惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Secure Thoughts
V
Visual Studio Blog
C
Check Point Blog
S
SegmentFault 最新的问题
GbyAI
GbyAI
WordPress大学
WordPress大学
Microsoft Security Blog
Microsoft Security Blog
S
Schneier on Security
The Cloudflare Blog
Microsoft Azure Blog
Microsoft Azure Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
博客园_首页
Know Your Adversary
Know Your Adversary
The Hacker News
The Hacker News
Engineering at Meta
Engineering at Meta
Project Zero
Project Zero
U
Unit 42
小众软件
小众软件
Simon Willison's Weblog
Simon Willison's Weblog
Stack Overflow Blog
Stack Overflow Blog
P
Palo Alto Networks Blog
云风的 BLOG
云风的 BLOG
B
Blog
人人都是产品经理
人人都是产品经理
P
Proofpoint News Feed
A
About on SuperTechFans
Scott Helme
Scott Helme
C
Cyber Attacks, Cyber Crime and Cyber Security
宝玉的分享
宝玉的分享
E
Exploit-DB.com RSS Feed
L
Lohrmann on Cybersecurity
S
Security @ Cisco Blogs
C
CXSECURITY Database RSS Feed - CXSecurity.com
I
InfoQ
IT之家
IT之家
S
Securelist
Hacker News: Ask HN
Hacker News: Ask HN
博客园 - 叶小钗
MyScale Blog
MyScale Blog
博客园 - 聂微东
罗磊的独立博客
H
Heimdal Security Blog
T
Tor Project blog
Security Latest
Security Latest
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
G
GRAHAM CLULEY
O
OpenAI News
博客园 - Franky
T
Threat Research - Cisco Blogs
C
Cybersecurity and Infrastructure Security Agency CISA

Cyber Security News

Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild Criminal IP at Infosecurity Europe 2026: Introducing AITEM, the Next Chapter of Attack Surface Management Maine Takes Data Breach Reporting Portal Offline After Fake VRChat and Discord Filings 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From Hackers Server BugHunter - Bug Bounty Toolkit Powered by Claude and Free AI Providers Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication Anthropic Fable 5 and Mythos 5 Access Blocked to All Users Following Government Directive Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications Facebook and Instagram Down Globally, Users Reporting Multiple Issues Google Sues Chinese Cybercrime Network for Using Gemini AI to Launch Cyberattacks 400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers Critical Vulnerability Chain in LangGraph Allows Attackers to Gain Full Server Control SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target Diplomatic Organizations Authorities Dismantle Cryptocurrency Laundering Services ‘AudiA6’ Used by Ransomware Gangs Hackers Use Free Spotify Premium Hacks on TikTok and Instagram to Spread Vidar Infostealer Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive Data Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters CISA Requires Federal Agencies to Patch Critical Vulnerabilities Within 3 Days OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers Critical Langflow Vulnerability Exploited to Execute Malicious Code Hackers Abuse SniperDz PhaaS Ecosystem for Brand Impersonation and Browser Hijacking Researcher Hacked Google Using AI and Earned $500,000 Bug Bounty GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks Claude Mythos Turning N-Days Into N-Hours With Rapid Working Exploit Creation CISA Warns of Check Point Security Gateway Vulnerability Actively Exploited in Ransomware Attacks Hackers Use Weaponized DMG Files to Target macOS Users With Infostealer Malware Hackers Use BLUERABBIT Backdoor to Encrypt Files and Wipe Disks Across Windows Systems Hackers Abuse Residential Proxy Networks to Hide Malicious Activity and Evade Detection Cybercriminals Abuse Chinese-Language Guarantee Marketplaces to Trade Stolen Credentials Ivanti Command Injection Vulnerability Exploited in Attacks Following PoC Release PoC Exploit Released for Guest-to-Host Escape Linux Kernel Vulnerability Oracle Emergency Security Update to Fix Critical RCE Vulnerability GreatXML BitLocker Bypass 0-Day Exploited Via Windows Defender Offline Scan Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader in Espionage Attacks Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious Script Hackers Abuse AWS CloudTrail and Google Cloud Logging to Evade Detection and Exfiltrate Logs China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks Top 5 Best Tools for Simulated DDoS Attacks in 2026 Critical Vulnerability in Hugging Face Transformers Enables Remote Code Execution Attacks OWASP CVE Lite CLI - New Tool to Scan for Vulnerabilities in Your Projects Anthropic's Claude Services Down — claude.ai, Claude Code, and Cowork Affected [Updated] Hackers Publish Malicious Python Package Mimicking Legitimate Parsimonious Parser Hackers are Increasingly Weaponizing Trusted Tools to Deploy Notorious Malware New Magecart Attack Turns Stripe into a Malware Command Server Hola Browser for Windows Delivery Pipeline Compromised to Deliver Cryptominer New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation Microsoft 365 Service Degradation Bypassed Windows Driver Auto-Update Controls New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets Malicious Browser Add-Ons Target ChatGPT, Claude, Copilot, Gemini, and DeepSeek Users
Threat Actor Malware Platform Exposed via Unlocked PHP Installation Page
Abinaya · 2026-06-15 · via Cyber Security News

A misconfigured PHP installation page exposed the internal infrastructure of a live malware distribution platform, allowing a security researcher to gain unintentional administrative access to a threat actor’s dashboard.

What initially appeared to be a fake software download site turned out to be an active backend system used to deliver malware.

During routine IOC validation and web enumeration, several sensitive directories were discovered, including an exposed installation endpoint located at “/install/install.php”.

The presence of this installer on a live production system proved to be a critical security flaw. The PHP application lacked safeguards to verify whether it had already been installed, allowing the setup process to be rerun.

After analyzing a suspicious domain shared on X, the researcher reinitialized the application by configuring a controlled MySQL instance and supplying the installer with connection details.

As part of the process, the system created a new database schema. It prompted the creation of an administrator account, effectively granting full administrative access.

Discovery on X (Source: Potato.id)
Discovery on X (Source: Potato.id)

Unlocked PHP Installation Page Exposed Malware

Initially, accessing the dashboard resulted in a 500 Internal Server Error due to inconsistencies between the application and the newly configured database.

However, after the threat actor restored the backend configuration, the researcher regained access without having to log in again.

This was possible because the application relied on server-side session handling without properly invalidating active sessions.

The previously issued session token remained valid, allowing seamless access to the administrative panel.

Further analysis revealed that the platform was a relatively simple but functional malware distribution system.

Redirect to Malware site (Source: Potato.id)
Redirect to Malware site (Source: Potato.id)

It consisted of a PHP-based admin panel connected to a MySQL database, with file storage used to host malicious payloads.

The system generated dynamic download pages based on URL parameters and used multi-stage redirection chains to route victims.

In several cases, intermediary services were used before redirecting users to the final malware-hosting domain, helping the attackers evade detection.

The administrative dashboard included features for managing downloads, tracking visitor activity, and configuring campaign settings, indicating a structured operation rather than a basic phishing setup.

Forbidden Access (Source: Potato.id)
Forbidden Access (Source: Potato.id)

Despite its functionality, the infrastructure suffered from weak security practices, particularly around deployment and session management.


Indicators of compromise (IoCs):

Domains: micronsoftwares[.]com, wetransfer[.]ICU.

SHA256: 7b03fb383a5ce784a3cb9b0f8a76a84e984d14e553de5d98faff3d07d9793085.

According to Potato, in a report shared with Cybersecurity News, this incident highlights how even active threat actor infrastructure can be compromised by simple misconfigurations.

The failure to turn off installation scripts and enforce proper session controls created an unintended entry point into the system.

Although the researcher briefly gained administrative access, the vulnerability was later patched by the operators. The malicious infrastructure, however, remains active and continues to distribute malware.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.