New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
2026-06-05T13:24:09Z•f5dc1b1f2e24fe3010e39d514b6182204f555498aaef4314b70a46ce46b3e932
China-linkedCisco Unified CMEverest FormsGitHub token theftHTTP/2 DoSIISKnown Exploited VulnerabilityMagentoMicrosoft 365 Android token leakPCPJackPoC availableRCERedisSMTP relaySSRFWordPressautonomous-AI bug huntingcloud compromiseespionageweb shell
What happened
A broad set of high-risk incidents and vulnerabilities were reported: a China-linked espionage cluster OP-512 is targeting Microsoft IIS servers with a custom web‑shell framework; active exploitation of a critical WordPress plugin RCE in Everest Forms Pro (CVE-2026-3300); Cisco Unified CM patched an SSRF-to-root bug with public PoC (CVE-2026-20230); cloud servers across AWS/GCP/Azure were hijacked by PCPJack to build a covert SMTP relay; and multiple other severe issues were disclosed including a Redis authenticated RCE found by an autonomous tool (CVE-2026-23479), a Magento extension RCE (CVE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- f5dc1b1f2e24fe3010e39d514b6182204f555498aaef4314b70a46ce46b3e932
- Enrichment time
- 2026-06-05T13:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.