markcardiff.tech:/reports/
root@markcardiff:~/reports$ ls -la public-reports

Reports

Public security notes and defensive observations from markcardiff.tech. Reports are written for public consumption: concise, cautious on attribution, and focused on practical defensive takeaways.

Status online
Format static HTML
Theme terminal
WordPress ClickFix-Style Web Compromise /reports/wordpress-clickfix-style-web-compromise.html

A public-safe incident report on a redacted WordPress support-site compromise involving rogue plugin code, modified plugin JavaScript, blockchain-backed configuration, and ClickFix-style malware lures.

wp2shell: WordPress Core CVE-2026-63030 Remote Code Execution /reports/wp2shell-wordpress-core-cve-2026-63030.html

A public defensive vulnerability brief on CVE-2026-63030, affected WordPress Core versions, fixed releases, exposure impact, and high-level SOC watchpoints.

ShinyHunters / UNC6240: Oracle PeopleSoft CVE-2026-35273 Campaign /reports/shinyhunters-oracle-peoplesoft-cve-2026-35273.html

A public threat intelligence report on ShinyHunters exploitation of Oracle PeopleSoft, including public IOCs, TTPs, timeline graphics, and SOC detection ideas.

DragonForce Ransomware: From Opportunistic RaaS to Cartel-Style Extortion Platform /reports/dragonforce-ransomware-research.html

A research-focused public overview of DragonForce ransomware, its affiliate model, cartel positioning, reported payload lineage, timeline, and SOC watchpoints.

SSH Password Guessing Activity Observed Against markcardiff.tech /reports/ssh-password-guessing-observations.html

A public write-up of opportunistic SSH password guessing activity, top usernames, source infrastructure context, and high-level defensive interpretation.

Publication posture

Reports intentionally avoid sensitive operational detail and focus on externally safe observations, limitations, and defensive interpretation.

Navigation

Return to the landing page or open a report from the listing above.