#remotecommandexecution — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #remotecommandexecution, aggregated by home.social.
-
GiveWP Plugin Flaw Lets Hackers Execute Server Commands
A critical flaw in the GiveWP WordPress donation plugin, known as CVE-2026-82222, allows hackers to run malicious commands on your server - and it's surprisingly easy to exploit. This maximum-severity vulnerability can be triggered by an unauthenticated attacker, putting your site at risk of a devastating takeover.
#Wordpress #Givewp #Cve202682222 #PluginVulnerability #RemoteCommandExecution
-
Implants in the Supply Chain
Three distinct implants—SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS—have been discovered embedded in ZBT router firmware distributed through a global supply chain reaching the United States, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor listening on port 9992, offering root shell access from the internet with trivial MAC address bypass. SPEAKINGSTONE is a phone-home surveillance implant that beacons to ZBT's cloud infrastructure, capable of DNS hijacking, ISP credential theft, and remote command execution. A sinkholed backup domain revealed 392 devices, 390 located in China, primarily on China Mobile's network. Internet scans identified 203 DARKLANTERN instances across 22 countries. These implants use plaintext protocols without authentication, making them hijackable by any network adversary. The affected hardware appears in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commerciall...
Pulse ID: 6a90b7387fc31b76fc1f2e4c
Pulse Link: https://otx.alienvault.com/pulse/6a90b7387fc31b76fc1f2e4c
Pulse Author: AlienVault
Created: 2026-08-27 22:16:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Australia #BackDoor #Canada #China #Cloud #CyberSecurity #DNS #Germany #InfoSec #Mac #OTX #OpenThreatExchange #Philippines #RemoteCommandExecution #Russia #SupplyChain #UDP #UnitedStates #bot #AlienVault
-
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...
Pulse ID: 6a8775e8885af9073b89474a
Pulse Link: https://otx.alienvault.com/pulse/6a8775e8885af9073b89474a
Pulse Author: AlienVault
Created: 2026-08-20 21:47:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault
-
Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2
A compact 12 KB Windows backdoor masquerading as Realtek software
has been identified using WMI for persistence and hiding its command-
and-control address within whitespace in a desktop.ini file. The malwaresupports remote command execution and file delivery while using stealth
techniques to evade detection.Pulse ID: 6a82fbb54b642510eca18ebf
Pulse Link: https://otx.alienvault.com/pulse/6a82fbb54b642510eca18ebf
Pulse Author: cryptocti
Created: 2026-08-17 12:16:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti
-
Hackers attack HFS servers to drop malware and Monero miners
#ACTIVELYEXPLOITED #REJETTOHFS #REMOTECOMMANDEXECUTION #malware https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/ -
TP-Link Resolves High-Stakes Vulnerability in Archer C5400X Gaming Router https://thecyberexpress.com/tp-link-archer-c5400x-vulnerability/ #ArcherC5400Xvulnerability #remotecommandexecution #TheCyberExpressNews #CybersecurityNews #Vulnerabilities #TheCyberExpress #FirewallDaily #gamingrouter #CVE20245035
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362
-
"⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"
A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!
Source: [The Hacker News](https://thehackernews.com/)
Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐