#remotecommandexecution — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #remotecommandexecution, aggregated by home.social.
-
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...
Pulse ID: 6a8775e8885af9073b89474a
Pulse Link: https://otx.alienvault.com/pulse/6a8775e8885af9073b89474a
Pulse Author: AlienVault
Created: 2026-08-20 21:47:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault
-
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...
Pulse ID: 6a8775e8885af9073b89474a
Pulse Link: https://otx.alienvault.com/pulse/6a8775e8885af9073b89474a
Pulse Author: AlienVault
Created: 2026-08-20 21:47:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault
-
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...
Pulse ID: 6a8775e8885af9073b89474a
Pulse Link: https://otx.alienvault.com/pulse/6a8775e8885af9073b89474a
Pulse Author: AlienVault
Created: 2026-08-20 21:47:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault
-
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...
Pulse ID: 6a8775e8885af9073b89474a
Pulse Link: https://otx.alienvault.com/pulse/6a8775e8885af9073b89474a
Pulse Author: AlienVault
Created: 2026-08-20 21:47:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault
-
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...
Pulse ID: 6a8775e8885af9073b89474a
Pulse Link: https://otx.alienvault.com/pulse/6a8775e8885af9073b89474a
Pulse Author: AlienVault
Created: 2026-08-20 21:47:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault
-
Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2
A compact 12 KB Windows backdoor masquerading as Realtek software
has been identified using WMI for persistence and hiding its command-
and-control address within whitespace in a desktop.ini file. The malwaresupports remote command execution and file delivery while using stealth
techniques to evade detection.Pulse ID: 6a82fbb54b642510eca18ebf
Pulse Link: https://otx.alienvault.com/pulse/6a82fbb54b642510eca18ebf
Pulse Author: cryptocti
Created: 2026-08-17 12:16:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti
-
Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2
A compact 12 KB Windows backdoor masquerading as Realtek software
has been identified using WMI for persistence and hiding its command-
and-control address within whitespace in a desktop.ini file. The malwaresupports remote command execution and file delivery while using stealth
techniques to evade detection.Pulse ID: 6a82fbb54b642510eca18ebf
Pulse Link: https://otx.alienvault.com/pulse/6a82fbb54b642510eca18ebf
Pulse Author: cryptocti
Created: 2026-08-17 12:16:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti
-
Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2
A compact 12 KB Windows backdoor masquerading as Realtek software
has been identified using WMI for persistence and hiding its command-
and-control address within whitespace in a desktop.ini file. The malwaresupports remote command execution and file delivery while using stealth
techniques to evade detection.Pulse ID: 6a82fbb54b642510eca18ebf
Pulse Link: https://otx.alienvault.com/pulse/6a82fbb54b642510eca18ebf
Pulse Author: cryptocti
Created: 2026-08-17 12:16:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti
-
Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2
A compact 12 KB Windows backdoor masquerading as Realtek software
has been identified using WMI for persistence and hiding its command-
and-control address within whitespace in a desktop.ini file. The malwaresupports remote command execution and file delivery while using stealth
techniques to evade detection.Pulse ID: 6a82fbb54b642510eca18ebf
Pulse Link: https://otx.alienvault.com/pulse/6a82fbb54b642510eca18ebf
Pulse Author: cryptocti
Created: 2026-08-17 12:16:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti
-
Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2
A compact 12 KB Windows backdoor masquerading as Realtek software
has been identified using WMI for persistence and hiding its command-
and-control address within whitespace in a desktop.ini file. The malwaresupports remote command execution and file delivery while using stealth
techniques to evade detection.Pulse ID: 6a82fbb54b642510eca18ebf
Pulse Link: https://otx.alienvault.com/pulse/6a82fbb54b642510eca18ebf
Pulse Author: cryptocti
Created: 2026-08-17 12:16:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti
-
Technical Analysis of a Novel IMEEX Framework
The IMEEX framework is a newly discovered, custom-built malware targeting Windows systems. Delivered as a 64-bit DLL, it offers extensive control over compromised machines, featuring execution of additional modules, file manipulation, process management, registry modification, and remote command execution. It primarily targets Djibouti and Afghanistan, gathering system information and communicating with its command-and-control server over encrypted channels. The framework employs advanced techniques like masquerading as legitimate processes, mutex creation, and encrypted communications to maintain persistence and evade detection. Its modular approach, robust capabilities, and potential infrastructure overlap with ShadowPad suggest an evolution in threat actor tactics.
Pulse ID: 670cf932eede40d2e1660012
Pulse Link: https://otx.alienvault.com/pulse/670cf932eede40d2e1660012
Pulse Author: AlienVault
Created: 2024-10-14 10:57:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Afghanistan #CyberSecurity #ICS #InfoSec #Mac #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #ShadowPad #Windows #bot #AlienVault
-
Hackers attack HFS servers to drop malware and Monero miners
#ACTIVELYEXPLOITED #REJETTOHFS #REMOTECOMMANDEXECUTION #malware https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/ -
Hackers attack HFS servers to drop malware and Monero miners
#ACTIVELYEXPLOITED #REJETTOHFS #REMOTECOMMANDEXECUTION #malware https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/ -
Hackers attack HFS servers to drop malware and Monero miners
#ACTIVELYEXPLOITED #REJETTOHFS #REMOTECOMMANDEXECUTION #malware https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/ -
Hackers attack HFS servers to drop malware and Monero miners
#ACTIVELYEXPLOITED #REJETTOHFS #REMOTECOMMANDEXECUTION #malware https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/ -
Hackers attack HFS servers to drop malware and Monero miners
#ACTIVELYEXPLOITED #REJETTOHFS #REMOTECOMMANDEXECUTION #malware https://www.bleepingcomputer.com/news/security/hackers-attack-hfs-servers-to-drop-malware-and-monero-miners/ -
TP-Link Resolves High-Stakes Vulnerability in Archer C5400X Gaming Router https://thecyberexpress.com/tp-link-archer-c5400x-vulnerability/ #ArcherC5400Xvulnerability #remotecommandexecution #TheCyberExpressNews #CybersecurityNews #Vulnerabilities #TheCyberExpress #FirewallDaily #gamingrouter #CVE20245035
-
TP-Link Resolves High-Stakes Vulnerability in Archer C5400X Gaming Router https://thecyberexpress.com/tp-link-archer-c5400x-vulnerability/ #ArcherC5400Xvulnerability #remotecommandexecution #TheCyberExpressNews #CybersecurityNews #Vulnerabilities #TheCyberExpress #FirewallDaily #gamingrouter #CVE20245035
-
TP-Link Resolves High-Stakes Vulnerability in Archer C5400X Gaming Router https://thecyberexpress.com/tp-link-archer-c5400x-vulnerability/ #ArcherC5400Xvulnerability #remotecommandexecution #TheCyberExpressNews #CybersecurityNews #Vulnerabilities #TheCyberExpress #FirewallDaily #gamingrouter #CVE20245035
-
TP-Link Resolves High-Stakes Vulnerability in Archer C5400X Gaming Router https://thecyberexpress.com/tp-link-archer-c5400x-vulnerability/ #ArcherC5400Xvulnerability #remotecommandexecution #TheCyberExpressNews #CybersecurityNews #Vulnerabilities #TheCyberExpress #FirewallDaily #gamingrouter #CVE20245035
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362
-
"⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"
A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!
Source: [The Hacker News](https://thehackernews.com/)
Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐
-
"⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"
A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!
Source: [The Hacker News](https://thehackernews.com/)
Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐
-
"⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"
A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!
Source: [The Hacker News](https://thehackernews.com/)
Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐
-
"⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"
A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!
Source: [The Hacker News](https://thehackernews.com/)
Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐