< ciso
brief />
Tag Banner

All news with #web shell tag

55 articles

Citrix NetScaler exploitation drops web shells, steals configs

🛡️ LevelBlue observed threat actors exploiting a critical pre-auth command injection in Citrix NetScaler ADC and NetScaler Gateway to deploy web shells and exfiltrate configuration data. The activity weaponizes CVE-2026-88771 and included attacker-supplied authentication strings, payload retrieval via curl/wget, and second-stage scripts that establish reverse shells, create privileged accounts, and upload archived configs. The incidents follow recent disclosures of CVE-2026-88771 and CVE-2026-88772 amid active exploitation reports.
read more →

Zimbra RCE Exploited to Deploy Web Shells and Steal Mail

🛡️ Microsoft found threat actors exploiting CVE-2026-73570 in Zimbra Collaboration Suite to deploy JSP web shells, establish reverse shells, escalate privileges, and exfiltrate mailbox data. The unauthenticated command injection flaw affected systems with SNMP notifications enabled and the optional zimbra-snmp package installed, and was patched in Zimbra 10.1.20 in July 2026. Attackers used varied persistence and lateral-movement techniques, including systemd services, cron jobs, SSH identity reuse, and custom Go-based tooling to harvest credentials and export mailbox databases. Organizations are urged to patch, remove the zimbra-snmp package if necessary, restrict SNMP/SMTP access, rotate secrets, and hunt for web shells and other artifacts.
read more →

Attackers Bypass WAFs to Exploit Oracle PeopleSoft

🛡️ Google warns of renewed mass exploitation of a critical Oracle PeopleSoft flaw (CVE-2026-35273, CVSS 9.8) by activity linked to ShinyHunters/UNC6240. The campaign weaponizes a modified exploit that URL-encodes the character "P" to bypass WAF rules, targeting multiple sectors globally and deploying web shells, trojanized installers, and backdoors. Affected organizations are urged to apply patches, disable or remove the PSEMHUB component, inspect logs and web directories, rotate credentials, and hunt for signs of data exfiltration and persistence.
read more →

Critical RCE in WooCommerce Wholesale Lead Capture

🛡️ Wordfence reports attackers uploading PHP webshells via a critical flaw in the premium WooCommerce Wholesale Lead Capture plugin. The vulnerability (CVE-2026-27540) was patched in version 2.0.3.2 on February 20, but exploitation attempts—over 100,000 blocked—continued months later. Site owners should update immediately, scan uploads directories, and check access logs for the vulnerable AJAX action.
read more →

Stealth rootkit targets F5 BIG‑IP APM webtops

🔒 Sophos analyzed a Linux rootkit that hides web shells inside compromised F5 BIG‑IP APM environments by modifying PHP content in memory rather than writing files to disk. The implant hooks Apache’s PHP-loading process, targets specific BIG‑IP APM PHP files, and serves altered in‑memory versions so file‑integrity checks appear normal. It also provides a secondary access channel via a local UNIX socket, complicating detection and response.
read more →

F5 BIG-IP APM in-memory PHP web shell analysis

🛡️ Sophos on September 7 detailed malware targeting F5 BIG-IP Access Policy Manager that injects a PHP web shell into memory rather than writing it to disk. The malware hooks Apache and libphp, rewrites file-handling calls, and places a web shell in-memory when specific .php3 scripts are loaded, evading file-based detection. Related installer components modify /usr/sbin/httpd and other binaries and may persist through install images, with links to CVE-2025-53521 and mitigation guidance.
read more →

Critical Elementor Pro flaw exploited to hijack sites

⚠️ A critical vulnerability (CVE-2026-32475) in Elementor Pro was patched on August 19 after active exploitation that uploads webshells and enables remote command execution. The flaw affects versions 4.2.1 and earlier and abuses faulty file-upload array validation in forms with a File Upload field. Wordfence blocked nearly 200,000 attempts and advises immediate upgrade to 4.2.2 and checks for rogue PHP files in uploads.
read more →

Cl0p affiliates exploit PTC Windchill and FlexPLM flaws

🔒 Threat actors tied to the Cl0p group are exploiting internet-exposed PTC Windchill and FlexPLM deployments to achieve unauthenticated remote code execution and deploy JSP web shells. According to a coordinated advisory from Ransom-ISAC, eCrime.ch, and DEFUSED, attackers chain a FlexPLM WSDL information disclosure with a Windchill login servlet flaw (CVE-2026-12569) to stage data theft and double extortion. Targets include manufacturing, automotive, aerospace, and retail organizations, with multiple IoCs published by PTC.
read more →

Critical wp2shell WordPress flaws exploited widely

🔒 Hackers are actively exploiting the wp2shell vulnerability chain (CVE-2026-63030 and CVE-2026-60137) in WordPress Core to install persistent webshells and malicious plugins. The exploit abuses the REST API batch-processing feature to achieve unauthenticated remote code execution. WordPress released emergency patches (7.0.2, 6.9.5, 6.8.6) and forced automatic updates while researchers report mass scanning, plugin abuse, and backdoor deployments.
read more →

Widespread wp2shell WordPress RCE and exploitation

🛡️ Attackers are actively exploiting two critical WordPress flaws, CVE-2026-63030 and CVE-2026-60137, together dubbed wp2shell, enabling unauthenticated remote code execution on default installations. Researchers report rapid abuse following public exploit release, extensive scanning, and post-exploitation activity including malicious plugin uploads, web shells, and creation of backdoor admin accounts. Organizations are urged to patch and inspect sites for indicators of compromise.
read more →

PhantomEnigma Abuses Brazilian Government Sites

🛡️ ANY.RUN uncovered an active PhantomEnigma campaign that hijacked over 20 Brazilian government websites to deliver malware. The operation used authenticated emails, compromised mailboxes, and trusted .gov.br hosts to redirect victims to malicious installers and a modular index.js backdoor. Researchers linked hundreds of sandbox sessions to reveal the campaign’s infrastructure, delivery chains, and detection guidance.
read more →

Weekly recap: ShareFile warning and broad threats

🛡️ Progress urged ShareFile customers to shut down Windows Storage Zone Controllers amid a credible external threat, temporarily disabling access while investigating; there are no signs of account or data compromise. Other top stories include a critical Zimbra XSS patch, a compromised Jscrambler npm package distributing a multi-platform Rust stealer, and Microsoft detailing the destructive GigaWiper backdoor. Large-scale web shell operations (SHELLSTORM), HalluSquatting attacks against AI assistants, and many actively exploited CVEs round out the week's threats.
read more →

Australia warns of widespread CMS exploitation

🛡️ The Australian Cyber Security Centre (ACSC) has warned of a large-scale campaign scanning and exploiting vulnerabilities in content management systems worldwide, impacting many SMBs in Australia. The actors deploy webshells via flaws allowing unauthenticated file upload, remote code execution, SSRF or deserialization, affecting products like WordPress, Joomla, Craft CMS and others. The ACSC advises inspecting servers for compromise, isolating and remediating infected hosts, patching vulnerable systems, and restoring from known-good backups.
read more →

Australia alerts on global CMS exploitation campaign

⚠️ The Australian Cyber Security Centre (ACSC) warned of a global campaign exploiting vulnerabilities in multiple content management systems and plugins, with many Australian small and medium businesses affected. Threat actors are deploying webshells to maintain persistence, steal credentials, and escalate access. The campaign targets several CMS platforms and specific plugins, and the ACSC cautions that AI may be used to accelerate attacks. Administrators are urged to apply patches, remove unused components, and tighten web-server protections.
read more →

Exposed server reveals mass WordPress backdoor campaign

🔍 Researchers found a cybercrime crew's unsecured server containing tools, logs, and target lists that revealed a large-scale webshell access brokerage dubbed WP-SHELLSTORM. The exposed files showed automated scanners exploiting known WordPress and Joomla plugin flaws, notably the Breeze caching and Joomla JCE bugs, and included lists naming over 1.4 million domains. Two security teams analyzed the leaked repository and measured confirmed compromises in the thousands, while also tracing earlier credential-stealing activity against corporate Nacos instances. The leak underscores how public exploits and poor operator hygiene enabled mass compromise at scale.
read more →

Compromised JavaScript in Popular WordPress Plugins

🛡️ An attacker served tampered JavaScript used by PushEngage, OptinMonster, and TrustPulse, executing only when a logged-in WordPress administrator loaded the files. The malicious code created an attacker-controlled admin account, installed a hidden plugin backdoor providing remote code execution, and exfiltrated credentials to a fake tidio[.]cc domain. Sansec disclosed the campaign on June 13; PushEngage confirmed exposures that lasted longer than the brief windows seen for the other plugins. Site owners should treat any site that loaded the affected scripts during the window as compromised and perform server-side scans and credential rotations immediately.
read more →

KnowledgeDeliver zero-day enables web shell installs

🛡️ Mandiant found attackers exploited a critical unauthenticated deserialization flaw (CVE-2026-5426) in KnowledgeDeliver LMS to deliver the Godzilla web shell. The issue stemmed from a shared hardcoded ASP.NET machineKey across customer deployments, allowing signed malicious ViewState payloads and remote code execution. Compromised installations were used to push fake installers, deploy Cobalt Strike beacons, and modify site scripts to load attacker-controlled payloads.
read more →

KnowledgeDeliver LMS ViewState Flaw Enables Web Shell

🛡️ A high-severity ASP.NET ViewState deserialization flaw (CVE-2026-5426) in Digital Knowledge KnowledgeDeliver was exploited as a zero-day to deploy the Godzilla web shell and later Cobalt Strike Beacon. Google Mandiant and GTIG found attackers abused hard-coded machineKey values in vendor-supplied web.config files to craft malicious __VIEWSTATE payloads, gaining unauthenticated RCE on affected instances prior to February 24, 2026. The intrusion included file system escalation, tampering with site JavaScript to deliver a fake security plugin, and a targeted encrypted payload named for the victim organization.
read more →

Ongoing Exploitation of Cisco Catalyst SD-WAN Systems

🔔 Talos reports active, in-the-wild exploitation of multiple Cisco Catalyst SD‑WAN vulnerabilities, including CVE-2026-20182 and a chained set (CVE-2026-20133, CVE-2026-20128, CVE-2026-20122) that enable unauthorized access, persistent webshell deployment, and privilege escalation. The threat cluster UAT-8616 and other adversaries have deployed JSP webshells such as XenShell, Godzilla, and Behinder and have installed miners, C2 implants, and reconnaissance and tunneling tools post-compromise. Customers should urgently apply Cisco updates, follow Talos detection guidance and Snort/ClamAV signatures, and engage TAC for incident support and remediation.
read more →

cPanel Vulnerability Exposes Hosting Supply Chain Risks

🔒 A recently disclosed cPanel vulnerability, tracked as CVE-2026-41940, is being exploited at scale to deploy backdoors, plant SSH keys, steal credentials, and compromise hosting systems. Researchers at XLab link much of the activity to a long-running group called Mr_Rot13, with automated scans from over 2,000 attacker IPs observed after the late-April disclosure. The incident highlights weak visibility into hosting control planes and urges organizations to treat exposed control panels as high-priority incidents: patch immediately, rotate credentials, hunt for webshells, and review logs for persistence.
read more →