Sponsor of the Day:
Jerkmate
https://portswigger.net/burp/documentation/desktop/testing-workflow/vulnerabilities/input-validation/command-injection/exfiltrate-data
Exploiting OS command injection vulnerabilities to exfiltrate data with Burp Suite - PortSwigger
Once you have identified a request that is vulnerable to asynchronous OS command injection, you can attempt to exfiltrate the output from injected commands ...
os command injectionburp suite portswiggerexploitingvulnerabilitiesexfiltrate
https://blog.knowbe4.com/malicious-pdfs-carry-stealthy-backdoor
New Malicious PDFs Carry Stealthy Backdoor And Exfiltrate Data Via Email
Dec 26, 2025 - The Turla threat group, certainly Russian-speaking and widely attributed to Russian intelligence services, is back with a new phishing technique.
stealthy backdoordata vianewmaliciouspdfs
https://www.stepsecurity.io/blog/pgserve-compromised-on-npm-malicious-versions-harvest-credentials
CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentials and Exfiltrate...
On April 21, 2026, malicious versions of pgserve were published to npm. pgserve is an embedded PostgreSQL server for development — zero config,...
pgservecompromisednpmmaliciousversions