Threat actors are actively exploiting a critical directory-traversal vulnerability in Broadcom's VMware vCenter, tracked as CVE-2026-59310 (CVSS 9.8), to gain persistent remote…
reverse_ssh is an open-source tool used to establish SSH connections to threat actor-controlled infrastructure. It enables outbound connections, bypassing inbound security controls.…
The magic-login backdoor is a persistence module installed in the mu-plugins directory that allows unauthenticated administrative entry via a URL parameter targeting…
The backdoor used in the Alibaba supply chain attack targets Wukong, an enterprise collaboration application, by injecting malicious code to achieve persistence…
The backdoor used in the Alibaba supply chain attack targets Qoder, an enterprise collaboration application, by injecting malicious code to maintain persistence…
The final-stage payload is a complex backdoor equipped with comprehensive command execution, arbitrary file upload/download, host reconnaissance, payload staging, and lateral movement…
The final-stage backdoor in the Alibaba supply chain attack injects malicious code into DingTalk, a popular enterprise collaboration app, to maintain persistence…