Web Shell is a mitre_attack tracked across 13 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed November 1, 2025; most recent activity June 17, 2026.
UAT-7290, a China-linked advanced persistent threat group, has been active since at least 2022, focusing on espionage against telecommunications providers in South Asia. The group employs a range of Linux and Windows…
A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and…
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…
Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…
Security researchers have identified a remote code execution (RCE) vulnerability in the .NET framework that impacts various enterprise applications. Piotr Bazydło from watchTowr presented these findings at Black Hat…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the OpenPLC ScadaBR vulnerability, tracked as CVE-2021-26829, to its Known Exploited Vulnerabilities catalog after confirming active…
CISA, in collaboration with the NSA and Canada's Cyber Security Centre, has issued a warning about Chinese hackers using BrickStorm malware to backdoor VMware vSphere servers. The attacks primarily affect government and…
Hackers are actively exploiting a vulnerability in Cisco IOS XE to deploy the BADCANDY web shell. This attack targets devices running the affected software, allowing unauthorized access and control. The ongoing…
Hackers are actively exploiting a vulnerability in Cisco IOS XE to deploy the BADCANDY web shell. This exploitation is occurring in the wild, affecting systems running the vulnerable software. The BADCANDY web shell…