the thin-scc-wrapper WebSocket interface. Threat actors have used the flaw for reconnaissance, deploying web shells and backdoors (including VShell and Spark RAT), lateral movement, and data theft. Multiple sectors across several countries are affected, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog.
read more β†’