Tag: web shell
6 articles

Citrix NetScaler Flaw Exploited for Root Access, Web Shell Deployment
Security experts have uncovered a critical Citrix NetScaler flaw, CVE-2026-88772, that's being exploited to gain root access and deploy web shells, with attackers targeting ADC and Gateway appliances worldwide. This severe vulnerability, scoring 9.5 on the CVSS scale, allows for a devastating memory overflow that bypasses authentication and hands over total control.

Compromised Plugin Backdoors 1,500 WordPress Sites
A malicious update to the WordPress plugin Admin Menu Editor Pro infected around 1,500 sites with a backdoor, after hackers compromised the plugin's update server and uploaded a trojanized version. The attackers even created a hidden user account and installed a web shell on affected sites.

Clop Ransomware Operation Exploits Windchill Flaw with Custom Web Shell
The Clop ransomware operation has exploited a critical flaw in PTC Windchill and FlexPLM servers, deploying a custom web shell that allows for easy credential theft and massive data exfiltration. This sneaky move gives attackers a direct path to sensitive data, with no extra tools needed.

Spirals Ransomware Encrypts Network in Record Time
In a lightning-fast attack, the newly identified Spirals ransomware gang compromised a network and encrypted its entire system in under 24 hours, showcasing an alarming level of speed and sophistication. The attack began with a simple vulnerability - an exposed IIS server - which allowed hackers to upload a web shell and rapidly escalate their privileges.

CISA Flags Exploited PTC Windchill Flaw Amid Web Shell Attacks
PTC has confirmed that attackers are exploiting a high-severity flaw, CVE-2026-12569, in its Windchill software to drop malicious web shells on vulnerable systems, allowing them to execute arbitrary code remotely. The company has reported heightened threat activity, urging users to take immediate action to protect themselves.

Hackers Exploit KnowledgeDeliver Flaw to Install Web Shells
Hackers have exploited a critical flaw in KnowledgeDeliver, using it as a zero-day to sneakily install a powerful .NET web shell called Godzilla on vulnerable servers. This sneaky attack was made possible by a deserialization vulnerability, CVE-2026-5426, that allowed threat actors to execute code at the operating-system level.