Security researchers at Huntress have detailed a multi-stage intrusion in which a threat actor compromised three web servers belonging to a popular recreation management platform used by local municipalities and parks organisations, planting webshells and going after payment card data. The activity, first observed on 10 September 2026, began noisily. Over roughly six hours the The post Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data appeared first on IT Security Guru.
First seen on itsecurityguru.org
Jump to article: www.itsecurityguru.org/2026/09/30/attacker-signs-up-as-a-member-to-plant-webshells-on-parks-and-recreation-platform-hunts-for-card-data
![]()

