Skip to main content
← All Articles

Tag

#Webshell

8 articles

Advertisement

CVE-2026-73570: Unauthenticated RCE in Zimbra ZCS Exploited
CRITICAL
Vulnerabilities

CVE-2026-73570: Unauthenticated RCE in Zimbra ZCS Exploited

Threat actors are actively exploiting CVE-2026-73570, an unauthenticated RCE flaw in Zimbra Collaboration Suite, to deploy web shells and exfiltrate sensitive data.

Runtime Rebel Intel
4 min read · Oct 1, 2026
CRITICAL
Vulnerabilities

CVE-2026-12569: Clop Exploits Windchill with Custom Web Shell

Clop ransomware group exploited CVE-2026-12569 in PTC Windchill and FlexPLM servers, deploying a custom web shell for deep data theft. Patch immediately.

Runtime Rebel Intel
4 min read · Aug 19, 2026
MEDIUM
Supply Chain

BdThemes WordPress Plugin Supply Chain Attack Creates Rogue Admins

A supply chain attack on BdThemes WordPress plugins exploited an XSS vulnerability, creating stealthy rogue admin accounts and webshells.

Runtime Rebel Intel
5 min read · Aug 11, 2026
CRITICAL
Vulnerabilities

WordPress Core RCE via CVE-2026-63030 — wp2shell Mitigation Guide

Attackers are exploiting critical wp2shell vulnerabilities in WordPress Core to deploy persistent webshells. Learn how to detect and secure your servers.

Runtime Rebel Intel
3 min read · Jul 21, 2026
OP-512: Analyzing the Custom Web Shell Framework Targeting Microsoft IIS
HIGH
Threat Intel

OP-512: Analyzing the Custom Web Shell Framework Targeting Microsoft IIS

Security researchers have identified OP-512, a China-nexus threat cluster targeting Microsoft IIS servers with a bespoke web shell framework for espionage.

Runtime Rebel Intel
4 min read · Jun 5, 2026
HIGH
Malware

Scanning for EncystPHP Webshell on FreePBX Systems — Detection Guide

Attackers are actively scanning for the EncystPHP webshell, targeting vulnerable FreePBX systems to establish persistent access and execute remote commands.

Runtime Rebel Intel
4 min read · Apr 13, 2026

Advertisement

HIGH
Vulnerabilities

CVE-2024-34102: PolyShell Exploits Target 56% of Magento Stores

Attackers are aggressively exploiting the CosmicSting vulnerability (CVE-2024-34102) in Magento and Adobe Commerce stores using PolyShell polyglot web shells.

Runtime Rebel Intel
3 min read · Mar 26, 2026
900+ Sangoma FreePBX Servers Compromised via Web Shell Exploitation
HIGH
Vulnerabilities

900+ Sangoma FreePBX Servers Compromised via Web Shell Exploitation

Over 900 Sangoma FreePBX instances are currently infected with web shells following a command injection campaign first observed in late 2025.

Runtime Rebel Intel
4 min read · Feb 27, 2026