<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Webshell</title><description>Cybersecurity articles tagged #Webshell on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-73570: Unauthenticated RCE in Zimbra ZCS Exploited</title><link>https://runtimerebel.com/blog/cve-2026-73570-unauthenticated-rce-in-zimbra-zcs-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-73570-unauthenticated-rce-in-zimbra-zcs-exploited</guid><description>Threat actors are actively exploiting CVE-2026-73570, an unauthenticated RCE flaw in Zimbra Collaboration Suite, to deploy web shells and exfiltrate sensitive data.</description><pubDate>Thu, 01 Oct 2026 03:05:44 GMT</pubDate><category>Zimbra</category><category>Webshell</category><category>Remote Code Execution</category><category>Data Exfiltration</category><category>CVE-2026-73570</category></item><item><title>CVE-2026-12569: Clop Exploits Windchill with Custom Web Shell</title><link>https://runtimerebel.com/blog/cve-2026-12569-clop-exploits-windchill-with-custom-web-shell</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-12569-clop-exploits-windchill-with-custom-web-shell</guid><description>Clop ransomware group exploited CVE-2026-12569 in PTC Windchill and FlexPLM servers, deploying a custom web shell for deep data theft. Patch immediately.</description><pubDate>Wed, 19 Aug 2026 00:40:12 GMT</pubDate><category>Clop</category><category>PTC Windchill</category><category>CVE-2026-12569</category><category>Webshell</category><category>Data Theft</category></item><item><title>BdThemes WordPress Plugin Supply Chain Attack Creates Rogue Admins</title><link>https://runtimerebel.com/blog/bdthemes-wordpress-plugin-supply-chain-attack-creates-rogue-admins</link><guid isPermaLink="true">https://runtimerebel.com/blog/bdthemes-wordpress-plugin-supply-chain-attack-creates-rogue-admins</guid><description>A supply chain attack on BdThemes WordPress plugins exploited an XSS vulnerability, creating stealthy rogue admin accounts and webshells.</description><pubDate>Tue, 11 Aug 2026 08:45:01 GMT</pubDate><category>WordPress</category><category>Supply Chain Attack</category><category>XSS</category><category>Webshell</category><category>BdThemes</category></item><item><title>WordPress Core RCE via CVE-2026-63030 — wp2shell Mitigation Guide</title><link>https://runtimerebel.com/blog/wordpress-core-rce-via-cve-2026-63030-wp2shell-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-core-rce-via-cve-2026-63030-wp2shell-mitigation-guide</guid><description>Attackers are exploiting critical wp2shell vulnerabilities in WordPress Core to deploy persistent webshells. Learn how to detect and secure your servers.</description><pubDate>Tue, 21 Jul 2026 17:23:43 GMT</pubDate><category>CVE-2026-63030</category><category>CVE-2026-60137</category><category>WordPress</category><category>Webshell</category><category>Wp2shell</category></item><item><title>OP-512: Analyzing the Custom Web Shell Framework Targeting Microsoft IIS</title><link>https://runtimerebel.com/blog/op-512-analyzing-the-custom-web-shell-framework-targeting-microsoft-iis</link><guid isPermaLink="true">https://runtimerebel.com/blog/op-512-analyzing-the-custom-web-shell-framework-targeting-microsoft-iis</guid><description>Security researchers have identified OP-512, a China-nexus threat cluster targeting Microsoft IIS servers with a bespoke web shell framework for espionage.</description><pubDate>Fri, 05 Jun 2026 16:54:33 GMT</pubDate><category>OP 512</category><category>Microsoft IIS</category><category>Webshell</category><category>Espionage</category><category>China Nexus</category></item><item><title>Scanning for EncystPHP Webshell on FreePBX Systems — Detection Guide</title><link>https://runtimerebel.com/blog/scanning-for-encystphp-webshell-on-freepbx-systems-detection-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/scanning-for-encystphp-webshell-on-freepbx-systems-detection-guide</guid><description>Attackers are actively scanning for the EncystPHP webshell, targeting vulnerable FreePBX systems to establish persistent access and execute remote commands.</description><pubDate>Mon, 13 Apr 2026 16:35:41 GMT</pubDate><category>EncystPHP</category><category>Freepbx</category><category>Webshell</category><category>PHP Malware</category><category>Threat Intel</category></item><item><title>CVE-2024-34102: PolyShell Exploits Target 56% of Magento Stores</title><link>https://runtimerebel.com/blog/cve-2024-34102-polyshell-exploits-target-56-of-magento-stores</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-34102-polyshell-exploits-target-56-of-magento-stores</guid><description>Attackers are aggressively exploiting the CosmicSting vulnerability (CVE-2024-34102) in Magento and Adobe Commerce stores using PolyShell polyglot web shells.</description><pubDate>Thu, 26 Mar 2026 00:39:42 GMT</pubDate><category>CVE-2024-34102</category><category>Magento</category><category>Adobe Commerce</category><category>CosmicSting</category><category>PolyShell</category><category>Webshell</category></item><item><title>900+ Sangoma FreePBX Servers Compromised via Web Shell Exploitation</title><link>https://runtimerebel.com/blog/900-sangoma-freepbx-servers-compromised-via-web-shell-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/900-sangoma-freepbx-servers-compromised-via-web-shell-exploitation</guid><description>Over 900 Sangoma FreePBX instances are currently infected with web shells following a command injection campaign first observed in late 2025.</description><pubDate>Fri, 27 Feb 2026 20:11:30 GMT</pubDate><category>Sangoma</category><category>Freepbx</category><category>Webshell</category><category>Command Injection</category><category>Shadowserver</category><category>Asterisk</category></item></channel></rss>