New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

2026-06-05T13:24:09Zf5dc1b1f2e24fe3010e39d514b6182204f555498aaef4314b70a46ce46b3e932
China-linkedCisco Unified CMEverest FormsGitHub token theftHTTP/2 DoSIISKnown Exploited VulnerabilityMagentoMicrosoft 365 Android token leakPCPJackPoC availableRCERedisSMTP relaySSRFWordPressautonomous-AI bug huntingcloud compromiseespionageweb shell

What happened

A broad set of high-risk incidents and vulnerabilities were reported: a China-linked espionage cluster OP-512 is targeting Microsoft IIS servers with a custom web‑shell framework; active exploitation of a critical WordPress plugin RCE in Everest Forms Pro (CVE-2026-3300); Cisco Unified CM patched an SSRF-to-root bug with public PoC (CVE-2026-20230); cloud servers across AWS/GCP/Azure were hijacked by PCPJack to build a covert SMTP relay; and multiple other severe issues were disclosed including a Redis authenticated RCE found by an autonomous tool (CVE-2026-23479), a Magento extension RCE (CVE

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
f5dc1b1f2e24fe3010e39d514b6182204f555498aaef4314b70a46ce46b3e932
Enrichment time
2026-06-05T13:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework · Baitaphish