Australian Cyber Security Centre (ACSC)
Australian agency that issued an alert about a global exploitation campaign targeting vulnerable CMS systems and plugins, including web shell deployment.
Australian agency that issued an alert about a global exploitation campaign targeting vulnerable CMS systems and plugins, including web shell deployment.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity vulnerabilities affecting iCagenda and Balbooa Forms extensions for Joomla to…
A vulnerability in the Ninja Forms WordPress plugin exploited in a global CMS campaign for web shell deployment.
A vulnerability in the WavePlayer WordPress plugin exploited in a global CMS campaign for web shell deployment.
A vulnerability in the WPBookit WordPress plugin exploited in a global CMS campaign for web shell deployment.
A vulnerability in the Breeze Cache WordPress plugin exploited in a global CMS campaign for web shell deployment.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…
SquareShell is a web shell deployed by UNK_MassTraction using a PHP gadget shell command after exploiting CVE-2025-49113 in Roundcube. It is accessible…
A previously exploited security flaw in BeyondTrust Remote Support and PRA products that allowed attackers to deploy web shells and backdoors.