Dossier
Malware delivery
Coverage of Malware delivery in the Nexus archive.
- What happens if you visit a WordPress site hacked through wp2shell?
WordPress patched a critical core vulnerability chain called wp2shell, which allows attackers to gain full control of sites without authentication, leading to risks like credential theft, malware delivery, and malicious redirects for visitors. Attackers have already begun exploiting the flaw, injecting harmful content and compromising user trust.
- Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
A researcher analyzed 3,000 Live ClickFix payloads, revealing API-driven servers distribute malware through disguised commands on fake 'prove you're human' pages. A new delivery method was identified to bypass Windows' script scanning.