Cyber Investigations

A technical deep dive into wp2shell

• Cyber Investigations Media

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 18:41

Hackers are exploiting critical vulnerabilities in WordPress, ServiceNow and SonicWall turning trusted websites, cloud platforms and VPN appliances into pathways for administrator access, remote code execution and malware deployment.

In this cybersecurity news episode, we break down a WordPress exploit chain involving route confusion and SQL injection, a ServiceNow pre-authentication sandbox escape, and SonicWall SMA1000 zero-days used to gain root access and install custom Java malware.

Learn how attackers abuse server-side request forgery, command injection, sandbox escapes, WebSocket tunnelling, Java instrumentation agents, webshells and memory-resident malware. We also explain why broken trust boundaries, exposed internal services and weak validation between system components create such dangerous attack paths.

This technical cyber threat analysis is designed for cybersecurity professionals, students, ethical hackers and anyone studying penetration testing, vulnerability research, incident response, malware analysis, network security or cloud security.

Thanks for listening.

Follow the podcast for more cyber security news, malware analysis, threat intelligence, AI security, and real-world attacker tradecraft.

For contact or story tips, email: cyberinvestigationsau@gmail.com

Disclaimer: This podcast is for education and awareness only. Technical details are shared to help defenders improve detection, response, and security controls.

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

Cyber Investigations Artwork

Cyber Investigations

Cyber Investigations Media