Skip to main content

Tag: php web shell

2 articles

Network appliance sits idle in data center with blurred laptop screen in background.

F5 BIG-IP Malware Exploits Memory to Evade Detection

Sophos has uncovered a sneaky malware exploit in F5 BIG-IP systems that hides a PHP web shell in memory, evading detection by not leaving a digital footprint on disk. This stealthy technique injects the web shell into specific PHP scripts, allowing hackers to carry out remote code execution without being caught.

Analyst 207
WordPress admin dashboard on a laptop screen with a cityscape background and office items nearby.

BdThemes Plugins Targeted in Supply Chain Attack

A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

Analyst 207