Wordfence and Defiant detail critical flaws in WooCommerce Wholesale Lead Capture and The Events Calendar, both reachable without credentials.
A fileless rootkit dubbed PoisonedRefresh injects PHP web shells into the memory of compromised F5 BIG-IP APM appliances.
Clop's bespoke Windchill web shell decrypts keystore credentials and maps vaults for mass exfiltration.
Attackers tampered with JavaScript files for three popular WordPress plugins, creating hidden admin accounts and web shells only when site…