Custom web shell linked to Clop ransomware gang targets PTC Windchill servers
The web shell was found after attackers exploited the CVE-2026-12569 RCE flaw in PTC Windchill.
The web shell was found after attackers exploited the CVE-2026-12569 RCE flaw in PTC Windchill.
The infection chain begins with a malicious Windows shortcut (LNK) disguised as a PDF file.
The group exploited a vulnerability at a financial service provider, which was caused by a flawed software update.
The attacker used WinRAR to archive files and the s5cmd tool to upload stolen data to an attacker-controlled S3 bucket.
Exploitation of the macOS flaws has been observed in attacks deploying a Monero crypto miner.
In brief: Microsoft fixed a zero-day, Russian hackers targeted two power plants in Poland last year; and more.
There is no evidence that City-Forum is operated by ShinyHunters, although some of the Salesforce techniques resemble earlier ShinyHunters campaigns.
Researchers found that DeadLock uses the Polygon blockchain to store configuration data and information used by its leak site.
The attackers used path traversal techniques before installing a malicious cron job to maintain access.
Mozilla said the risk of a supply chain attack is low because access to the repository was limited to a small group of employees.
Showing elements 61 - 70