home.social

#remotecommandexecution — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #remotecommandexecution, aggregated by home.social.

  1. GiveWP Plugin Flaw Lets Hackers Execute Server Commands

    A critical flaw in the GiveWP WordPress donation plugin, known as CVE-2026-82222, allows hackers to run malicious commands on your server - and it's surprisingly easy to exploit. This maximum-severity vulnerability can be triggered by an unauthenticated attacker, putting your site at risk of a devastating takeover.

    osintsights.com/givewp-plugin-

    #Wordpress #Givewp #Cve202682222 #PluginVulnerability #RemoteCommandExecution

  2. GiveWP Plugin Flaw Lets Hackers Execute Server Commands

    A critical flaw in the GiveWP WordPress donation plugin, known as CVE-2026-82222, allows hackers to run malicious commands on your server - and it's surprisingly easy to exploit. This maximum-severity vulnerability can be triggered by an unauthenticated attacker, putting your site at risk of a devastating takeover.

    osintsights.com/givewp-plugin-

    #Wordpress #Givewp #Cve202682222 #PluginVulnerability #RemoteCommandExecution

  3. Implants in the Supply Chain

    Three distinct implants—SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS—have been discovered embedded in ZBT router firmware distributed through a global supply chain reaching the United States, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor listening on port 9992, offering root shell access from the internet with trivial MAC address bypass. SPEAKINGSTONE is a phone-home surveillance implant that beacons to ZBT's cloud infrastructure, capable of DNS hijacking, ISP credential theft, and remote command execution. A sinkholed backup domain revealed 392 devices, 390 located in China, primarily on China Mobile's network. Internet scans identified 203 DARKLANTERN instances across 22 countries. These implants use plaintext protocols without authentication, making them hijackable by any network adversary. The affected hardware appears in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commerciall...

    Pulse ID: 6a90b7387fc31b76fc1f2e4c
    Pulse Link: otx.alienvault.com/pulse/6a90b
    Pulse Author: AlienVault
    Created: 2026-08-27 22:16:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Australia #BackDoor #Canada #China #Cloud #CyberSecurity #DNS #Germany #InfoSec #Mac #OTX #OpenThreatExchange #Philippines #RemoteCommandExecution #Russia #SupplyChain #UDP #UnitedStates #bot #AlienVault

  4. Implants in the Supply Chain

    Three distinct implants—SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS—have been discovered embedded in ZBT router firmware distributed through a global supply chain reaching the United States, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor listening on port 9992, offering root shell access from the internet with trivial MAC address bypass. SPEAKINGSTONE is a phone-home surveillance implant that beacons to ZBT's cloud infrastructure, capable of DNS hijacking, ISP credential theft, and remote command execution. A sinkholed backup domain revealed 392 devices, 390 located in China, primarily on China Mobile's network. Internet scans identified 203 DARKLANTERN instances across 22 countries. These implants use plaintext protocols without authentication, making them hijackable by any network adversary. The affected hardware appears in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commerciall...

    Pulse ID: 6a90b7387fc31b76fc1f2e4c
    Pulse Link: otx.alienvault.com/pulse/6a90b
    Pulse Author: AlienVault
    Created: 2026-08-27 22:16:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Australia #BackDoor #Canada #China #Cloud #CyberSecurity #DNS #Germany #InfoSec #Mac #OTX #OpenThreatExchange #Philippines #RemoteCommandExecution #Russia #SupplyChain #UDP #UnitedStates #bot #AlienVault

  5. Implants in the Supply Chain

    Three distinct implants—SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS—have been discovered embedded in ZBT router firmware distributed through a global supply chain reaching the United States, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor listening on port 9992, offering root shell access from the internet with trivial MAC address bypass. SPEAKINGSTONE is a phone-home surveillance implant that beacons to ZBT's cloud infrastructure, capable of DNS hijacking, ISP credential theft, and remote command execution. A sinkholed backup domain revealed 392 devices, 390 located in China, primarily on China Mobile's network. Internet scans identified 203 DARKLANTERN instances across 22 countries. These implants use plaintext protocols without authentication, making them hijackable by any network adversary. The affected hardware appears in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commerciall...

    Pulse ID: 6a90b7387fc31b76fc1f2e4c
    Pulse Link: otx.alienvault.com/pulse/6a90b
    Pulse Author: AlienVault
    Created: 2026-08-27 22:16:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Australia #BackDoor #Canada #China #Cloud #CyberSecurity #DNS #Germany #InfoSec #Mac #OTX #OpenThreatExchange #Philippines #RemoteCommandExecution #Russia #SupplyChain #UDP #UnitedStates #bot #AlienVault

  6. Implants in the Supply Chain

    Three distinct implants—SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS—have been discovered embedded in ZBT router firmware distributed through a global supply chain reaching the United States, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor listening on port 9992, offering root shell access from the internet with trivial MAC address bypass. SPEAKINGSTONE is a phone-home surveillance implant that beacons to ZBT's cloud infrastructure, capable of DNS hijacking, ISP credential theft, and remote command execution. A sinkholed backup domain revealed 392 devices, 390 located in China, primarily on China Mobile's network. Internet scans identified 203 DARKLANTERN instances across 22 countries. These implants use plaintext protocols without authentication, making them hijackable by any network adversary. The affected hardware appears in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commerciall...

    Pulse ID: 6a90b7387fc31b76fc1f2e4c
    Pulse Link: otx.alienvault.com/pulse/6a90b
    Pulse Author: AlienVault
    Created: 2026-08-27 22:16:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Australia #BackDoor #Canada #China #Cloud #CyberSecurity #DNS #Germany #InfoSec #Mac #OTX #OpenThreatExchange #Philippines #RemoteCommandExecution #Russia #SupplyChain #UDP #UnitedStates #bot #AlienVault

  7. Implants in the Supply Chain

    Three distinct implants—SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS—have been discovered embedded in ZBT router firmware distributed through a global supply chain reaching the United States, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor listening on port 9992, offering root shell access from the internet with trivial MAC address bypass. SPEAKINGSTONE is a phone-home surveillance implant that beacons to ZBT's cloud infrastructure, capable of DNS hijacking, ISP credential theft, and remote command execution. A sinkholed backup domain revealed 392 devices, 390 located in China, primarily on China Mobile's network. Internet scans identified 203 DARKLANTERN instances across 22 countries. These implants use plaintext protocols without authentication, making them hijackable by any network adversary. The affected hardware appears in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commerciall...

    Pulse ID: 6a90b7387fc31b76fc1f2e4c
    Pulse Link: otx.alienvault.com/pulse/6a90b
    Pulse Author: AlienVault
    Created: 2026-08-27 22:16:24

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Australia #BackDoor #Canada #China #Cloud #CyberSecurity #DNS #Germany #InfoSec #Mac #OTX #OpenThreatExchange #Philippines #RemoteCommandExecution #Russia #SupplyChain #UDP #UnitedStates #bot #AlienVault

  8. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  9. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  10. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  11. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  12. Popular Rust Crates Compromised in Build-Time Supply Chain Attack

    A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...

    Pulse ID: 6a8775e8885af9073b89474a
    Pulse Link: otx.alienvault.com/pulse/6a877
    Pulse Author: AlienVault
    Created: 2026-08-20 21:47:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #CyberSecurity #InfoSec #Linux #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #RemoteCommandExecution #Rust #SupplyChain #Windows #bot #AlienVault

  13. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti

  14. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti

  15. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti

  16. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti

  17. Backdoor Uses Realtek Masquerading and Whitespace Encoding to Hide C2

    A compact 12 KB Windows backdoor masquerading as Realtek software

    has been identified using WMI for persistence and hiding its command-
    and-control address within whitespace in a desktop.ini file. The malware

    supports remote command execution and file delivery while using stealth
    techniques to evade detection.

    Pulse ID: 6a82fbb54b642510eca18ebf
    Pulse Link: otx.alienvault.com/pulse/6a82f
    Pulse Author: cryptocti
    Created: 2026-08-17 12:16:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #Windows #bot #cryptocti

  18. Technical Analysis of a Novel IMEEX Framework

    The IMEEX framework is a newly discovered, custom-built malware targeting Windows systems. Delivered as a 64-bit DLL, it offers extensive control over compromised machines, featuring execution of additional modules, file manipulation, process management, registry modification, and remote command execution. It primarily targets Djibouti and Afghanistan, gathering system information and communicating with its command-and-control server over encrypted channels. The framework employs advanced techniques like masquerading as legitimate processes, mutex creation, and encrypted communications to maintain persistence and evade detection. Its modular approach, robust capabilities, and potential infrastructure overlap with ShadowPad suggest an evolution in threat actor tactics.

    Pulse ID: 670cf932eede40d2e1660012
    Pulse Link: otx.alienvault.com/pulse/670cf
    Pulse Author: AlienVault
    Created: 2024-10-14 10:57:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #CyberSecurity #ICS #InfoSec #Mac #Malware #OTX #OpenThreatExchange #RemoteCommandExecution #ShadowPad #Windows #bot #AlienVault

  19. "⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"

    A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!

    Source: [The Hacker News](thehackernews.com/)

    Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐

  20. "⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"

    A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!

    Source: [The Hacker News](thehackernews.com/)

    Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐

  21. "⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"

    A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!

    Source: [The Hacker News](thehackernews.com/)

    Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐

  22. "⚠️ OpenSSH Flaw: Potential for Remote Command Execution ⚠️"

    A now-patched flaw in OpenSSH could be potentially exploited to run arbitrary commands remotely on compromised hosts. Stay informed!

    Source: [The Hacker News](thehackernews.com/)

    Tags: #OpenSSH #Flaw #RemoteCommandExecution #CyberSecurity #PatchUp 💻🔐