Clop Ransomware Group’s Custom Web Shell Tactics
Clop (aka Cl0p) is a prolific ransomware group known for mass exploitation of file transfer and PLM software. They deploy custom web…
Clop (aka Cl0p) is a prolific ransomware group known for mass exploitation of file transfer and PLM software. They deploy custom web…
A vulnerability in the Ninja Forms WordPress plugin exploited in a global CMS campaign for web shell deployment.
A vulnerability in the WavePlayer WordPress plugin exploited in a global CMS campaign for web shell deployment.
A vulnerability in the WPBookit WordPress plugin exploited in a global CMS campaign for web shell deployment.
A vulnerability in the Breeze Cache WordPress plugin exploited in a global CMS campaign for web shell deployment.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…
SquareShell is a web shell deployed by UNK_MassTraction using a PHP gadget shell command after exploiting CVE-2025-49113 in Roundcube. It is accessible…
A previously exploited security flaw in BeyondTrust Remote Support and PRA products that allowed attackers to deploy web shells and backdoors.
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks…