Skip to main content

Glossary

Payload

The part of malware or an exploit that carries out its actual malicious action — such as encrypting files, opening a backdoor, or exfiltrating data — as distinct from the delivery mechanism, such as a phishing attachment, that gets it onto the target system.

Recent coverage mentioning Payload

ClearFake WebDAV Delivers Stealers & RATs to Ukrainian Gov
HIGH
Malware

ClearFake WebDAV Delivers Stealers & RATs to Ukrainian Gov

ClearFake WebDAV infection chain leverages Cloudflare Workers and BNB Smart Chain to deploy Amatera stealer, ZigCryptoStealer, and NetSupport Manager.

Runtime Rebel Intel
4 min read · Sep 8, 2026
Ransomware Groups Exploit Insiders: A Shifting Threat Landscape
HIGH
Threat Intel

Ransomware Groups Exploit Insiders: A Shifting Threat Landscape

Ransomware groups are increasingly recruiting insiders to bypass advanced security, posing a significant threat to organizational data and operations.

Runtime Rebel Intel
3 min read · Sep 6, 2026
MEDIUM
Malware

ClickFix Payloads via Blockchain Affect 5,400+ Websites

Over 5,400 compromised WordPress and PrestaShop sites deliver ClickFix payloads and WebRTC stagers from BNB Smart Chain via EtherHiding.

Runtime Rebel Intel
4 min read · Sep 5, 2026
SonicWall SMA 1000 Zero-Days: Unauthenticated RCE Explained
CRITICAL
Vulnerabilities

SonicWall SMA 1000 Zero-Days: Unauthenticated RCE Explained

Zero-day vulnerabilities in SonicWall SMA 1000 series appliances enable unauthenticated remote code execution, posing critical risks to organizations.

Runtime Rebel Intel
4 min read · Sep 5, 2026
WordPress RCE Exploited via CVE-2026-14894 & CVE-2026-32475
CRITICAL
Vulnerabilities

WordPress RCE Exploited via CVE-2026-14894 & CVE-2026-32475

Attackers exploit critical RCE flaws in WordPress Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475) to deploy web shells and seize sites.

Runtime Rebel Intel
4 min read · Sep 4, 2026
Node.js Abuse: Attackers Deploy Malware via Trusted Runtime
MEDIUM
Threat Intel

Node.js Abuse: Attackers Deploy Malware via Trusted Runtime

Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.

Runtime Rebel Intel
4 min read · Sep 3, 2026

Advertisement

← All 285 glossary terms