Sansec segnala sfruttamento massivo di PolyShell dal 19 marzo e scansioni da oltre 50 IP. Il malware usa WebRTC DataChannels (DTLS su UDP) per caricare payload ed aggirare CSP e il monitoraggio HTTP.
Part of the PlainSec briefing for 2026-03-27
Every edition of this story: Store Magento Colpiti da Skimmer WebRTC che sfrutta PolyShell