PAM (Pluggable Authentication Modules): Linux Authentication Framework
PAM is a Linux authentication framework that was backdoored by Velvet Ant to allow secret password access and credential theft. The group…
PAM is a Linux authentication framework that was backdoored by Velvet Ant to allow secret password access and credential theft. The group…
OpenSSH is a suite of secure networking utilities that was backdoored by Velvet Ant to log credentials and commands, with a hidden…
Operation Highland is a campaign by the China-linked Velvet Ant group that backdoored Linux PAM and OpenSSH components to maintain persistent access…
A hidden plugin installed by the attacker acts as a web shell, allowing remote command execution on the compromised server without authentication.
LiteLLM, an AI gateway, was backdoored in late March 2026. Its build pipeline installed a poisoned Trivy that stole publishing tokens, leading…
INFINITERED is custom malware deployed by UNC6508 that trojanizes REDCap system files. It hijacks the upgrade process to persist, harvests login credentials…
HellsUchecker is a backdoor delivered via EtherHiding and ClickFix campaigns, capable of executing files retrieved from C2 and reporting results back.
OpenSSH Server was installed on a Windows workstation by the attacker to enable key-based SSH access and reverse tunnels, providing a backdoor…
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors tampered with the official release channels…
ZenoX, a Brazilian cybersecurity company, found that certain username and password pairs were repeated across thousands of distinct IP addresses in the…