Skip to main content

Tag: web shell

6 articles

Rows of computer servers and networking equipment in a data center, with a Citrix NetScaler appliance prominently displayed…

Citrix NetScaler Flaw Exploited for Root Access, Web Shell Deployment

Security experts have uncovered a critical Citrix NetScaler flaw, CVE-2026-88772, that's being exploited to gain root access and deploy web shells, with attackers targeting ADC and Gateway appliances worldwide. This severe vulnerability, scoring 9.5 on the CVSS scale, allows for a devastating memory overflow that bypasses authentication and hands over total control.

Analyst 207
WordPress website backend interface on a laptop screen in a workspace.

Compromised Plugin Backdoors 1,500 WordPress Sites

A malicious update to the WordPress plugin Admin Menu Editor Pro infected around 1,500 sites with a backdoor, after hackers compromised the plugin's update server and uploaded a trojanized version. The attackers even created a hidden user account and installed a web shell on affected sites.

Analyst 207
Brightly-lit industrial control system terminal on a rack in a factory setting.

Clop Ransomware Operation Exploits Windchill Flaw with Custom Web Shell

The Clop ransomware operation has exploited a critical flaw in PTC Windchill and FlexPLM servers, deploying a custom web shell that allows for easy credential theft and massive data exfiltration. This sneaky move gives attackers a direct path to sensitive data, with no extra tools needed.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit corporate server room.

Spirals Ransomware Encrypts Network in Record Time

In a lightning-fast attack, the newly identified Spirals ransomware gang compromised a network and encrypted its entire system in under 24 hours, showcasing an alarming level of speed and sophistication. The attack began with a simple vulnerability - an exposed IIS server - which allowed hackers to upload a web shell and rapidly escalate their privileges.

Analyst 207
Industrial control systems and server equipment in a brightly-lit manufacturing setting.

CISA Flags Exploited PTC Windchill Flaw Amid Web Shell Attacks

PTC has confirmed that attackers are exploiting a high-severity flaw, CVE-2026-12569, in its Windchill software to drop malicious web shells on vulnerable systems, allowing them to execute arbitrary code remotely. The company has reported heightened threat activity, urging users to take immediate action to protect themselves.

Analyst 207
Server room with rows of equipment and a blurred laptop screen in the foreground.

Hackers Exploit KnowledgeDeliver Flaw to Install Web Shells

Hackers have exploited a critical flaw in KnowledgeDeliver, using it as a zero-day to sneakily install a powerful .NET web shell called Godzilla on vulnerable servers. This sneaky attack was made possible by a deserialization vulnerability, CVE-2026-5426, that allowed threat actors to execute code at the operating-system level.

Analyst 207