Skip to main content

Threats Tagged 't1505.003'

View all threats tagged with 't1505.003'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1505.003

Threats Tagged 't1505.003'

Click on any threat for detailed analysis and mitigation recommendations

A threat actor compromised three web servers hosting recreation management software for municipalities and parks organizations by exploiting a file upload vulnerability. After multiple failed exploitation attempts, the attacker registered legitimate accounts and abused the member file upload function to deploy webshells. The attacker enumerated systems, extracted database credentials, and targeted payment card data from Fortis webhook logs. User-agent strings indicate Chinese origin, with suspected AI-generated scripts throughout the operation. The adversary adapted tactics across compromises, employing timestomping and file masquerading for defense evasion. When one server returned to production prematurely, the attacker injected a trojanized jQuery file into authentication pages, establishing WebRTC and WebSocket channels for credential harvesting via Cloudflare Workers infrastructure.

Join the discussion

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating. Key takeaways: Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations. Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing within hours of the July 17, 2026 disclosure. Patches are available in WordPress 7.0.2 and 6.9.5; WordPress.org has enabled forced automatic updates across affected supported installations. Background Tenable's Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding wp2shell, two vulnerabilities in WordPress Core that can be chained together to achieve pre-authentication remote code execution. FAQ What is wp2shell? wp2shell is the name given to two vulnerabilities in WordPress Core. When was wp2shell first disclosed? On July 17, 2026, WordPress released security updates addressing the wp2shell vulnerabilities alongside two GitHub Security Advisories. Adam Kues of Searchlight Cyber, who discovered and disclosed CVE-2026-63030, published research on the same day and chose to hold back the technical specifics given the severity of the finding. Searchlight Cyber also launched wp2shell.com , a testing tool that allows administrators to check whether their WordPress installation is vulnerable. On July 20, Searchlight Cyber published a full technical breakdown of the attack chain. What are the vulnerabilities associated with wp2shell? wp2shell is a two-vulnerability exploit chain affecting WordPress Core. CVE Description CVSSv3 CVE-2026-63030 WordPress Core REST API Batch-Route Confusion Remote Code Execution Vulnerability 9.8 CVE-2026-60137 WordPress Core WP_Query author__not_in SQL Injection Vulnerability 5.9 CVE-2026-63030 is a REST API batch-route confusion weakness introduced in WordPress 6.9. CVE-2026-60137 is a SQL injection flaw in the author__not_in parameter of WP_Query , present in WordPress 6.8 and later. When chained on WordPress 6.9.0 through 7.0.1, the two flaws allow an unauthenticated attacker to reach the REST API batch endpoint at /wp-json/batch/v1 and achieve remote code execution. CVE-2026-60137 was discovered and disclosed by security researchers TF1T, dtro, and haongo. CVE-2026-60137 also affects WordPress 6.8.0 through 6.8.5 as a standalone SQL injection issue. Because CVE-2026-63030 was introduced in WordPress 6.9, the full RCE chain is only achievable on 6.9.x and 7.0.x installations. How severe is the wp2shell vulnerability chain? An anonymous, unauthenticated user can execute the chain against a default WordPress installation with no plugins required. No preconditions exist beyond the default WordPress configuration. Cloudflare notes that the vulnerable code path is reached when “a persistent object cache is not in use.” Note: wp2shell targets WordPress Core itself rather than a plugin or theme. All four prior WordPress-related entries in the CISA Known Exploited Vulnerabilities (KEV) catalog involve plugins, not core. Pre-authentication remote code execution in WordPress Core is uncommon. CVE Product Added to KEV Ransomware CVE-2026-41940 WebPros cPanel & WHM and WP2 (WordPress Squared) April 30, 2026 Known CVE-2020-25213 WordPress File Manager Plugin November 3, 2021 Unknown CVE-2020-11738 WordPress Snap Creek Duplicator Plugin November 3, 2021 Unknown CVE-2019-9978 WordPress Social Warfare Plugin November 3, 2021 Unknown How widespread are the attacks exploiting wp2shell? WordPress is the most widely deployed content management system in the world. Some hosted installations will receive patc…

Join the discussion

The China-nexus threat group Longlegs continues to deploy Warlock ransomware by exploiting Microsoft SharePoint vulnerabilities, particularly the ToolShell exploit chain. Over the past two months, the group targeted at least four organizations including water utilities, telecommunications providers, government bodies, and universities in Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. The attackers exploit SharePoint flaws for initial access, use DLL sideloading techniques, abuse vulnerable signed drivers like K7RKScan to disable security software, and leverage Visual Studio Code tunneling for covert remote access. They deploy ransomware at scale by staging payloads in domain SYSVOL shares for rapid network-wide distribution, successfully compromising over 40 hosts in some incidents.

Join the discussion

Microsoft Threat Intelligence identified active exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite's SNMP notification path. Exploitation occurred between patch availability on July 20, 2026 and public disclosure on August 13, 2026. Attackers delivered JSP webshells and reverse shells without requiring authentication, achieving privilege escalation through PAM configuration abuse and establishing persistent access via systemd services. Post-exploitation activity included cluster-wide lateral movement using Zimbra SSH keys, collection of authentication secrets and mailbox data, and attempted exfiltration using cloud-storage tools. Multiple organizations across different regions and industries were affected through both automated payload delivery and hands-on-keyboard operations targeting internet-facing Zimbra mail servers.

Join the discussion

A malicious cyber actor exploited a Citrix NetScaler Gateway zero-day vulnerability on September 24, 2026, three days before public disclosure. The attacker, using IP address 149.104.78.141, attempted exploitation that was detected through behavioral analysis despite no CVE-specific signatures existing at the time. The exploitation chain aimed to establish persistence through a password-protected webshell, attempting to set setuid and setgid bits on /bin/sh for root access. The attacker tried to configure the web server to execute a hidden PHP webshell disguised as a CSS file, using aliases to route requests. Though unsuccessful in compromising the targeted sensor, the post-exploitation playbook revealed sophisticated techniques for maintaining access and evading detection through web server manipulation.

Join the discussion

UNC6240, also known as ShinyHunters, has resumed mass exploitation of CVE-2026-35273 targeting Oracle PeopleSoft systems globally across multiple sectors including education, technology, healthcare, agriculture, transportation, and government. The threat actor bypassed web application firewall rules by URL-encoding a single character in the request path, accessing the vulnerable Environment Management Hub endpoint on systems where operators believed WAF rules had mitigated exposure. Following initial exploitation, UNC6240 deployed multiple web shells including x.jsp and u.jsp, a trojanized backdoor called SIDEEYE delivered via Ple64.exe, Neo-reGeorg tunneling tools, and MeshAgent for persistent access. The actor conducted reconnaissance, credential theft, and prepared for data exfiltration with established patterns indicating potential extortion activities.

Join the discussion

CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. LevelBlue's Threat Hunt Operations & Research (THOR) team identified active exploitation across multiple customer environments featuring malicious authentication events with attacker-controlled usernames containing pitboss and NSPPE strings. Observed activities included command-execution testing, payload retrieval using curl and wget, configuration collection and staging, reverse-shell deployment, persistence mechanisms, web-shell installation, and attempted exfiltration of NetScaler configuration data. Analysis revealed two second-stage payloads: main.py establishing reverse shells to command-and-control infrastructure, and update_c08937.pl creating privileged accounts, deploying PHP web shells, and attempting configuration exfiltration. Post-exploitation artifacts included creation of sec_monitor superuser accounts, modification of system binaries, deployment of .local_jou...

Join the discussion

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

Join the discussion

An Israeli influence-for-hire company called BlackCore has been identified conducting digital manipulation campaigns across multiple countries. The company operates through a sophisticated infrastructure offering services including discourse dominance, organic engagement manipulation, and counter-operations. Researchers identified a specific campaign involving a 14-week training program delivered to Angolan government employees in early 2026, which included the creation and deployment of fake social media personas and coordinated inauthentic behavior. The operation utilized AI-generated profile pictures, fake news outlets like 'Agita News', and coordinated amplification tactics across Facebook, Instagram, and TikTok. BlackCore's promotional materials openly advertised their capabilities to conduct deceptive influence operations on behalf of government clients, demonstrating how influence-for-hire services have become accessible to state actors seeking to manipulate online discourse.

Join the discussion

A significant supply chain attack compromised Brevo's infrastructure on September 14, 2026, affecting over 100,000 customer websites. Attackers injected malicious code into Brevo's JavaScript assets and widgets, delivering two distinct payloads: a WordPress plugin backdoor automatically installed when site administrators visited their own sites while logged in, and ClickFix overlays targeting regular visitors. The attack vector involved modification of Brevo's CDN-hosted files and creation of malicious subdomains under sendibt1.com. Evidence suggests attackers gained access to Brevo's Cloudflare account, allowing them to modify DNS records and rewrite content dynamically. The malicious activity lasted approximately four hours, from 16:05 to 20:12 UTC. Brevo's prominent clients include eBay, Louis Vuitton, Michelin, and Amnesty International, amplifying the attack's potential impact significantly.

Join the discussion

Showing 1 to 10 of 72 results

Filters:Tag: t1505.003
Page 1 of 8
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses