National Cyber Warfare Foundation (NCWF)

Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers


0 user ratings
2026-04-03 17:10:41
milo
Blue Team (CND)
Threat actors are increasingly using HTTP cookies as a control channel for PHP-based web shells on Linux servers and to achieve remote code execution, according to findings from the Microsoft Defender Security Research Team.
"Instead of exposing command execution through URL parameters or request bodies, these web shells rely on threat actor-supplied cookie values to gate execution,



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/04/microsoft-details-cookie-controlled-php.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.