WordPress Comment Activates Backdoor Via SQL Trigger

Attackers are using SQL triggers as a backdoor to create a malicious admin user whenever a special comment is submitted to an infected WordPress website.
ALFA TEaM v4.1 Web Shell New Features

A new PHP web shell by ALFA TEaM that has some interesting new features like the ability to create a cPanel phishing page that blocks the victim from a part of their website until they interact with the phishing page.
Real-time Phishing Kit Targets Banco Itau Business Accounts

A phishing kit targeting Banco Itau users that has real-time capabilities and QR codes to gain unauthorized access to victim accounts.
Magento 2 PHP Skimmer 0x3C Captures Customer Data To Image File

A PHP skimmer injected into a Magento 2 core file that captures POST data on the cart checkout page and saves the stolen data to an image file on the hosting server.