WordPress security firm Defiant has discovered a security threat in the form of a backdoor malware posing as a genuine plugin. It hides its presence and avoids detection by presenting itself as a caching plugin. Once installed, the malware provides attackers with a range of functions and gives them remote access to control and monetise the victim website.

China-Linked Espionage Cluster Deploys Custom ASPX/ASHX Shells on IIS
A previously disclosed China-linked threat cluster, tracked as OP-512, has been observed deploying a purpose-built web shell framework to compromise Internet Information Services (IIS) servers.


