#WebShells
One encoded POST to PSEMHUB bypassed every WAF signature, wrote dual JSP shells, and added scheduled-task persistence in PeopleSoft. Static keyword rules cannot detect layered Base64 and parameter splitting.
#WAFBypass #PeopleSoft #WebShells
September 27, 2026 at 10:00 PM
Spent the morning reading the Citrix NetScaler threads. The scary part isn't the RCE - it's that patching doesn't evict the webshells. Someone still has to check every box by hand. Unsexy verification work IS the job. I now quote it as its own line item.
September 27, 2026 at 7:26 PM
Attackers exploited the Oracle PeopleSoft CVE-2026-35273 vulnerability to deploy web shells, giving attackers persistent, unauthorized access to the system. #Oracle #PeopleSoft #CVE #webshells https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
ShinyHunters-linked attackers exploit CVE-2026-35273 in Oracle PeopleSoft, bypassing WAF rules to deploy web shells on dozens of systems.
thehackernews.com
September 27, 2026 at 5:29 PM
Wichtig: Die Schwachstellen wurden offenbar bereits vor Patch-Verfügbarkeit aktiv ausgenutzt. Nach Angaben von Kevin Beaumont wurden dabei im September Webshells auf kompromittierten Systemen abgelegt.
September 27, 2026 at 4:35 PM
Two CISA KEV bugs, one bad week: SharePoint webshells and MikroTik routers taken over without a password. https://intel.threadlinqs.com/threat/TL-2026-2669 #ThreatIntel #CVE_2026_65660 #CVE_2026_67279 #Inmemory
September 26, 2026 at 11:23 PM
🤖 CVE-2026-87902: critical WordPress flaw actively exploited. Attackers write files to disk that execute shell commands on access — patch and audit webroots for webshells.

https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/
September 24, 2026 at 5:35 AM
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug www.infosecurity-magazine.com/news/woocomm...
PHP Webshell Campaign Targets WordPress Through WooCommerce Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
www.infosecurity-magazine.com
September 21, 2026 at 4:42 PM
El parche llevaba meses publicado. Los webshells se subieron igual.

CVE-2026-27540, plugin premium de WooCommerce. Los plugins de pago no salen en tu pantalla de Actualizaciones: licencia caducada, cero avisos.

¿Sabes cuáles tiene tu web?

Foto de Justin Morgan en Unsplash
September 18, 2026 at 7:35 AM
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug(WooCommerceプラグインの重大な脆弱性を悪用、WordPressにPHP Webshellを設置) #InfosecurityMagazine (Sep 16)

www.infosecurity-magazine.com/news/woocomm...
PHP Webshell Campaign Targets WordPress Through WooCommerce Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
www.infosecurity-magazine.com
September 18, 2026 at 2:09 AM
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug(重大なWooCommerceプラグイン脆弱性を狙うPHP Webシェル攻撃) #InfosecurityMagazine (Sep 16)

www.infosecurity-magazine.com/news/woocomm...
PHP Webshell Campaign Targets WordPress Through WooCommerce Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
www.infosecurity-magazine.com
September 17, 2026 at 12:21 AM
Attackers Exploit Critical WooCommerce Plugin Flaw to Deploy Webshells

Attackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload PHP webshells and execute remote code on WordPress sites.
Attackers Exploit Critical WooCommerce Plugin Flaw to Deploy Webshells
Attackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload PHP webshells and execute remote code on WordPress sites.
privacyneedle.com
September 16, 2026 at 3:32 PM
A critical flaw in the WooCommerce Wholesale Lead Capture plugin (CVE-2026-27540) is being used to plant PHP webshells. Over 100,000 attacks blocked, but many sites remain vulnerable. Update to v2.0.3.2 immediately.
WooCommerce plugin allows anyone to install backdoors
A critical flaw in the WooCommerce Wholesale Lead Capture plugin (CVE-2026-27540) is being used to plant PHP webshells. Over 100,000 attacks blocked, but many sites remain vulnerable. Update to v2.0.3
www.alextech.ai
September 16, 2026 at 11:38 AM
📦 mage2kishan/module-malware-scanner 1.2.3

Active malware prevention + on-disk scanner for Magento 2. Three real-time guards (REST API, universal upload, custom-options) block PolyShell webshells, polyglot files and PHP-object-injection pay...

🔗 https://github.com/mage2sk/module-malware-scanner
September 9, 2026 at 5:59 AM
📦 mage2kishan/module-malware-scanner 1.2.2

Active malware prevention + on-disk scanner for Magento 2. Three real-time guards (REST API, universal upload, custom-options) block PolyShell webshells, polyglot files and PHP-object-injection pay...

🔗 https://github.com/mage2sk/module-malware-scanner
September 9, 2026 at 4:25 AM
Cómo bloquear PHP en wp-content/uploads (2026)

La segunda opción (141 caracteres) cumple con todos los requisitos.

Bloquear la ejecución de PHP en uploads es clave para evitar webshells en WordPress....

#webshells #htaccess #nginx #wordfence #wpcontent
Cómo bloquear PHP en wp-content/uploads (2026) - Seguridad en Wordpress
Cómo bloquear la ejecución de PHP en wp-content/uploads con .htaccess en Apache o un bloque location en Nginx, para frenar webshells.
seguridadenwordpress.com
September 8, 2026 at 5:26 AM
📦 mage2kishan/module-malware-scanner 1.2.1

Active malware prevention + on-disk scanner for Magento 2. Three real-time guards (REST API, universal upload, custom-options) block PolyShell webshells, polyglot files and PHP-object-injection pay...

🔗 https://github.com/mage2sk/module-malware-scanner
September 7, 2026 at 1:23 PM
Elementor Pro WordPress Flaw Exploited to Upload Webshells and Execute Commands - CySecurity News - Latest Information Security and Hacking Incidents https://www.cysecurity.news/2026/09/elementor-pro-wordpress-flaw-exploited.html
September 7, 2026 at 5:13 AM
Elementor Pro WordPress Flaw Exploited to Upload Webshells and Execute Commands #CriticalVulnerability #CVE #CVEexploits
Elementor Pro WordPress Flaw Exploited to Upload Webshells and Execute Commands
 A critical vulnerability in the Elementor Pro WordPress plugin is being actively exploited to upload malicious PHP files and execute commands remotely on the affected websites.  The vulnerability, tracked as CVE-2026-32475, affects the Elementor Pro versions 4.2.1 and lower. This issue was patched on August 19. Elementor Pro has more than 6 million active installations and is widely used to design WordPress websites with drag-and-drop tools.  The vulnerability is related to the insufficient validation of file-upload arrays in Elementor Pro forms. Attackers can exploit this issue by uploading an empty file as the first element of the upload array and a malicious PHP file as the second. Then the plugin will not validate the following files in the array, thus allowing the attacker-controlled PHP payload to be successfully uploaded on the server without any additional checks.  Once the malicious file is uploaded, it will be stored on the /wp-content/uploads/elementor/forms/ directory with a randomly generated name but preserving the attacker’s .php extension. Then the attacker will be able to directly access this file on the server to execute arbitrary commands and potentially deploy a webshell for further attacks. To successfully exploit the vulnerability, an attacker needs to have access to a WordPress website with a published Elementor Pro Form widget that contains at least one File Upload field.  This is a relatively common case for WordPress websites that utilize Elementor Pro forms. WordPress security company Defiant, which operates the Wordfence firewall, noted that exploitation began on August 19, the same day Elementor released the 4.2.2 version to address the vulnerability. Wordfence observed that the traffic was especially heavy between August 19 and 23, having blocked more than 190,000 attempts to target its customers.  Wordfence has identified IP addresses that were responsible for thousands of exploitation attempts. Website administrators can add these addresses to their blocklists to protect their WordPress sites. Administrators that utilize Elementor Pro need to make sure to update their software to the latest versions, preferably 4.2.2 or newer. Moreover, they should check their /wp-content/uploads/elementor/forms/ directories for any unexpected .php files.  As the name suggests, the directory is supposed to contain the files that users upload with Elementor forms, meaning that the discovery of any .php files should be investigated and potentially result in an intrusion assessment.
dlvr.it
September 5, 2026 at 4:57 PM
SussyFinder: a single-file PHP scanner that catches webshells other tools miss, using entropy + Z-score anomaly detection. Runs on PHP 4.3–8.x, zero dependencies, GPLv3. Looking for contributors — good first issues are open. 🔍 github.com/Cvar1984/sussyfinder
September 5, 2026 at 9:16 AM
Bug no plugin WordPress com mais de 6 milhões de instalações permite upload de webshells e execução remota de comandos. Há patch desde 19 de agosto, mas os ataques já rolam.
Falha crítica no Elementor Pro já está a ser usada para atacar sites
Bug no plugin WordPress com mais de 6 milhões de instalações permite upload de webshells e execução remota de comandos. Há patch desde 19 de agosto, mas os ataques já rolam.
pixelmagazine.pt
September 5, 2026 at 9:16 AM
Chinese APT 'Nie' runs Claude and DeepSeek agents to auto-hack targets, then hides webshells inside PNG images. https://intel.threadlinqs.com/threat/TL-2026-2325 #ThreatIntel #CVE_2014_6271 #CVE_2020_1938 #Glutton
September 4, 2026 at 11:39 AM
Wordfence has blocked over 190,000 exploit attempts against the Elementor Pro flaw CVE-2026-32475. Attacks began 19 August, the day it went public. The unauthenticated file upload, fixed in 4.2.2, drops PHP webshells under wp-content/uploads/elementor/forms/. bleepingcomputer.com/new...
Critical Elementor Pro flaw exploited to take over WordPress sites
Unauthenticated file upload in Elementor Pro 4.2.1 and earlier, patched in 4.2.2.
www.bleepingcomputer.com
September 3, 2026 at 3:05 PM