KNUCKLEBALL: Python Script Used in SonicWall Exploitation
KNUCKLEBALL is a Python script deployed by threat actors to launch Suo5, an open-source HTTP proxy, and a Behinder-like web shell named…
KNUCKLEBALL is a Python script deployed by threat actors to launch Suo5, an open-source HTTP proxy, and a Behinder-like web shell named…
ORANGETAIL is a Behinder-like custom Java web shell used by threat actors to maintain persistent access on compromised SonicWall SMA 1000 appliances.…
A previously undocumented threat actor, tracked as UTA0533 by Volexity, exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series…
This week's cybersecurity landscape is marked by a series of critical threats and vulnerabilities. Progress has urged ShareFile customers to shut down…
SHELLSTORM is a large-scale operation that exploited 27 CVEs in WordPress plugins to deploy web shells on over 1.4 million domains. The…
A vulnerability in the Sneeit Framework exploited in a global CMS campaign for web shell deployment.
A vulnerability in the Gravity Forms WordPress plugin exploited in a global CMS campaign for web shell deployment.
A vulnerability in Craft CMS exploited in a global CMS campaign for web shell deployment.
A vulnerability in MaxSite CMS exploited in a global CMS campaign for web shell deployment.
A vulnerability in MetInfo CMS exploited in a global CMS campaign for web shell deployment.