VShell Command-and-Control Listener
A command-and-control listener found running on the attacker's staging server alongside the Hermes agent tooling.
A command-and-control listener found running on the attacker's staging server alongside the Hermes agent tooling.
An attacker installed the open-source Hermes AI assistant on a rented server, disabled its permission-requesting YOLO mode, and directed it at Thailand's…
This week's cybersecurity landscape is marked by a series of critical threats and vulnerabilities. Progress has urged ShareFile customers to shut down…
SHELLSTORM is a large-scale operation that exploited 27 CVEs in WordPress plugins to deploy web shells on over 1.4 million domains. The…
A cybercrime crew left its server exposed for three weeks, revealing the inner workings of a mass site-hacking operation tracked as WP-SHELLSTORM.…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…
UNK_MassTraction is a suspected China-aligned threat activity cluster first detected by Proofpoint in May 2026. It targets physics and engineering departments at…
A suspected Chinese state group linked by Sysdig to the SNOWLIGHT-to-VShell toolchain in April 2025. The same tools were used by WP-SHELLSTORM,…
VShell was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…