Lo sfruttamento attivo delle vulnerabilità di SharePoint on-premises ricorda che l'applicazione delle patch da sola potrebbe non porre fine a un'intrusione se gli aggressori riescono anche ad accedere alle machine key di IIS e ad altri segreti del livello applicativo.
An active campaign against content management systems shows how one unpatched plugin can become a foothold for web shells, credential theft, and lingering access.
A critical remote code execution flaw in PTC Windchill PDMlink and FlexPLM has landed in CISA’s exploited-vulnerability list, putting product-data systems under urgent defensive pressure.
A reported espionage cluster tied to custom IIS web shells shows how ordinary ASP.NET handlers can become a quiet foothold on exposed servers.
A surge in web shell attacks exposes critical vulnerabilities in Sangoma FreePBX systems, leaving more than 900 organizations open to cybercriminal control.
Un’ondata di attacchi con web shell mette a nudo vulnerabilità critiche nei sistemi Sangoma FreePBX, lasciando oltre 900 organizzazioni esposte al controllo dei cybercriminali.