Reports
Public security notes and defensive observations from markcardiff.tech. Reports are written for public consumption: concise, cautious on attribution, and focused on practical defensive takeaways.
A public-safe incident report on a redacted WordPress support-site compromise involving rogue plugin code, modified plugin JavaScript, blockchain-backed configuration, and ClickFix-style malware lures.
wp2shell: WordPress Core CVE-2026-63030 Remote Code Execution /reports/wp2shell-wordpress-core-cve-2026-63030.htmlA public defensive vulnerability brief on CVE-2026-63030, affected WordPress Core versions, fixed releases, exposure impact, and high-level SOC watchpoints.
ShinyHunters / UNC6240: Oracle PeopleSoft CVE-2026-35273 Campaign /reports/shinyhunters-oracle-peoplesoft-cve-2026-35273.htmlA public threat intelligence report on ShinyHunters exploitation of Oracle PeopleSoft, including public IOCs, TTPs, timeline graphics, and SOC detection ideas.
DragonForce Ransomware: From Opportunistic RaaS to Cartel-Style Extortion Platform /reports/dragonforce-ransomware-research.htmlA research-focused public overview of DragonForce ransomware, its affiliate model, cartel positioning, reported payload lineage, timeline, and SOC watchpoints.
SSH Password Guessing Activity Observed Against markcardiff.tech /reports/ssh-password-guessing-observations.htmlA public write-up of opportunistic SSH password guessing activity, top usernames, source infrastructure context, and high-level defensive interpretation.
Publication posture
Reports intentionally avoid sensitive operational detail and focus on externally safe observations, limitations, and defensive interpretation.
Navigation
Return to the landing page or open a report from the listing above.