#web-shells

[ follow ]
fromThe Hacker News
14 hours ago

Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS Servers

Cybersecurity researchers have shed light on a Chinese-speaking cybercrime group codenamed UAT-8099 that has been attributed to search engine optimization (SEO) fraud and theft of high-value credentials, configuration files, and certificate data. The attacks are designed to target Microsoft Internet Information Services (IIS) servers, with most of the infections reported in India, Thailand, Vietnam, Canada, and Brazil, spanning universities, tech firms, and telecom providers. The group was first discovered in April 2025. The targets are primarily mobile users, encompassing both Android and Apple iPhone devices.
Information security
Information security
fromSecurityWeek
1 week ago

GeoServer Flaw Exploited in US Federal Agency Hack

CVE-2024-36401 RCE in GeoServer enabled attackers to breach a federal agency, deploy web shells, move laterally, and maintain persistence for weeks.
[ Load more ]