Search/netgear
Vendor

netgear

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
rax45 firmware
Connections
589 relationships
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities," Fortinet FortiGuard Labs said. Evidence indicates that the botnet has been active in the wild since July 2026, exploiting known vulnerabilities in publicly-accessible devices to deliver the malware. Some of the security flaws weaponized by the botnet are below - CVE-2007-3010 - Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability CVE-2016-6277 - NETGEAR Multiple Routers Remote Code Execution Vulnerability CVE-2018-14558 - Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability CVE-2019-14931 - Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability CVE-2020-10987 - Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability CVE-2021-46422 - Telesquare SDT-CW3B1 Command Injection vulnerability CVE-2022-37055 - D-Link Routers Buffer Overflow Vulnerability CVE-2024-29269 - Telesquare TLR-2005KSH Command Injection Vulnerability CVE-2025-10123 - D-Link DIR-823X Command Injection Vulnerability CVE-2025-55583 - D-Link DIR-868L B1 router Command Injection Vulnerability Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture. The script subsequently clears Bash history to erase traces of the attack. Upon execution, the binary checks for the presence of analysis tools, sandboxes, and virtual environments, before establishing encrypted communications with a command-and-control (C2) server on port 443. The port choice is intentional as it allows the malware to blend in with expected HTTPS traffic at the network perimeter. Once the host is registered with the C2 server, it waits for further commands to take action. It supports a number of commands that allow an operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the host into a proxy node, launch an SSH brute-force scanner, trigger DDoS attacks over DNS, TCP, and UDP, and fire an HTTP-based exploit dispatcher for exploiting known flaws. The CVE attack module includes the ability to launch exploits for eight security flaws impacting Hikvision (CVE-2021-36260), Atlassian Confluence (CVE-2022-26134), WSO2 (CVE-2022-29464), Zyxel (CVE-2022-30525), TP-Link (CVE-2023-1389), PHP (CVE-2024-4577), D-Link (CVE-2024-10914), Kubernetes (CVE-2025-1974). The proxy component, on the other hand, transforms an infected router, firewall, IP camera, or other edge device into a SOCKS5 proxy that the threat actor can leverage as a network relay to conduct follow-on operations and evade detection. "This capability significantly increases the value of an infected host to attackers," Fortinet said. "The victim's IP address can be used to disguise malicious traffic, bypass geographic restrictions, or provide access to internal networks through an already compromised machine." "In larger botnets, the same functionality could also be used to build a distributed proxy infrastructure, enabling anonymous traffic forwarding or monetization through residential and enterprise proxy services."
thehackernews.comAug 17, 2026extracted
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. The malware's capabilities extend beyond turning devices into proxy nodes and include credential theft, SSH brute-forcing, and launching distributed denial-of-service (DDoS) attacks. Since at least July, Evooo1Bot has been targeting devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link across various regions by exploiting known vulnerabilities. “While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities,” Fortinet researchers found. Newer builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. However, Fortinet notes that some of the embedded exploits are not correctly implemented, leading to failed exploitation. When leveraging an exploit successfully, a script downloads one of the 12 available malware builds that match the host’s CPU architecture, then clears Bash history to wipe traces of the attack. Evooo1Bot uses encrypted command-and-control (C2) communications over port 443 and performs extensive checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before it launches on the infected device. Persistence is established through systemd, SysV init, shell profiles, and rc.local, while a cron job attempts to re-download the payload every five minutes. An interactive shell gives operators direct control over compromised systems, while file-transfer commands support uploads and downloads. The malware also features a credential sniffer module that monitors ‘/proc/net/tcp’ and attempts to capture HTTP Basic Authentication and Cookie headers. The SOCKS5 module supports direct listening and reverse-relay modes, allowing attackers to conceal malicious traffic, circumvent geographic restrictions, or potentially access networks through compromised systems. Fortinet says proxying sessions run independently, and multiple can be opened simultaneously, allowing monetization through residential proxy services if the botnet grows large enough. The SSH scanner module uses 150 username and password combinations for enterprise-oriented accounts, and performs post-login checks to avoid honeypots. Finally, the DDoS module that was inherited by Mirai supports 16 flood methods, including UDP, DNS, SYN, ACK, GRE, fragmented TCP, and an HTTP flood with customizable requests. To defend against botnet malware, keep your IoT devices’ firmware updated, replace default admin credentials, turn off remote access panels, and replace devices when the vendor no longer provides support for them. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 15, 2026extracted
New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices. A Taiwan-based security researcher at Fortinet’s FortiGuard Labs, Yi Ping (Cara) Lin, shared an analysis of the new botnet family on August 13, which she called ‘Evooo1Bot’ after the hardcoded string ‘evooo1’ found in every binary. The botnet was discovered after observed exploitation of the following vulnerabilities: CVE-2007-3010: Alcatel OmniPCX Enterprise remote code execution (RCE) vulnerability CVE-2016-6277: NETGEAR Multiple Routers RCE vulnerability CVE-2018-14558: Tenda AC7, AC9 and AC10 Routers command injection vulnerability CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote command injection vulnerability CVE-2020-10987: Tenda AC1900 Router AC15 Model RCE vulnerability CVE-2021-46422: Telesquare SDT-CW3B1 command injection vulnerability CVE-2022-37055: D-Link Routers buffer overflow vulnerability CVE-2024-29269, Telesquare TLR-2005KSH command injection vulnerability CVE-2025-10123, D-Link DIR-823X command injection vulnerability CVE-2025-55583: D-Link DIR-868L B1 router command injection vulnerability All payload callbacks for these exploitation attempts pointed to the same loader URL at 91.92.40[.]118/wget.sh, linked to Evooo1Bot. Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions. Evooo1Bot, A Sophisticated Mirai-Class Botnet Evooo1Bot reuses the distributed denial-of-service (DDoS) engine from the Mirai source code. Mirai is a notorious malware strain that infects internet-of-things (IoT) devices using default credentials, turning them into a massive networks – a botnet – to launch DDoS attacks. Its source code was publicly leaked in September 2016 on Hack Forums by user ‘Anna-senpai,’ later unmasked by the FBI as college student Paras Jha along with co-creators Josiah White and Dalton Norman. Originally built to target Minecraft servers and sell DDoS-protection services, the creators released the code to flood the web with noise and obscure their identities as law enforcement closed in, inadvertently spawning countless modern malware variants that continue to reuse Mirai's DDoS engine today. Despite working from the Mirai framework, the developers of Evooo1Bot have significantly extended their malware with numerous capabilities, including: Encrypted command-and-control (C2) communications and a 28-command remote administration interface An SSH brute-force scanner A reverse SOCKS relay module Multiple layers of string obfuscation using AES-256-CTR, ChaCha20 and XOR-based key derivation A credential sniffer An integrated exploit arsenal targeting multiple known vulnerabilities across IoT devices, networking equipment and enterprise applications Lin highlighted that the SOCKS relay module is “arguably the most operationally significant” as it transforms a compromised edge device into a persistent proxy, allowing the attacker to conceal their true origin, pivot into internal networks and conduct follow-on operations through the victim's infrastructure. “These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware,” Lin wrote.
infosecurity-magazine.comAug 14, 2026extracted
New Mirai variant adds stealth capabilities to notorious botnet code
New Mirai variant adds stealth capabilities to notorious botnet code Malware that adds multiple capabilities to the infamous Mirai botnet code has been actively exploiting vulnerabilities in internet-facing hardware for at least a month, researchers said Thursday. Dubbed Evooo1Bot, the Linux-based malware targets routers and other hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare, according to researchers at FortiGuard Labs. Unpatched bugs in those devices allow Evooo1Bot to spread and carry out potential malicious activity, the researchers said. Evooo1Bot appears to be previously undocumented, they said. The report does not specify how many devices have been compromised worldwide, but the company’s telemetry shows activity concentrated in North America, South America, Europe, India, China and Japan. Beyond Mirai’s usual distributed denial-of-service (DDoS) functions, Evooo1Bot’s features include encrypted communications with command-and-control servers; a scanner that looks for Secure Shell (SSH) code and skips devices clearly set up as honeypots for malicious traffic; and a “sniffer” that looks for default access credentials that haven’t been changed since a device was put into service. “These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware,” FortiGuard Labs said. The malware also abuses the widely used SOCKS protocol that allows devices to connect with servers through a proxy. That capability “is arguably the most operationally significant,” FortiGuard Labs said. “By transforming a compromised router, firewall, IP camera, or other edge device into a persistent proxy, the malware enables attackers to conceal their true origin, pivot into internal networks, and conduct follow-on operations through the victim's infrastructure.” The source code for Mirai was publicly released in 2016, and in the decade since, it has served as the basis for numerous variants that have drawn the attention of law enforcement agencies and cybersecurity specialists. Descendants such as Aisuru and KimWolf were targeted by agencies from the U.S., Canada and Germany in March. A Canadian man was charged in May with running KimWolf. Joe Warminsky has been the news editor for Recorded Future News since 2022. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.
therecord.mediaAug 13, 2026extracted
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets. The Federal Court released a public version of the ruling on June 15. It is the first time the Canadian Security Intelligence Service has used its threat reduction warrant powers this way. The warrant let CSIS alter, degrade, and destroy botnet data on the infected machines and cut the devices loose from the networks. The targets were Canada-based servers, small office and home office (SOHO) routers, and Internet of Things devices: Ring doorbells, security cameras, TVs, and other Wi-Fi-enabled appliances. Justice Catherine Kane granted the warrant on May 1, 2024, renewed it that August, and issued the confidential reasons in February 2026. The warrant stayed out of public view for more than two years, until this month's redacted release. CSIS needed the order because the cleanup would likely have been a crime without it. Reaching into someone else's device and wiping data is computer mischief under the Criminal Code, so the Service needed a judge's sign-off before touching the machines. The court found the threat to Canada clearly established and imminent, and the measures necessary, reasonable, and proportional. It stressed the operation went after devices, not people: no user identities sought, no content intercepted, any personal data swept up incidentally destroyed. The two botnets ran the standard relay playbook. A command tier issued the orders; a layer of infected devices relayed the traffic. By routing through hijacked Canadian hardware, a foreign state can look like an ordinary connection, a home worker, or an ISP customer, while it probes critical infrastructure, government, and military networks. The owner of the infected doorbell gets left looking responsible for traffic they never sent. The court flagged the energy sector among the targets and warned that the adversaries could direct the botnets to probe and potentially disrupt Canadian infrastructure. The public ruling settles the what: two foreign adversaries, a threat to Canada's security, the court found clearly made out. What it strips is the who. The timing and the technique match a specific moment in early 2024, but The Bureau, which surfaced the ruling, says it cannot tell from the redacted reasons whether Canada's two botnets were both Chinese, both Russian, or one of each. The foreign-state hand is a finding. The flag is the redaction. Same Tactic, a Different Authority That moment was a run of court-ordered botnet cleanups in the United States. In a December 2023 operation, the FBI used the botnet's own command channel to delete the KV-botnet malware from hundreds of U.S. SOHO routers, mostly end-of-life Cisco and NetGear boxes that the China-linked Volt Typhoon was using to hide access it had planted ahead of a possible crisis inside American communications, energy, water, and transportation systems. Weeks later, it ran a near-identical operation against a separate network of Ubiquiti routers that Russia's GRU, the APT28 group, had turned into an espionage relay. Canada's cyber centre had joined the allied warnings about state actors abusing SOHO and IoT gear. Same court-ordered shape both times: neglected consumer gear, a state operator, a judge signing off on remote disinfection. The difference is who holds the warrant. The U.S. operations were law enforcement, FBI, and DOJ acting under search-and-seizure authority. Canada's is an intelligence service using threat reduction measures, the CSIS's power to actively disrupt a threat rather than just collect intelligence on it, written into the CSIS Act years ago and reworked in the National Security Act, 2017, which took effect in 2019. CSIS had never reached for it like this until now. It Still Comes Down to Old Routers The lesson for defenders is the boring one. The botnets feed on the gear nobody maintains: end-of-life routers still wired into the network, IoT kits that never took their last firmware update, anything sitting on default credentials with a management panel facing the internet. A government cleanup does not touch that. In the U.S. operations, the malware came off, but the weaknesses stayed, and a reboot or factory reset could undo the fix and reopen the door to reinfection. Retiring the dead hardware and locking down what stays is on the owner, not the agency that cleaned up after them. One loose end the public ruling does not close: the application, by The Bureau's account, leaned on IP addresses CSIS had collected without a warrant, weeks after the Supreme Court of Canada held in R. v. Bykovets that an IP address carries a reasonable expectation of privacy. Whether that squares with CSIS's collection authorities, and whether the owners of the disinfected devices were ever told, stay open.
thehackernews.comJun 22, 2026extracted
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories
You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes. The supply chain is messy. Packages you did not check are stealing data, adding backdoors, and spreading. Attacking the systems behind apps is easier than breaking the apps themselves. The exploits are simple but still work, giving attackers easy access. AI tools are also part of the problem now. They trust bad input and take real actions, which makes the damage bigger. Then there are quieter issues. Apps take data they should not. Devices behave in strange ways. Attackers keep testing what they can get away with. No noise. Just ongoing damage. Here is the list for this week’s ThreatsDay Bulletin. State-backed crypto heistInter-blockchain communication protocol LayerZero has revealed that North Korean threat actors tracked TraderTraitor may have been behind the recent hack of decentralized finance (DeFi) project KelpDAO, resulting in the theft of $290 million. "The attack was specifically engineered to manipulate or poison downstream RPC infrastructure by compromising a quorum of the RPCs the LayerZero Labs DVN relied upon to verify transactions," LayerZero said. KelpDAO, in a post on X, said, "Two RPC nodes hosted by LayerZero were compromised. A simultaneous DDoS attack was launched against the third RPC node. This was an attack on LayerZero's infrastructure. Kelp's own systems were not involved in building or operating that infrastructure." Meanwhile, the Arbitrum Security Council has temporarily frozen the 30,766 ETH being held in the address on Arbitrum One that is connected to the KelpDAO exploit. In an analysis published today, Chainalysis said: "Crucially, this was not a smart contract hack, but a sophisticated attack on off-chain infrastructure. The attackers compromised internal RPC nodes and DDoS’d external nodes to feed false data to a single-point-of-failure verification network (a 1-of-1 DVN setup). This tricked the Ethereum contract into releasing funds based on a phantom token 'burn' on the source chain." It's worth noting that TraderTraiter was attributed to the mega Bybit hack in early 2025 that led to the theft of $1.5 billion in digital assets. Recently, Lazarus Group was also linked to the $285 million theft from the Drift Protocol. Active RCE exploitsSeparately, VulnCheck has warned of attacks attempting to exploit two flaws in MajorDoMo, a smart home automation platform. While CVE-2026-27175 is a critical command injection vulnerability that started seeing exploitation on April 13, CVE-2026-27174 allows unauthenticated remote code execution via the PHP console in the admin panel and was first detected on April 18. "CVE-2026-27175 was exploited to drop a PHP webshell that delivers persistent backdoor access," VulnCheck said. "CVE-2026-27174 saw exploitation that ended in a Metasploit php/meterpreter/reverse_tcp staged payload." Other vulnerabilities that have witnessed exploitation efforts include CVE-2025-22952, an SSRF in Elestio Memos, and CVE-2024-57046, an authentication bypass in NETGEAR DGN2200 routers. Supply chain malware surgeA number of malicious packages have been discovered in the npm registry: ixpresso-core, forge-jsx, @genoma-ui/components, @needl-ai/common, rrweb-v1, cjs-biginteger, sjs-biginteger, bjs-biginteger, @fairwords/websocket, @fairwords/loopback-connector-es, @fairwords/encryption, js-logger-pack, and @kindo/selfbot. These packages come with features to steal sensitive data from compromised hosts, perform system reconnaissance, andimplant an SSH backdoor by injecting the attacker's public key into ~/.ssh/authorized_keys, deliver an information stealer, and spread the XWorm remote access trojan (RAT). The packages published under the "@fairwords" scope have also been found to self-propagate to all npm packages using the victim's token and attempt cross-ecosystem propagation to PyPI via .pth file injection. New versions of js-logger-pack have since been found to leverage the Hugging Face repository to poll for updates and use it as a data-theft destination. Also detected was the compromise of @velora-dex/sdk (version 9.4.1) to decode and execute a Base64 payload that fetches a shell script from a remote server that, in turn, downloads and persists a Go-based remote access trojan called minirat on macOS systems. Another legitimate package to be compromised was mgc (versions 1.2.1 through 1.2.4), which was injected with a dropper that detects the operating system and fetches a platform-specific RAT from a GitHub Gist to exfiltrate valuable data. AI prompt injection surgeForcepoint has detected 10 new indirect prompt injection (IPI) payloads targeting artificial intelligence (AI) agents with malicious instructions designed to achieve financial fraud, data destruction, API key theft, and AI denial-of-service attacks. "Regardless of the specific payload technique or attacker intent, every case follows the same fundamental sequence: the attacker poisons web content, hides the payload from human view, waits for an AI agent to ingest the page, exploits the LLM's inability to distinguish trusted instructions from attacker-controlled content, and triggers a real-world action with a covert exfiltration return channel back to the attacker," the company said. Covert browser data accessThe Claude desktop app has been found granting itself permission to access web browser data, even if some browsers haven't even been installed on a user's computer, web privacy expert Alexander Hanff said. The app has been spotted placing configuration files in preset locations for Chromium-based browsers like Brave, Google Chrome, Microsoft Edge, and Vivaldi. The Native Messaging manifest files pre-authorize Claude to interact with the browser even before the user installs it. The issue has been described as a case of dark pattern that violates privacy laws in the E.U. Hardware display protectionThe U.K. National Cyber Security Centre (NCSC) has unveiled a new technology called SilentGlass that's designed to protect video connections from cyber attacks. "SilentGlass, a plug-and-play device, actively blocks anything unexpected or malicious between HDMI and Display Port connections and screens," NCSC said. "Already successfully deployed on Government estates, SilentGlass is now available for anyone to buy and use. It has been approved for use in the most high-threat environments." Passkeys replace passwordsIn a related development, the NCSC also endorsed passkeys as the default authentication standard and the "first choice of login" for access to all digital services. "Passkeys are a newer method for logging into online accounts, which do much of the heavy lifting for users, only requiring user approval rather than needing to input a password," NCSC said. "This makes passkeys quicker and easier to use and harder for cyber attackers to compromise." It also said the majority of cyber harms to individuals begin with criminals stealing or compromising login details, which makes passkey adoption a "huge leap" in boosting resilience to phishing attacks. More than 50% of active Google services users in the U.K. are said to be already using passkeys. Backdoor sabotage claimsReports from Iranian media have claimed that hardware made by Cisco, Juniper, Fortinet, and MikroTik either rebooted or disconnected during recent attacks on Iran, despite the country being cut off from the global internet. "The most striking and suspicious aspect of this incident is its precise timing and the lack of access to the international internet at that moment," Iranian news website Entekhab said. "This disruption occurred at a time when international gateways were effectively blocked or inaccessible; therefore, attributing this chain collapse to 'a simple cyber attack from beyond the borders' is not only unconvincing but also reveals the traces of deep-seated sabotage embedded within the equipment." The report hypothesizes the presence of hidden firmware backdoors or rogue implants within compromised devices, creating a dormant botnet that's activated when a certain event occurs without the need for internet access. The other possibility is a supply chain compromise. "If the chips or installation files of Cisco and Juniper products are compromised before entering the country, even replacing the operating system will not solve the problem, because the root of the problem is embedded in the hardware and read-only memory (ROM)," the report said. These arguments have found purchase in China, whose state media agency Xinhua called U.S.-made equipment the "real trojan horse." The disclosure comes as DomainTools revealed that the various hacktivist personas adopted by Iran, such as Homeland Justice, Karma, and Handala, "constitute a coordinated, MOIS-aligned cyber influence ecosystem operating under multiple branded identities that serve distinct but complementary operational roles." Ransomware infighting escalatesThe Krybit ransomware group has hacked the website of rival ransom group 0APT after the latter threatened to dox Krybit's members. According to security firm Barricade, 0APT leaked the complete database of the Krybit ransomware operation, including victim records, plaintext credentials, Bitcoin wallets, encryption tokens, and a 56MB exfiltration file inventory. In return, Krybit has hit back by compromising 0APT's server within 48 hours, defacing their data leak site, and publishing source code, bash history, Nginx logs, and system files. To rub salt into the wound, the group listed 0APT as victim #1 on their own leak site. Stealth malware-as-a-serviceThere is a new cryptor-as-a-service platform called FUD Crypt (fudcrypt[.]net). "For $800 to $2,000 per month, subscribers upload an arbitrary Windows executable and receive a multi-stage deployment package that attempts automatic DLL sideloading, in-memory AMSI and ETW interference, silent UAC elevation via CMSTPLUA, and Windows Defender tamper via Group Policy on Enterprise builds," Ctrl-Alt-Intel said. Formbook phishing surgeTwo different phishing campaigns targeting Greek, Spanish, Slovenian, Bosnian, Latin, and Central American companies are using different techniques to deliver Formbook malware. "FormBook is a data-stealing malware that targets Windows systems, primarily distributed through phishing emails with malicious attachments," WatchGuard said. “It collects sensitive information like login credentials, browser data, and screenshots, using advanced evasion techniques to avoid detection.” Stealth .NET execution abuseA highly sophisticated, multi-stage post-exploitation framework has been observed targeting organizations in the Middle East and EMEA financial sectors. "The threat actor leverages a legitimate, digitally signed Intel utility (IAStorHelp.exe) by abusing the .NET AppDomainManager mechanism, effectively turning a trusted binary into a stealthy execution container," CYFIRMA said. "This approach allows malicious code to be executed within a trusted environment. It bypasses conventional security controls without modifying the original signed binary." Because AppDomainManager hijacking enables stealth execution within a trusted signed binary, it allows malicious code to run without modifying the original executable, effectively bypassing code-signing trust controls. The attack begins with a phishing email containing a ZIP archive, which contains an LNK file masquerading as a PDF document to execute "IAStorHelp.exe." It's currently not known who is behind the campaign, but the level of sophistication, modular design, and operational discipline suggest capabilities consistent with advanced threat actors. RAT plus adware bundleA new malware campaign is spreading both a remote access trojan and adware together, allowing attackers to establish persistent access and make financial profits. The attack has been found to leverage a loader to deliver Gh0st RAT trojan and CloverPlus adware, an unwanted software designed to install advertising components and change browser behavior, such as startup pages and pop-up ads, per Splunk. macOS stealth execution abuseIn a new analysis, Cisco Talos revealed that bad actors can bypass security controls in Apple macOS by repurposing native features like Remote Application Scripting (RAS) for remote execution and abusing Spotlight metadata (Finder comments) to stage payloads in a way that evades static file analysis. "Because Finder is scriptable over RAE, the comment of a file on a remote machine can be set via the “eppc://” protocol. By Base64 encoding a payload locally, a multi-line script can be stored within this single string field. The make new file command handles the creation of the target file, ensuring that no pre-existing file is required," Talos said. "The payload resides entirely within the Spotlight metadata, a location that remains largely unexamined by standard endpoint detection and response (EDR) solutions. This creates a stealthy staging area where malicious code can persist on the disk without triggering alerts associated with suspicious file contents." In addition, attackers can move toolkits and establish persistence using built-in protocols such as SMB, Netcat, Git, TFTP, and SNMP operating entirely outside the visibility of standard SSH-based telemetry. In some cases, adversaries can also bypass built-in restrictions by using Terminal as a proxy for execution, encoding payloads in Base64 and deploying them in stages. LLM agent testing frameworkA group of academics has released a hackable, modular, and configurable open-source framework called Terrarium for studying and evaluating decentralized LLM-based multi-agent systems (MAS). "As the capabilities of agents progress (e.g., tool calling) and their state space expands (e.g., the internet), multi-agent systems will naturally arise in unique and unexpected scenarios," the researchers said, adding it acts as "an isolated playground for studying agent behavior, vulnerabilities, and safety. It enables full customization of the communication protocol, communication proxy, environment, tool usage, and agents." AI data privacy purgeAccording to Reuters, AI company Clarifai said it has deleted 3 million profile photos taken from dating site OkCupid in 2014. It follows a settlement reached last month between the U.S. Federal Trade Commission (FTC) and Match Group, OkCupid's owner. Clarifai is said to have certified the data deletion to the FTC on April 7, 2026, and deleted any models that trained on the data. The company also emphasized that it hadn't shared the data with third parties. The FTC opened the investigation in 2019, after The New York Times reported that Clarifai had built a training database using OkCupid dating profile photos. The behavior was a direct violation of OkCupid's privacy policy, although Clarifai was not accused of wrongdoing. Zero-credential RCE chainVulnCheck said it's seeing active exploitation of the Apache ActiveMQ Jolokia remote code execution chain that strings together CVE-2026-34197 and CVE-2024-32114. "CVE-2024-32114 removes authentication from the Jolokia endpoint entirely on ActiveMQ versions 6.0.0 through 6.1.1," VulnCheck's Jacob Baines said. "Combined with CVE-2026-34197, that is zero-credential RCE." Stealth phishing lureThere has been a surge in phishing emails utilizing empty subject lines as a way to lure users to actually click and open the email without the usual warning cues. Known as silent subject or null subject phishing, the technique is designed to exploit blind spots in email defenses, as it allows such emails to bypass security filters that rely on analyzing the subject lines for specific keywords that may indicate potential phishing or scam. "Emails with empty subject lines evade user suspicion by exploiting human curiosity," CyberProof said. "The primary objective of a silent subject campaign is to gain initial access through social engineering, leading to credential compromise, unauthorized access, and potential lateral movement within targeted environments, especially focusing on high-value or VIP users." Industrial-scale SIM farmsA Belarus-based turnkey solution is assisting SIM farm operators in supporting cybercrime on an industrial scale. Infrawatch said that it identified 87 instances of ProxySmart control panels in 17 countries that are linked to at least 24 commercial proxy providers and 35 cellular providers. The footprint spans 94 phone farm locations, distributed across 19 U.S. states, as well as countries in Europe and South America. ProxySmart provides an end-to-end platform for operating and monetizing mobile proxy infrastructure, including farm management, device control, customer provisioning, retail proxy sales, and payment handling. It's accessible via a web-based control panel that's self-hosted by the farm operator. Devices in the farms are either physical Android phones or USB 4G/5G modems. The phones are enrolled via an unsigned Android APK package downloaded from the ProxySmart website, with SMS send and receive capability included. Modems are managed through ModemManager, an open-source USB dongle management tool. The ProxySmart service is written in Python and obfuscated using PyArmour. "ProxySmart is publicly associated with a Belarus-based vendor footprint and offers an end-to-end stack for operating and monetizing a physical farm, including device management, automated IP rotation, customer provisioning, plan enforcement, and anti-bot countermeasures," the company said. "Technical analysis indicates operator capabilities consistent with large-scale evasion enablement, including automated IP rotation, remote device control, and network fingerprint spoofing." SIM farms enable a range of cybercrime activity such as smishing, premium-rate number fraud, bot sign-ups, and one-time password interception. In response to the findings, ProxySmart disputed its characterization as a SIM farm, stating it's a "data-path proxy management platform" and that its mobile proxy infrastructure "underpins a wide range of legitimate commercial and research activity" including advertising verification, brand protection, price monitoring, and anti-fraud model training, among others. Telegram under CSAM probeOfcom, the U.K.'s independent communications regulator, has launched an investigation into Telegram under the country's Online Safety Act to examine whether the platform is being used to share child sexual abuse material (CSAM) and is doing enough to combat the threat. "We received evidence from the Canadian Centre for Child Protection regarding the alleged presence and sharing of child sexual abuse material on Telegram, and carried out our own assessment of the platform," Ofcom said. "In light of this, we have decided to open an investigation to examine whether Telegram has failed, or is failing, to comply with its duties in relation to illegal content." In a statement shared with The Record, Telegram said it "categorically denies Ofcom's accusations," adding it has "virtually eliminated the public spread of CSAM on its platform through world-class detection algorithms and cooperation with NGOs." Earlier this year, Ofcom also commenced a probe into X to determine whether the service is taking necessary steps to take down illegal content, including non-consensual intimate images and CSAM. EU cracks disinfo opsThe European Union imposed sanctions on two pro-Russian organizations accused of spreading disinformation and supporting the Kremlin's hybrid influence operations against Europe and Ukraine. The measures target Euromore and the Foundation for the Support and Protection of the Rights of Compatriots Living Abroad (Pravfond). The move is part of the E.U.'s broader effort to counter Russian information and influence operations targeting Europe since the start of Moscow's full-scale invasion of Ukraine in 2022. The E.U. has imposed sanctions on 69 individuals and 19 entities linked to Russian hybrid warfare. Bot farm dismantledUkrainian authorities have dismantled a bot farm that's alleged to have supplied thousands of fake social media accounts to Russian intelligence services for use in disinformation campaigns against Ukraine. The suspected organizer of the network has been detained in the northern city of Zhytomyr, and nearly 20,000 fraudulent online profiles that were used in information operations have been blocked. The suspect is believed to have sold more than 3,000 fake Telegram accounts each month to Russian clients. The accounts were created using Ukrainian mobile phone numbers and then advertised on online platforms used by pro-Russian actors. If convicted, the suspect faces up to six years in prison. Malicious extensions surgeMore than 130,000 users have downloaded and installed malicious Chrome and Edge extensions that, while offering the promised functionality, also implement covert tracking, remote configuration capabilities, and data collection mechanisms.The 12 extensions posed as tools to download TikTok videos and were available through the official Chrome and Edge stores. The activity has been codenamed StealTok. The extensions have been found to use remote configuration to bypass store review. "Beyond privacy concerns, the use of remote configuration endpoints introduces a significant security risk, enabling post-installation behavior changes that bypass marketplace review mechanisms," LayerX said. Joomla SEO spam backdoorIn a new campaign spotted by Sucuri, threat actors are planting a new PHP-based backdoor on Joomla sites to inject SEO spam. The injected script acts as a remote loader to send information about the infected website and awaits further instructions from an attacker-controlled server. "Attackers inject malicious code that silently serves spam content to visitors and search engines, all without the site owner knowing," Sucuri said. "The goal is simple: abuse the site's reputation to push traffic towards products the attacker wants to promote." Post-exfiltration data tradeA new service called Leak Bazaar has been promoted on the Russian-speaking TierOne forum that claims to process data stolen from extortion and ransomware attacks and turn it into "something more legible, more selective and precise, and making it marketable for the general population to ingest." It's advertised by a user named Snow, who joined the forum on March 3, 2026. "What Leak Bazaar is really offering is not a DLS or Data or Dedicated Leak Site in the conventional sense, but a post-exfiltration service layer," Flare said. "It is trying to reassure both suppliers and buyers that the platform can solve the most frustrating part of data theft, which is that a large percentage of exfiltrated material is too noisy, too unstructured, or too cumbersome to use without additional labor." RDP scanning concentrationGreyNoise has disclosed that a small cluster of 21 IP addresses is now responsible for generating nearly half of all the RDP scanning traffic on the public internet. The addresses are registered to ColocaTel (AS213438), a company based in the Seychelles. According to the threat intelligence firm, mass internet scanning activity is now preceding vendor vulnerability disclosures more frequently than before, with 49% of surges arriving within 10 days of disclosure and 78% within 21 days.In a related development, security researcher Morgan Robertson revealed that almost three-quarters of Perforce P4 source code management servers connected to the internet are misconfigured and leaking source code and sensitive files. "The default Perforce settings allow unauthenticated users to create accounts, list existing users, access passwordless accounts, and, until version 2025.1, allowed syncing repositories remotely; potentially exposing intellectual property across more than a dozen sectors, including gaming, healthcare, automotive, finance, and government," Robertson said. "Action is recommended for all Perforce administrators to ensure security hardening, including setting stronger authentication requirements, disabling automatic account creation, and raising security levels." Emerging threat groups surgeVarious new hacktivist, data extortion, and ransomware crews have been spottedin the wild. These include Harakat Ashab al-Yamin al-Islamia, World Leaks, Lamashtu, Payouts King, BravoX, Black Shrantac, NBLOCK, Ndm448, Chip, Ransoomed, and Zollo. None of this is new. That is the problem. Old paths still open, basic checks still skipped, and trust still given where it should not be. Attackers are not doing anything magical, they are just faster and less careful because they do not need to be. The fixes are known but ignored. Patch early, check what you install, limit access, and stop trusting inputs by default. Most of the damage comes from things that were easy to prevent. Same story next week.
thehackernews.comApr 23, 2026extracted
UK warns of Chinese hackers using proxy networks to evade detection
The United Kingdom's National Cyber Security Centre (NCSC-UK) and international partners warned that China-nexus hackers are increasingly using large-scale proxy networks of hijacked consumer devices to evade detection and disguise their malicious activity. This joint advisory, co-signed by agencies from the United States, Australia, Canada, Germany, Japan, the Netherlands, New Zealand, Spain, and Sweden, says the majority of Chinese hacking groups have switched from individually procured infrastructure toward vast bonets of compromised devices, primarily small office and home office routers, along with internet-connected cameras, video recorders, and network-attached storage (NAS) equipment. These massive botnets allow them to route traffic through chains of compromised devices, entering the network at one point, passing through multiple intermediate nodes, and exiting near the intended target to avoid geographic detection. "The NCSC believes that the majority of China-nexus threat actors are using these networks [..], that multiple covert networks have been created and are being constantly updated, and that a single covert network could be being used by multiple actors," the joint advisory reads. "These networks are mainly made up of compromised Small Office Home Office (SOHO) routers, as well as Internet of Things (IoT) and smart devices." One such massive Chinese botnet, known as Raptor Train, infected more than 260,000 devices worldwide in 2024 and was linked by the FBI to malicious activity attributed to the Chinese state-sponsored Flax Typhoon hacking group and Chinese company Integrity Technology Group (sanctioned in January 2025). The FBI disrupted Raptor Train in September 2024 with help from researchers at Black Lotus Labs after linking it to campaigns targeting entities in the military, government, higher education, telecommunications, defense industrial base (DIB), and IT sectors, primarily in the U.S. and Taiwan. A separate network (KV-Botnet) was used by the Chinese state-backed Volt Typhoon threat group and consisted primarily of vulnerable Cisco and Netgear routers that were out of date and no longer received security patches. The FBI also disrupted KV-Botnet by wiping malware from infected routers in January 2024, but Volt Typhoon slowly started reviving it in November 2024 after an initial failed attempt in February. "Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks," said Paul Chichester, NCSC-UK's Director of Operations. Western intelligence agencies that signed the advisory warned that traditional defenses based on blocking static lists of malicious IP addresses are becoming less effective as these botnets continuously add new compromised nodes. Instead, network defenders at small, medium, and large organizations are advised to implement multifactor authentication, map network edge devices, leverage dynamic threat feeds that include known covert network indicators, and, where possible, apply IP allowlists, zero-trust controls, and machine certificate verification. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comApr 23, 2026extracted
Defending against China-nexus covert networks of compromised devices
Defending against China-nexus covert networks of compromised devices Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it Summary With support from the UK Cyber League, this advisory has been jointly released by the National Cyber Security Centre (NCSC-UK) and international partners: Australian Signals Directorate’s (ASD’s) Australian Cyber Security Centre (ACSC) Communications Security Establishment Canada's (CSE's) Canadian Centre for Cyber Security (Cyber Centre) Germany Federal Office for the Protection of the Constitution - Bundesamt für Verfassungsschutz (BfV) Germany Federal Intelligence Service – Bundesnachrichtendienst (BND) Germany Federal Office for Information Security - Bundesamt für Sicherheit in der Informationstechnik (BSI) Japan National Cybersecurity Office (NCO) - 国家サイバー統括室 Netherlands General Intelligence and Security Service - Algemene Inlichtingen- en Veiligheidsdienst (AIVD) Netherlands Defence Intelligence and Security Service - Militaire Inlichtingen- en Veiligheidsdienst (MIVD) New Zealand National Cyber Security Centre (NCSC-NZ) Spain National Cryptologic Centre - Centro Criptológico Nacional (CCN) Sweden National Cyber Security Centre - Nationellt cybersäkerhetscenter (NCSC-SE) United States Cybersecurity and Infrastructure Security Agency (CISA) United States Department of Defense Cyber Crime Center (DC3) United States Federal Bureau of Investigation (FBI) United States National Security Agency (NSA) Its purpose is to provide network defenders with the tools needed to defend against China-nexus cyber actors and their tactic of using large scale networks of compromised devices (covert networks) to route their cyber activity. Introduction Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices. The NCSC believes that the majority of China-nexus threat actors are using these networks (hereafter “covert networks”), that multiple covert networks have been created and are being constantly updated, and that a single covert network could be being used by multiple actors. These networks are mainly made up of compromised Small Office Home Office (SOHO) routers, as well as Internet of Things (IoT) and smart devices. Anyone who is a target of China-nexus cyber actors may be impacted by the use of covert networks. They have been used by Chinese state-sponsored actors Volt Typhoon to pre-position offensive cyber capabilities on critical national infrastructure. The group Flax Typhoon used a different covert network of compromised infrastructure to conduct cyber espionage. The use of covert networks of compromised devices - also known as botnets - to facilitate malicious cyber activity is not new, but China-nexus cyber actors are now using them strategically, and at scale. This advisory describes the typical makeup of a covert network and what they are being used for. It also includes protective advice for organisations being targeted by cyber activity using a covert network as an access vector. Covert Networks Covert networks are used to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. Actors have been observed using them for each phase of their Cyber Kill Chains, from performing scans as part of reconnaissance, to the delivery of malware, communicating with said malware, and exfiltrating stolen data from a victim. They can also be used for general deniable internet browsing, allowing threat actors to research exploitation techniques, new TTPs, and their victims without attribution. Some covert networks are also used by legitimate customers to browse the internet, making it challenging to attribute malicious activity. There is evidence that covert networks used by China-nexus actors are created and maintained by Chinese information security companies. A network known to network defenders as Raptor Train, which in 2024 infected more than 200,000 devices worldwide, was controlled and managed by the Chinese company, Integrity Technology Group. This company was also assessed by the FBI to be responsible for the computer intrusion activities attributed to China-based hackers known as Flax Typhoon. “Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks” NCSC Director of Operations, Paul Chichester Covert networks mostly consist of compromised SOHO routers, but they also pull in any vulnerable device they can exploit at scale. Raptor Train was made up of thousands of SOHO routers and IoT devices, such as web cameras and video recorders, as well as firewalls and Network Attached Storage (NAS) devices. The KV Botnet used by Volt Typhoon was mainly made up of vulnerable Cisco and NetGear routers. The edge devices were vulnerable because they were “end of life” – out of date and no longer receiving updates or security patches by their manufacturers. The cyber security industry has been aware of examples of these networks for some time and has publicly reported on the widespread scale of the threat and its implications. Mandiant Intelligence produced a public blog in May 2024 talking about covert networks in which they highlighted a key issue for defenders – indicator of compromise (IOC) Extinction. If a particular threat group could now come from one of many covert networks, each with potentially hundreds of thousands of endpoints, and each used by multiple threat actors, old network defence paradigms of static malicious IP block lists will be less effective. This is compounded by the dynamic nature of these networks where new nodes will be added as old devices are patched or removed from use. Typical Network Topology The number of covert networks used by China-nexus cyber actors is large, with new networks regularly developed and deployed. The existing covert networks change too, either because of defensive or legal action, or simply as a result of software updates and new exploits being used to target different technologies for incorporation into the network. Because of this, a description of all known covert networks in detail, including how they are constructed and how they communicate, would immediately be out of date – and for most network defenders would not be practically useful. However, most covert networks of compromised devices use the same basic set up. Understanding this generalised structure can aid researchers and defenders by helping them to understand which part of a network they may have found, and how to defend against it. The diagram above illustrates the basic setup of a covert network, where typically an actor will connect to the network via an on-ramp or entry node. Their traffic will be forwarded through multiple compromised devices, used as traversal nodes, before exiting the network from an exit node, usually in the same geographic region as the target. Protective Advice Defending from attackers using covert networks is not straightforward, and defensive tactics will be different based on the levels of resource and the nature of the target organisation. General advice for good cyber security practice should be followed, and some key messages can be found in the appendix of this advisory. The following advice is specifically tailored to steps which can be taken to combat the risk of attacks coming from large, dynamic networks of compromised devices. Further guidance for all organisations facing cyber security threats is available on the NCSC website. This guidance should be considered alongside all applicable laws and regulations of the UK and co-sealing countries relating to the security of networks and data. It will be each organisation’s responsibility to ensure compliance with any such laws and regulations. Organisations should note that following the recommended actions set out below will not remove all risks. All organisations The NCSC recommends the following steps for all affected organisations to either take themselves, or ask their managed service and/or security providers to investigate for them: Map and understand network edge devices, developing a clear understanding of organisational assets and what should be connecting to them. Baseline normal connections, especially to corporate virtual private networks (VPNs) or other similar services. - Would you expect connections from consumer broadband ranges? Leverage available dynamic threat feeds which include covert network infrastructure. Implement multi-factor authentication for remote connections. Smaller organisations should consider creating and actioning a free NCSC Cyber Action Toolkit. Larger or more at-risk organisations Some more comprehensive measures may be appropriate if the risk to an organisation is high enough, to be conducted either in-house or through a security provider: Apply IP address allow lists rather than deny lists for connections to corporate VPNs for remote workers. Use geographic allow lists or profile incoming connections based on operating system, time zones, and/or organisation specific system configuration settings. Implement zero trust policies for connections. Enforce machine certificates for Secure Sockets Layer (SSL) connections. Reduce the internet-facing presence of the IT estate. Investigate machine learning techniques to profile normal network edge activity to detect and block anomalies. The NCSC's Cyber Essentials can help protect organisations of all sizes. Largest or most at-risk organisations If Advanced Persistent Threat (APT) tracking is part of an organisation’s in-house capability, or if it is part of the service provided by a security vendor, consider tracking China-nexus covert networks as APTs in their own right. Active hunting – look for connections from IP addresses likely to be part of a covert network of compromised devices, for instance those hosting SOHO routers or IoT devices. Track and map covert networks reported by industry or government by looking at banners and certificates. Use threat reporting and threat feeds to create and implement dynamic blocklists and create alert rules to detect incoming threats. Consider using NetFlow feeds to look upstream and map covert networks to find new nodes. The NCSC Cyber Assessment Framework provides guidance for organisations under the highest levels of threat, including those operating essential services, in sectors such as energy, healthcare, transport, digital infrastructure and government. MITRE ATT&CK® This advisory has been compiled with respect to the MITRE ATT&CK® framework, a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. Appendix: Cyber Security Best Practices In addition to the protective advice outlined in this advisory, a number of cyber security best practices will also be useful in defending against the activity described in this advisory. Protect your devices and networks by keeping them up to date: use the latest supported versions, apply security updates promptly, use antivirus and scan regularly to guard against known malware threats. See NCSC Guidance: https://www.ncsc.gov.uk/collection/device-security-guidance/policies-and-settings/antivirus-and-other-security-software Set up a security monitoring capability so you are collecting the data that will be needed to analyse network intrusions. See NCSC Guidance: https://www.ncsc.gov.uk/guidance/introduction-logging-security-purposes and https://www.ncsc.gov.uk/information/logging-made-easy Use modern systems and software. These have better security built-in. If you cannot move off out-of-date platforms and applications straight away, there are short term steps you can take to improve your position. See NCSC Guidance: https://www.ncsc.gov.uk/collection/mobile-device-guidance/managing-the-risks-from-obsolete-products Restrict intruders' ability to move freely around your systems and networks. Pay particular attention to potentially vulnerable entry points such as third-party systems with onward access to your core network. During an incident, disable remote access from third-party systems until you are sure they are clean. See NCSC Guidance: https://www.ncsc.gov.uk/guidance/preventing-lateral-movement and https://www.ncsc.gov.uk/guidance/assessing-supply-chain-security Deploy a host-based intrusion detection system. A variety of products are available, free and paid-for, to suit different needs and budgets.
ncsc.gov.ukApr 23, 2026extracted
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database commands. "The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed," Onapsis said in an advisory. In a potential attack scenario, a bad actor could abuse the affected upload-related functionality to run malicious SQL against BW/BPC data stores, extract sensitive data, and delete or corrupt database content. "Manipulated planning figures, broken reports, or deleted consolidation data can undermine close processes, executive reporting, and operational planning," Pathlock said. "In the wrong hands, this issue also creates a credible path to both stealthy data theft and overt business disruption." Another security vulnerability that deserves a mention is a critical-severity remote code execution in Adobe Acrobat Reader (CVE-2026-34621, CVSS score: 8.6) that has come under active exploitation in the wild. That said, there are many unknowns at this stage. It is not clear how many people have been affected by the hacking campaign. Nor is there any information about who is behind the activity, who is being targeted, and what their motives could be. Also patched by Adobe are five critical flaws in ColdFusion versions 2025 and 2023 that, if successfully exploited, could lead to arbitrary code execution, application denial-of-service, arbitrary file system read, and security feature bypass. The vulnerabilities are listed below - CVE-2026-34619 (CVSS score: 7.7) - A path traversal vulnerability leading to security feature bypass CVE-2026-27304 (CVSS score: 9.3) - An improper input validation vulnerability leading to arbitrary code execution CVE-2026-27305 (CVSS score: 8.6) - A path traversal vulnerability leading to arbitrary file system read CVE-2026-27282 (CVSS score: 7.5) - An improper input validation vulnerability leading to security feature bypass CVE-2026-27306 (CVSS score: 8.4) - An improper input validation vulnerability leading to arbitrary code execution Fixes have also been released for two critical FortiSandbox vulnerabilities that could result in authentication bypass and code execution - CVE-2026-39813 (CVSS score: 9.1) - A path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. (Fixed in versions 4.4.9 and 5.0.6) CVE-2026-39808 (CVSS score: 9.1) - An operating system command injection vulnerability in FortiSandbox that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. (Fixed in version 4.4.9) The development comes as Microsoft addressed a staggering 169 security defects, including a spoofing vulnerability impacting Microsoft SharePoint Server (CVE-2026-32201, CVSS score: 6.5) that could allow an attacker to view sensitive information. The company said it's being actively exploited, although there are no insights into the in-the-wild exploitation associated with the bug. "SharePoint services, especially those used as internal document stores, can be a treasure trove for threat actors looking to steal data, especially data that may be leveraged to force ransom payments using double extortion techniques by threatening to release the stolen data if payment is not made," Kev Breen, senior director of threat research at Immersive, said. "A secondary concern is that threat actors with access to SharePoint services could deploy weaponised documents or replace legitimate documents with infected versions that would allow them to spread to other hosts or victims moving laterally across the organization." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Apple ASUS AVEVA Broadcom (including VMware) Canon Cisco Citrix CODESYS D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal Elastic F5 Fortinet Foxit Software FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NETGEAR Node.js NVIDIA ownCloud Palo Alto Networks Phoenix Contact Progress Software QNAP Qualcomm Rockwell Automation Ruckus Wireless Samsung Schneider Electric Siemens SonicWall Splunk Spring Framework Supermicro Synology TP-Link WatchGuard, and Xiaomi
thehackernews.comApr 15, 2026extracted
How to protect your organization from AirSnitch Wi-Fi vulnerabilities | Kaspersky official blog
At the NDSS Symposium 2026 in San Diego in February, a group of respected researchers presented a study unveiling the AirSnitch attack, which bypasses the Wi-Fi client isolation feature — also commonly known as guest network or device isolation. This attack allows connecting to a single wireless network via an access point, and then gaining access to other connected devices, including those using entirely different service set identifiers (SSIDs) on that same hardware. Targeted devices could easily be running on wireless subnets protected by WPA2 or WPA3 protocols. The attack doesn’t actually break encryption; instead, it exploits the way access points handle group keys and packet routing. In practical terms, this means that a guest network provides very little in the way of real security. If your guest and employee networks are running on the same physical device, AirSnitch allows a connected attacker to inject malicious traffic into neighboring SSIDs. In some cases, they can even pull off a full-blown man-in-the-middle (MitM) attack. Wi-Fi security and the role of isolation Wi-Fi security is constantly evolving; every time a practical attack is made against the latest generation of protection, the industry shifts toward more complex algorithms and procedures. This cycle started with the FMS attacks used to crack WEP encryption keys, and continues to this day: recent examples include the KRACK attacks on WPA2, and the FragAttacks, which impacted every security protocol version from WEP all the way through WPA3. Attacking modern Wi-Fi networks effectively (and quietly) is no small feat. Most professionals agree that using WPA2/WPA3 with complex keys and separating networks based on their purpose is usually enough for protection. However, only specialists really know that client isolation was never actually standardized within the IEEE 802.11 protocols. Different manufacturers implement isolation in completely different ways — using Layer 2 or Layer 3 of network architecture; in other words, handling it at either the router or the Wi-Fi controller level — meaning the behavior of isolated subnets varies wildly depending on your specific access point or router model. While marketing claims that client isolation is perfect for keeping restaurant or hotel guests from attacking one another — or ensuring corporate visitors can’t access anything but the internet — in reality, isolation often relies on people not trying to hack it. This is exactly what the AirSnitch research highlights. Types of AirSnitch attacks The name AirSnitch doesn’t just refer to a single vulnerability, but a whole family of architectural flaws found in Wi-Fi access points. It’s also the name of an open-source tool used to test routers for these specific weaknesses. However, security professionals need to keep in mind that there’s only a very thin line between testing and attacking. The model for all these attacks is the same: a malicious client is connected to an access point (AP) where isolation is active. Other users — the targets — are connected to the same SSID or even different SSIDs on that same AP. This is a very realistic scenario; for example, a guest network might be open and unencrypted, or an attacker could simply get the guest Wi-Fi password by posing as a legitimate visitor. For certain AirSnitch attacks, the attacker needs to know the victim’s MAC or IP address beforehand. Ultimately, how effective each attack is depends on the specific hardware manufacturer (more on that below). GTK attack After the WPA2/WPA3 handshake, the access point and the clients agree on a Group Transient Key (GTK) to handle broadcast traffic. In this scenario, the attacker wraps packets destined for a specific victim inside a broadcast traffic envelope. They then send these directly to the victim while spoofing the access point’s MAC address. This attack only allows for traffic injection, meaning the attacker won’t receive a response. However, even that is enough to deliver malicious ICMPv6 routing advertisements, or DNS and ARP messages to the client — effectively bypassing isolation. This is the most universal version of the attack working on any WPA2/WPA3 network that uses a shared GTK. That said, some enterprise-grade access points support GTK randomization for each individual client, which renders this specific method ineffective. Broadcast packet redirection This version of the attack doesn’t even require the attacker to authenticate at the access point first. The attacker sends packets to the AP with a broadcast destination address (FF:FF:FF:FF:FF:FF) and the ToDS flag set to 1. As a result, many access points treat this packet as legitimate broadcast traffic; they encrypt it using the GTK, and blast it out to every client on the subnet, including the victim. Just like in the previous method, traffic specifically meant for a single victim can be pre-packaged inside. Router redirection This attack exploits an architectural gap between Layer 2 and Layer 3 security found in some manufacturers’ hardware. The attacker sends a packet to the access point, setting the victim’s IP address as the destination at the network layer (L3). However, at the wireless layer (L2), the destination is set to the access point’s own MAC address, so the isolation filter doesn’t trip. The routing subsystem (L3) then dutifully routes the packet back out to the victim, bypassing the L2 isolation entirely. Like the previous methods, this is another transmit-only attack where the attacker can’t see the reply. Port stealing to intercept packets The attacker connects to the network using a spoofed version of the victim’s MAC address, and floods the network with ARP responses claiming, “this MAC address is on my port and SSID”. The target network’s router updates its MAC tables, and starts sending the victim’s traffic to this new port instead. Consequently, traffic intended for the victim ends up with the attacker — even if the victim is connected to a completely different SSID. In a scenario where the attacker connects via an open, unencrypted network, this means traffic meant for a client on a WPA2/WPA3-secured network is actually broadcast over the open air, where not only the attacker but anyone nearby can sniff it. Port stealing to send packets In this version, the attacker connects directly to the victim’s Wi-Fi adapter, and bombards it with ARP requests spoofing the access point’s MAC address. As a result, the victim’s computer starts sending its outgoing traffic to the attacker instead of the network. By running both stealing attacks simultaneously, an attacker can, in several scenarios, execute a full MitM attack. Practical consequences of AirSnitch attacks By combining several of the techniques described above, a hacker can pull off some pretty serious moves: Complete bidirectional traffic interception for a MitM attack. This means they can snatch and modify data moving between the victim and the access point without the victim ever knowing. Hopping between SSIDs. An attacker sitting on a guest network can reach hosts on a locked-down corporate network if both are running off the same physical access point. Attacks on RADIUS. Since many companies use RADIUS authentication for their corporate Wi-Fi, an attacker can spoof the access point’s MAC address to intercept initial RADIUS authentication packets. From there, they can brute-force the shared secret. Once they have that, they can spin up a rogue RADIUS server and access point to hijack data from any device that connects to it. Exposing unencrypted data from “secure” subnets: Traffic that’s supposed to be sent to a client under the protection of WPA2/WPA3 can be retransmitted onto an open guest network, where it’s essentially broadcast for anyone to hear. To pull off these attacks effectively, a hacker needs a device capable of simultaneous data transmission and reception with both the victim’s adapter and the access point. In a real-world scenario, this usually means a laptop with two Wi-Fi adapters running specifically configured Linux drivers. It’s worth noting that the attack isn’t exactly silent: it requires a flood of ARP packets, it can cause brief Wi-Fi glitches when it starts, and network speeds might tank to around 10Mbps. Despite these red flags, it’s still very much a practical threat in many environments. Vulnerable devices As part of the study, several enterprise and home access points and routers were put to the test. The list included products from Cisco, Netgear, Ubiquiti, Tenda, D-Link, TP-Link, LANCOM, and ASUS, as well as routers running popular community firmware like DD-WRT and OpenWrt. Every single device tested was vulnerable to at least some of the attacks described here. Even more concerning, the D-Link DIR-3040 and LANCOM LX-6500 were susceptible to every single variation of AirSnitch. Interestingly, some routers were equipped with protective mechanisms that blocked the attacks, even though the underlying architectural flaws were still present. For example, the Tenda RX2 Pro automatically disconnects any client whose MAC address appears on two BSSIDs simultaneously, which effectively shuts down port stealing. The researchers emphasize that any network administrator or IT security team serious about defense should test their own specific configurations. That’s the only way to pinpoint exactly which threats are relevant to your organization’s setup. How to protect your corporate network from AirSnitch The threat is most immediate for organizations running guest and corporate Wi-Fi networks on the same access points without additional VLAN segmentation. There are also significant risks for companies using RADIUS with outdated settings or weak shared secrets for wireless authentication. The bottom line is that we need to stop viewing client isolation on an access point as a real security measure, and start seeing it as just a convenience feature. Real security needs to be handled differently: Segment the network using VLANs. Each SSID should have its own VLAN, with strict 802.1Q packet tagging maintained all the way from the access point to the firewall or router. Implement stricter packet inspection at the routing level — depending on the hardware capabilities. Features like Dynamic ARP Inspection, DHCP snooping, and limiting the number of MAC addresses per port help defend against IP/MAC spoofing. Enable individual GTK keys for each client, if your equipment supports it. Use more resilient RADIUS and 802.1X settings, including modern cipher suites and robust shared secrets. Log and analyze EAP/RADIUS authentication anomalies in your SIEM. This helps track many attack attempts beyond just AirSnitch. Other red flag events to watch for include the same MAC address appearing on different SSIDs, spikes in ARP requests, or clients rapidly jumping between BSSIDs or VLANs. Apply security at higher levels of the network topology. Many of these attacks lose their punch if the organization has universally implemented TLS and HSTS for all business application traffic, requires an active VPN for all Wi-Fi connections, or has fully embraced a Zero Trust architecture.
kaspersky.comApr 10, 2026extracted
Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices
Cybersecurity researchers have lifted the curtain on a stealthy botnet that's designed for distributed denial-of-service (DDoS) attacks. Called Masjesu, the botnet has been advertised via Telegram as a DDoS-for-hire service since it first surfaced in 2023. It's capable of targeting a wide range of IoT devices, such as routers and gateways, spanning multiple architectures. "Built for persistence and low visibility, Masjesu favors careful, low-key execution over widespread infection, deliberately avoiding blocklisted IP ranges such as those belonging to the Department of Defense (DoD) to ensure long-term survival," Trellix security researcher Mohideen Abdul Khader F said in a Tuesday report. It's worth noting that the commercial offering also goes by the moniker XorBot owing to its use of XOR-based encryption to conceal strings, configurations, and payload data. It was first documented by Chinese security vendor NSFOCUS in December 2023, linking it to an operator named "synmaestro." A subsequent iteration of the botnet observed a year later was found to have added 12 different command injection and code execution exploits to target routers, cameras, DVRs, and NVRs from D-Link, Eir, GPON, Huawei, Intelbras, MVPower, NETGEAR, TP-Link, and Vacron, and obtain initial access. Also added were new modules to conduct DDoS flood attacks. "As an emerging botnet family, XorBot is showing a strong growth momentum, continuously infiltrating and controlling new IoT devices," NSFOCUS said in November 2024. "Notably, these controllers are increasingly inclined to use social media platforms such as Telegram as the main channels for recruitment and promotion, attracting target 'customers' through initial active promotional activities, laying a solid foundation for the subsequent expansion and development of the botnet." The latest findings from Trellix show that Masjesu has marketed the ability to carry out volumetric DDoS attacks, emphasizing its diverse botnet infrastructure and its suitability for targeting content delivery networks (CDNs), game servers, and enterprises. Attacks mounted by the botnet primarily originate from Vietnam, Ukraine, Iran, Brazil, Kenya, and India, with Vietnam accounting for nearly 50% of the observed traffic. Once deployed on a compromised device, the malware moves to create and bind a socket with a hard-coded TCP port (55988) to enable the attacker to connect directly. If this operation fails, the attack chain is immediately killed. Otherwise, the malware proceeds to set up persistence, ignore termination-related signals, stop commonly used processes like wget and curl, possibly to disrupt competing botnets, and then connects to an external server to receive DDoS attack commands for executing them against targets of interest. Masjesu also boasts of self-propagating capabilities, allowing it to probe random IP addresses for open ports and wrangle successfully compromised devices into its infrastructure. One notable addition to the list of exploitation targets is Realtek routers, which is carried out by scanning for 52869 – a port associated with Realtek SDK's miniigd daemon. Multiple DDoS botnets, such as JenX and Satori, have embraced the same approach in the past. "The botnet continues to expand by infecting a broad range of IoT devices across multiple architectures and manufacturers," Trellix said. "Notably, Masjesu appears to avoid targeting sensitive critical organizations that could trigger significant legal or law-enforcement attention, a strategy that likely improves its long-term survivability." Update The Masjesu botnet has been attributed with high confidence by Breakglass Intelligence to a Turkish national named Seyit Girgin, who is "operating from at least two GitHub accounts, multiple Telegram channels, and a constellation of criminal infrastructure spanning DDoS-for-hire, game credential theft, and Discord token stealing with credit card hooks." (The story was updated after publication on April 14, 2026, with additional insights from Breakglass Intelligence.)
thehackernews.comApr 8, 2026extracted
Evasive Masjesu DDoS Botnet Targets IoT Devices
Trellix has dived into the inner workings of Masjesu, a botnet built for distributed denial-of-service (DDoS) attacks that has infected a variety of IoT devices. Masjesu has been active since at least 2023, with its operator mainly advertising it on Telegram as capable of launching DDoS attacks of hundreds of gigabytes in magnitude. The operator’s posts target both Chinese and English-speaking users, “suggesting that their services continue to target both Chinese and US customers,” Trellix says. Currently, the operator’s Telegram channel has over 400 subscribers, but the botnet’s userbase appears larger, as an initial channel promoting the botnet was closed by the platform for policy violations. Most of the devices ensnared by Masjesu are in Vietnam, an analysis of attack source countries shows. However, the botnet has also infected numerous devices in Brazil, India, Iran, Kenya, and Ukraine. “The data strongly suggests a distributed attack originating from multiple ASNs. This indicates the involvement of various networks, rather than the botnet being exclusively hosted on a single Virtual Private Server (VPS) provider,” Trellix notes. Recently analyzed Masjesu samples show it can target multiple architectures, including i386, MIPS, ARM, SPARC, PPC, 68K (Motorola 68000), and AMD64. The botnet spreads through vulnerabilities in D-Link routers, GPON routers, Huawei home gateways, MVPower DVRs, Netgear routers, UPnP services, and other IoT devices. On the infected devices, the malware binds a socket with a hardcoded TCP port to provide operators with remote access and hardens itself for persistence. The malware stores sensitive strings – including command-and-control (C&C) domains, ports, folder names, and process names – encrypted in a lookup table and decrypts them at runtime. To achieve persistence, Masjesu starts by forking a new process and renaming its original executable path to mimic the path and function of a legitimate Linux dynamic linker. It then creates a cron job to run the renamed executable every 15 minutes, converts the process into a background daemon, and renames it to appear as a legitimate system component. The malware also terminates commonly used processes, such as wget and curl, and locks down shared temporary folders, likely to prevent infections from other botnets. To spread, it scans random IP addresses on the internet to find vulnerable devices it can infect. Masjesu uses multiple C&C domains and fallback IPs, configures a 60-second receive timeout on the socket connection to the C&C, and decrypts received data client-side. Based on the data received from the server, the botnet can launch various types of DDoS attacks, including UDP, TCP, VSE, GRE, RDP, OSPF, ICMP, IGMP, TCP_SYN, TCP-ACK, TCP-ACKPSH, and HTTP floods. Related: Aisuru and Kimwolf DDoS Botnets Disrupted in International Operation Related: 174 Vulnerabilities Targeted by RondoDox Botnet Related: Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet Related: Aeternum Botnet Loader Employs Polygon Blockchain C&C to Boost Resilience
securityweek.comApr 8, 2026extracted
US Bans All Foreign-Made Consumer Routers
US Bans All Foreign-Made Consumer Routers This is for new routers; you don’t have to throw away your existing ones: The Executive Branch determination noted that foreign-produced routers (1) introduce “a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense” and (2) pose “a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons.” More information: Any new router made outside the US will now need to be approved by the FCC before it can be imported, marketed, or sold in the country. In order to get that approval, companies manufacturing routers outside the US must apply for conditional approval in a process that will require the disclosure of the firm’s foreign investors or influence, as well as a plan to bring the manufacturing of the routers to the US. Certain routers may be exempted from the list if they are deemed acceptable by the Department of Defense or the Department of Homeland Security, the FCC said. Neither agency has yet added any specific routers to its list of equipment exceptions. […] Popular brands of router in the US include Netgear, a US company, which manufactures all of its products abroad. One exception to the general absence of US-made routers is the newer Starlink WiFi router. Starlink is part of Elon Musk’s company SpaceX. Presumably US companies will start making home routers, if they think this policy is stable enough to plan around. But they will be more expensive than routers made in China or Taiwan. Security is never free, but policy determines who pays for it.
schneier.comApr 2, 2026extracted
US foreign router ban criticized for being ‘industrial policy disguised as cybersecurity’
SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Copilot tricked into telling reseachers how to hack itselfHow to social engineer an AI's reasoning engine AI and ml Payments giant Stripe is about to drop over $7 billion to become a gateway to AI token salesAI gateways look promising as companies struggle with model orchestration Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
go.theregister.comMar 30, 2026extracted
US: FCC Bans Foreign-Made Routers Over National Security Concerns
The US Federal Communications Commission (FCC) has banned the import and sale of all “consumer-grade” internet routers produced in a foreign country, citing “an unacceptable risk” to the national security of the US. The ban, announced in an FCC public notice on March 23, means that all such routers made in foreign countries – not just a few select Chinese vendors – are now placed on the FCC’s covered list. The only exceptions include routers that have been granted a conditional approval by the US Department of Defense (DoD) or Department of Homeland Security (DHS). At the time of writing, the list of exceptions only includes drone systems and online surveillance systems. The agency highlighted that foreign-made routers “were directly implicated” in the Volt, Flax and Salt Typhoon cyber-attacks which targeted critical American communications, energy, transportation and water infrastructure. Consumer Routers Under Fire While the public notice sounds like a blanket ban of all foreign-made routers in the US, the FCC specifically banned “consumer-grade routers” as defined in NIST Internal Report 8425A, which refers to ones “intended for residential use and can be installed by the customer.” Existing Wi-Fi and wired routers currently in use may continue operating without restriction. Futher, companies that have previously secured FCC radio authorization for specific foreign-manufactured networking equipment are permitted to maintain imports of those approved models. However, since nearly all consumer-grade routers are produced outside the US, the FCC’s action effectively prohibits the import of the majority of future consumer router models. Shane Barney, CISO at Keeper Security, warned that focusing solely on country-of-origin risks oversimplifying a much broader security challenge. “In enterprise environments, routers and network devices are seen not just as connectivity tools, but as high-value control points that sit outside traditional security oversight. That risk is often compounded through weak governance rather than manufacturing geography,” he said. “Network infrastructure is frequently under-managed, lacks consistent patching and operates without integration into modern identity and access management frameworks. This creates an ideal foothold for attackers seeking persistent, low-visibility access into corporate environments.” For instance, in the Volt Typhoon and Salt Typhoon cyber-attacks, Chinese state-backed hackers primarily exploited vulnerabilities in Cisco and Netgear routers which were susceptible because their manufacturers had discontinued security updates for those specific, end-of-life models. US firm Netgear is understood to manufacture its routers in locations like Taiwan and Vietnam, meaning the firm will likely be heavily affected by the ban. Two major Chinese router makers, Huawei and ZTE, were placed on agency’s covered list in 2021. Another Chinese provider, TP-Link, is still widely used in the US. The company has taken recent steps to reduce its association with China, including a 2022 corporate restructuring that separated it from its Chinese parent entity. In 2024, the company established a global headquarters in California. TP-Link sued US firm Netgear in November 2025 for suggesting that TP-Link had been infiltrated by the Chinese government.
infosecurity-magazine.comMar 25, 2026extracted
FCC bans foreign-made routers from US market over ‘unacceptable risk’
FCC bans foreign-made routers from US market over ‘unacceptable risk’ The Federal Communications Commission has banned all consumer routers produced outside of the U.S. from being imported unless their manufacturers obtain an exemption due to what the agency called an “unacceptable risk to the national security of the United States and to the safety and security of U.S. persons.” Most routers used by American consumers are manufactured outside of the U.S. so the ban could have a significant impact. The new rule follows a similar FCC ban on foreign-made drones that was issued in December. The ban applies only to future imports, meaning that Americans who already own foreign-made devices can keep using products they already have in their homes. To be exempt from the ban, router companies will have to receive a “specific determination” from the Department of Homeland Security or Department of War saying their products do not pose security risks. In a statement, a spokesperson for TP-Link — a router company founded in China that is now headquartered in California — said “virtually all routers are made outside the United States, including those produced by U.S.-based companies like TP-Link, which manufactures its products in Vietnam.” “It appears that the entire router industry will be impacted by the FCC’s announcement concerning new devices not previously authorized by the FCC,” they said. The interagency committee proposing the ban found that American consumers’ reliance on foreign-made routers introduces supply chain vulnerabilities that could threaten the U.S. economy, critical infrastructure and defense posture while also creating “severe cybersecurity risk,” the FCC said in a National Security Determination (NSD) on March 20. Compromised routers can facilitate network surveillance, data exfiltration, botnet attacks, and unauthorized network access, the FCC said. “Unsecure and foreign-produced routers are prime targets for attackers and have been used in multiple recent cyberattacks to enable hackers to gain access to networks and use them as launching pads to compromise critical infrastructure,” the NSD said. They “are enabling hackers to create massive networks that can be leveraged to carry out password spraying, unauthorized network access, and act as proxies for espionage.” State-sponsored hackers behind the Salt Typhoon attacks used compromised foreign-manufactured routers to “jump to embed and gain long term access to certain networks and pivot to others depending on their target,” the NSD said. The Cybersecurity and Infrastructure Security Agency also has called routers an “attack-vector of choice,” the NSD said, citing a September 2025 agency advisory that detailed the threat. In September 2024, the FBI, Cyber National Mission Force and National Security Agency published a joint cybersecurity assessment that said hackers have used foreign-made routers to create botnets used for malicious activity, including distributed denial-of-service attacks. The FCC also pointed to an October 2024 announcement from Microsoft that the company had found that compromised, foreign-produced routers were used to mount password spray attacks against its customers. In February, Texas sued TP-Link Systems for allegedly facilitating hacks of consumers’ devices by the Chinese Communist Party even as it marketed itself as having strong security and privacy protections. “TP-Link is confident in the security of our supply chain and we welcome this evaluation of the entire industry,” the company said in response to the FCC notice. American-made routers have also proven vulnerable to hacks. In January 2024, the Department of Justice said that Cisco and NetGear routers that were no longer supported with security patches and other software updates were used by the Volt Typhoon hackers. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaMar 24, 2026extracted
Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet
Law enforcement agencies in the United States and Europe have disrupted SocksEscort, a malicious proxy service that facilitated criminal activities. These proxy services enable users to hide their identity and bypass security systems. In the case of SocksEscort, it has been used for various types of cybercrime, including DDoS attacks, ransomware attacks, and the distribution of child abuse materials. According to Europol and the US Justice Department, SocksEscort has been powered by compromised routers and other IoT devices, with roughly 363,000 IP addresses from 163 countries linked to the cybercrime service since 2020. In February 2026, just before the takedown operation was initiated, SocksEscort was supported by approximately 8,000 hacked routers, including 2,500 in the US. Lumen Technologies, whose Black Lotus Labs assisted the disruption efforts, said “SocksEscort maintained an average size of approximately 20,000 distinct victims weekly, with communications routed through an average of 15 command-and-control nodes.” Authorities estimate that SocksEscort customers paid a total of more than $5.7 million for the proxy service, and US Justice Department data indicates many users profited substantially from it, with some defrauding victims of hundreds of thousands or even $1 million in individual schemes. Europol reported that “law enforcement agencies successfully took down and seized 34 domains as well as 23 servers located in seven countries. In addition, the United States froze a total of USD 3.5 million in cryptocurrency. The infected modems used to offer the proxy service have been disconnected from the service.” The FBI on Thursday issued an alert for the AVrecon malware that has powered the SocksEscort service. The agency said the proxy service’s operators exploited known vulnerabilities in routers and IoT devices to deploy the malware and create a botnet. “SocksEscort uses AVrecon malware to target approximately 1,200 device models manufactured by Cisco, D-Link, Hikvision, MicroTik, Netgear, TP-Link, and Zyxel,” the FBI said. “The vast majority of observed devices infected with AVrecon malware are small-office/home-office (SOHO) routers infected using critical vulnerabilities such as Remote Code Execution (RCE) and command injection.” The agency has shared information on the AVrecon malware’s distribution, execution, persistence, and communication, providing indicators of compromise (IoCs) and recommendations for securing devices. News of the SocksEscort takedown comes shortly after Europol, Microsoft, and cybersecurity companies announced a joint effort to take down the phishing-as-a-service platform Tycoon 2FA. Related: SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown Related: RaccoonO365 Phishing Service Disrupted, Leader Identified Related: 1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium
securityweek.comMar 13, 2026extracted
US, Europol disrupt SocksEscort network that exploited thousands of residential routers
US, Europol disrupt SocksEscort network that exploited thousands of residential routers A cybercriminal platform that offered access to thousands of residential routers was disrupted by law enforcement agencies in the U.S. and Europe on Wednesday. The SocksEscort proxy network allowed cybercriminals to purchase access to routers infected with malware. Criminals could conceal their location and IP address by routing their activities through the infected routers. The Justice Department said from 2020 to 2026, SocksEscort offered access to about 369,000 different IP addresses in 163 countries but listed about 8,000 IP addresses as of February. Of those 8,000 available for sale, 2,500 were in the U.S. In total, 34 domains were seized and 23 servers were taken down by law enforcement agencies in seven countries. U.S. officials also froze access to $3.5 million worth of cryptocurrency. Alongside the operation against SocksEscort, the FBI published a flash alert about a malware strain known as AVRecon on Thursday, warning the public that it is targeted at routers and internet-of-things devices. Threat actors “have been found to compromise routers, install AVrecon Malware, and then sell access to the compromised devices as residential proxies using the SocksEscort residential proxy service.” SocksEscort uses AVrecon malware “to target approximately 1,200 device models manufactured by Cisco, D-Link, Hikvision, MicroTik, Netgear, TP-Link, and Zyxel,” the FBI said. Europol noted that when the devices were infected with the malware, owners would not know that their IP address was being abused. Catherine De Bolle, executive director of Europol, said proxy services like SocksEscort “provide criminals with the digital cover they need to launch attacks, distribute illegal content and evade detection.” “By dismantling this infrastructure, law enforcement has disrupted a service that enabled cybercrime on a global scale,” De Bolle said in a statement. U.S. officials executed seizure warrants against several U.S. domains that enabled the SocksEscort operation. Court documents tied the SocksEscort site to dozens of different cyberscams, including fraudulent unemployment insurance claims, cryptocurrency thefts and the takeover of U.S. bank accounts. The people behind SocksEscort allegedly netted more than $5.7 million from the service. Law enforcement agencies in Austria, France and the Netherlands took down SocksEscort servers and officials in Bulgaria, Germany, Hungary and Romania were involved in the investigation, which began in June 2025. The DOJ noted that private sector firms like Lumen’s Black Lotus Labs and the Shadowserver Foundation also provided assistance. Black Lotus Labs published its own advisory on AVRecon and SocksEscort, writing that over the past several years, the platform “maintained an average size of approximately 20,000 distinct victims weekly, with communications routed through an average of 15 command-and-control nodes (C2s).” In 2023, the company said AVrecon’s botnet was one of the largest it has seen targeting home office routers. An FBI official told The Register that SocksEscort had 124,000 users and that they planned to use the seized servers to target other cybercriminal activity. U.S. and European law enforcement agencies have ramped upbotnet takedowns in recent years to stymie cybercriminal and nation-state attack campaigns. Botnets like QakBot, 911 S5, IPStorm, KV, DanaBot, Anyproxy, 5socks and others have faced law enforcement scrutiny since 2021. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaMar 12, 2026extracted
OpenAI Rolls Out Codex Security Vulnerability Scanner
OpenAI is rolling out a new AI-powered software vulnerability scanner that the company claims can identify complex issues that other agentic tools may miss. Named Codex Security (formerly Aardvark), the tool is currently in research preview, but it has been tested in private beta since last year, including by major companies such as Netgear. Codex Security is now available to ChatGPT Pro, Enterprise, Business, and Edu customers with free usage for the next month. The AI giant says its new tool is designed to analyze repositories for system context and create a threat model focusing on the system’s role, trusted components, and exposures. Based on the generated threat model, Codex looks for vulnerabilities and rates them by potential real-world impact. It then also proposes patches for the identified flaws. According to OpenAI, Codex Security has been tested against 1.2 million commits over the past 30 days, identifying nearly 800 critical vulnerabilities and more than 10,000 high-severity issues. Vulnerabilities have been found in widely used open source projects such as Chromium, OpenSSL, PHP, GOGS, and GnuTLS. OpenAI’s announcement comes shortly after Claude unveiled its own AI vulnerability scanner, Claude Code Security, which led to the stocks of major cybersecurity companies tumbling. AI-powered vulnerability scanners are not new. GitHub has offered these capabilities for years, and Google claims to have made significant progress in this area. Related: Hackers Weaponize Claude Code in Mexican Government Cyberattack Related: OpenClaw Vulnerability Allowed Websites to Hijack AI Agents Related: Vulnerability in MS-Agent AI Framework Can Allow Full System Compromise
securityweek.comMar 10, 2026extracted
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited
Microsoft on Tuesday rolled out its first security update for 2026, addressing 114 security flaws, including one vulnerability that it said has been actively exploited in the wild. Of the 114 flaws, eight are rated Critical, and 106 are rated Important in severity. As many as 58 vulnerabilities have been classified as privilege escalation, followed by 22 information disclosure, 21 remote code execution, and five spoofing flaws. According to data collected by Fortra, the update marks the third-largest January Patch Tuesday after January 2025 and January 2022. These patches are in addition to two security flaws that Microsoft has addressed in its Edge browser since the release of the December 2025 Patch Tuesday update, including a spoofing flaw in its Android app (CVE-2025-65046, 3.1) and a case of insufficient policy enforcement in Chromium's WebView tag (CVE-2026-0628, CVSS score: 8.8). The vulnerability that has come under in-the-wild exploitation is CVE-2026-20805 (CVSS score: 5.5), an information disclosure flaw impacting Desktop Window Manager. The Microsoft Threat Intelligence Center (MTIC) and Microsoft Security Response Center (MSRC) have been credited with identifying and reporting the flaw. "Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager (DWM) allows an authorized attacker to disclose information locally," Microsoft said in an advisory. "The type of information that could be disclosed if an attacker successfully exploited this vulnerability is a section address from a remote ALPC port, which is user-mode memory." There are currently no details on how the vulnerability is being exploited, the scale of such efforts, and who may be behind the activity. "DWM is responsible for drawing everything on the display of a Windows system, which means it offers an enticing combination of privileged access and universal availability, since just about any process might need to display something," Adam Barnett, lead software engineer at Rapid7, said in a statement. "In this case, exploitation leads to improper disclosure of an ALPC port section address, which is a section of user-mode memory where Windows components coordinate various actions between themselves." Microsoft previously addressed an actively exploited zero-day flaw in DWM in May 2024 (CVE-2024-30051, CVSS score: 7.8), which was described as a privilege escalation flaw that was abused by multiple threat actors, in connection with the distribution of QakBot and other malware families. Satnam Narang, senior staff research engineer at Tenable, called DWM a "frequent flyer" on Patch Tuesday, with 20 CVEs patched in the library since 2022. Jack Bicer, director of vulnerability research at Action1, said the vulnerability can be exploited by a locally authenticated attacker to disclose information, defeat address space layout randomization (ASLR), and other defenses. "Vulnerabilities of this nature are commonly used to undermine Address Space Layout Randomization (ASLR), a core operating system security control designed to protect against buffer overflows and other memory-manipulation exploits," Kev Breen, senior director of cyber threat research at Immersive, told The Hacker News. "By revealing where code resides in memory, this vulnerability can be chained with a separate code execution flaw, transforming a complex and unreliable exploit into a practical and repeatable attack." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to apply the latest fixes by February 3, 2026. Another vulnerability of note concerns a security feature bypass impacting Secure Boot Certificate Expiration (CVE-2026-21265, CVSS score: 6.4) that could allow an attacker to undermine a crucial security mechanism that ensures that firmware modules come from a trusted source and prevent malware from being run during the boot process. In November 2025, Microsoft announced that it will be expiring three Windows Secure Boot certificates issued in 2011, effective June 2026, urging customers to update to their 2023 counterparts - Microsoft Corporation KEK CA 2011 (June 2026) - Microsoft Corporation KEK 2K CA 2023 (for signing updates to DB and DBX) Microsoft Windows Production PCA 2011 (October 2026) - Windows UEFI CA 2023 (for signing the Windows boot loader) Microsoft UEFI CA 2011 (June 2026) - Microsoft UEFI CA 2023 (for signing third-party boot loaders) and Microsoft Option ROM UEFI CA 2023 (for signing third-party option ROMs) "Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time," Microsoft said. "To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance." The Windows maker also pointed out that the latest update removes Agere Soft Modem drivers "agrsm64.sys" and "agrsm.sys" that were shipped natively with the operating system. The third-party drivers are susceptible to a two-year-old local privilege escalation flaw (CVE-2023-31096, CVSS score: 7.8) that could allow an attacker to gain SYSTEM permissions. In October 2025, Microsoft took steps to remove another Agere Modem driver called "ltmdm64.sys" following in-the-wild exploitation of a privilege escalation vulnerability (CVE-2025-24990, CVSS score: 7.8) that could permit an attacker to gain administrative privileges. Also high on the priority list should be CVE-2026-20876 (CVSS score: 6.7), a critical-rated privilege escalation flaw in Windows Virtualization-Based Security (VBS) Enclave, enabling an attacker to obtain Virtual Trust Level 2 (VTL2) privileges, and leverage it to subvert security controls, establish deep persistence, and evade detection. "It breaks the security boundary designed to protect Windows itself, allowing attackers to climb into one of the most trusted execution layers of the system," Mike Walters, president and co-founder of Action1, said. "Although exploitation requires high privileges, the impact is severe because it compromises virtualization-based security itself. Attackers who already have a foothold could use this flaw to defeat advanced defenses, making prompt patching essential to maintain trust in Windows security boundaries." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors since the start of the month to rectify several vulnerabilities, including — ABB Adobe Amazon Web Services AMD Arm ASUS Broadcom (including VMware) Cisco ConnectWise Dassault Systèmes D-Link Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Imagination Technologies Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Firefox ESR n8n NETGEAR Node.js NVIDIA ownCloud QNAP Qualcomm Ricoh Samsung SAP Schneider Electric ServiceNow Siemens SolarWinds SonicWall Sophos Spring Framework Synology TP-Link Trend Micro, and Veeam
thehackernews.comJan 14, 2026extracted
In Other News: HashJack AI Browser Attack, Charming Kitten Leak, Hacker Unmasked
SecurityWeek’s cybersecurity news roundup provides a concise compilation of noteworthy stories that might have slipped under the radar. We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape. Each week, we curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports. Here are this week’s stories: Suspected Scattered Spider members plead not guilty to TfL attack Thalha Jubair and Owen Flowers, the two suspected Scattered Spider members arrested earlier this year in the UK, have pleaded not guilty to the charges accusing them of launching a disruptive cyberattack against Transport for London (TfL). Jubair has also been charged in the US, where he has been accused of hacking into networks, stealing and encrypting victims’ data, and extorting them. HashJack attack targets AI browsers Researchers at Cato Networks have disclosed HashJack, a new indirect prompt injection attack targeting AI browser assistants. HashJack involves malicious prompts being hidden after the ‘#’ symbol in legitimate URLs. AI browser assistants in Comet, Edge, and Chrome execute the commands when they process the URL, potentially leading to phishing, data exfiltration, malware delivery, and misinformation. Impacted browser vendors have been notified and, except for Google (which classified it as a low-severity issue), they have released patches. Leak reveals inner workings of Iranian APT Charming Kitten Internal documents belonging to the Iranian threat group Charming Kitten (APT35) were leaked last month on GitHub, revealing the actor’s inner workings. An analysis conducted by DomainTools showed that the hackers operate as a “regimented, quota-driven cyber operations unit operating inside a bureaucratic military chain of command”. Members are assigned to specific tasks, and supervisors file monthly performance reports that include information such as phishing success rate, exploitation metrics, completed tasks, and hours worked. Scattered Lapsus$ Hunters member Rey identified as teen from Jordan Cybersecurity blogger Brian Krebs claims to have uncovered the real identity of ‘Rey’, a key member of the Scattered Lapsus$ Hunters cybercrime group. Krebs says Rey is 16-year-old Saif Al-Din Khader from Amman, Jordan. The teen reportedly admitted that he is Rey and claimed he is trying to retire from Scattered Lapsus$ Hunters while also collaborating with law enforcement in Europe, but Krebs was unable to verify those claims. TP-Link sues Netgear over false China link claims TP-Link has filed a lawsuit against Netgear in Delaware, accusing it of defamatory claims as part of a smear campaign falsely claiming that TP-Link has ties to the Chinese government. Underlining that it is incorporated and headquartered in California, TP-Link claims that Netgear’s campaign is creating an unfair advantage in the marketplace and that the false assertions violate federal and state laws. Comcast agrees to $1.5 million fine over vendor data breach Telecommunications provider Comcast has agreed (PDF) to pay a $1.5 million fine to settle an FCC investigation into a data breach at one of its third-party services providers. The incident occurred in February 2024 and involved debt collection agency Financial Business and Consumer Solutions (FBCS). Roughly 238,000 Comcast customers were impacted. High-severity Firefox vulnerability Aisle has published technical details on CVE-2025-13016, a high-severity vulnerability in Firefox’s WebAssembly engine that could lead to remote code execution. The vulnerable code was added to the browser in April 2025 alongside its own regression test, but remained unnoticed until October. It was patched in Firefox 145. “The vulnerable code passed code review, included a test specifically designed to exercise the same code path, and shipped in multiple Firefox releases,” Aisle notes. Gainsight says only a handful of customers affected by Salesforce attack The investigation into the attack that disrupted Gainsight-Salesforce integrations last week continues, but Gainsight continues to downplay the impact from the incident. After the company said last week that only three organizations were impacted by the data breach, its CEO said on Tuesday that only “a handful of customers” had their data compromised. Google, on the other hand, told the media that roughly 200 Salesforce instances might have been affected. ShadowV2 IoT botnet active during AWS outage ShadowV2, a Mirai-based botnet ensnaring vulnerable IoT devices, mainly routers, was seen active at the end of October, during a massive AWS outage that affected organizations in multiple countries worldwide. “So far, the malware appears to have only been active during the time of the large-scale AWS outage. We believe this activity was likely a test run conducted in preparation for future attacks,” Fortinet says. In September, Darktrace revealed that ShadowV2 was targeting Docker daemons running on internet-accessible AWS cloud instances. Bloody Wolf APT expands operations across Central Asia The Bloody Wolf APT is impersonating government agencies, mainly ministries of justice, in fresh attacks against entities in a broader set of countries in Central Asia, Group-IB reports. Relying on spear-phishing, the hacking group was seen deploying the STRRAT malware and the legitimate remote administration tool NetSupport. Historically, it has been targeting entities in Kazakhstan and Russia, but recently expanded to Kyrgyzstan and Uzbekistan. Related: In Other News: ATM Jackpotting, WhatsApp-NSO Lawsuit Continues, CISA Hiring Related: In Other News: Deepwatch Layoffs, macOS Vulnerability, Amazon AI Bug Bounty
securityweek.comNov 28, 2025extracted
TP-Link accuses rival Netgear of 'smear campaign' over alleged China ties
ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity SAAS Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report saysShow us the money ai and ml AI companies are burning books, advocates complain to FTCFahrenheit 203, the temperature GPUs stop gorging on literature DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
go.theregister.comNov 20, 2025extracted
Drilling Down on Uncle Sam’s Proposed TP-Link Ban
The U.S. government is reportedly preparing to ban the sale of wireless routers and other networking gear from TP-Link Systems, a tech company that currently enjoys an estimated 50% market share among home users and small businesses. Experts say while the proposed ban may have more to do with TP-Link’s ties to China than any specific technical threats, much of the rest of the industry serving this market also sources hardware from China and ships products that are insecure fresh out of the box. The Washington Post recently reported that more than a half-dozen federal departments and agencies were backing a proposed ban on future sales of TP-Link devices in the United States. The story said U.S. Department of Commerce officials concluded TP-Link Systems products pose a risk because the U.S.-based company’s products handle sensitive American data and because the officials believe it remains subject to jurisdiction or influence by the Chinese government. TP-Link Systems denies that, saying that it fully split from the Chinese TP-Link Technologies over the past three years, and that its critics have vastly overstated the company’s market share (TP-Link puts it at around 30 percent). TP-Link says it has headquarters in California, with a branch in Singapore, and that it manufactures in Vietnam. The company says it researches, designs, develops and manufactures everything except its chipsets in-house. TP-Link Systems told The Post it has sole ownership of some engineering, design and manufacturing capabilities in China that were once part of China-based TP-Link Technologies, and that it operates them without Chinese government supervision. “TP-Link vigorously disputes any allegation that its products present national security risks to the United States,” Ricca Silverio, a spokeswoman for TP-Link Systems, said in a statement. “TP-Link is a U.S. company committed to supplying high-quality and secure products to the U.S. market and beyond.” Cost is a big reason TP-Link devices are so prevalent in the consumer and small business market: As this February 2025 story from Wired observed regarding the proposed ban, TP-Link has long had a reputation for flooding the market with devices that are considerably cheaper than comparable models from other vendors. That price point (and consistently excellent performance ratings) has made TP-Link a favorite among Internet service providers (ISPs) that provide routers to their customers. In August 2024, the chairman and the ranking member of the House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party called for an investigation into TP-Link devices, which they said were found on U.S. military bases and for sale at exchanges that sell them to members of the military and their families. “TP-Link’s unusual degree of vulnerabilities and required compliance with PRC law are in and of themselves disconcerting,” the House lawmakers warned in a letter (PDF) to the director of the Commerce Department. “When combined with the PRC government’s common use of SOHO [small office/home office] routers like TP-Link to perpetrate extensive cyberattacks in the United States, it becomes significantly alarming.” The letter cited a May 2023 blog post by Check Point Research about a Chinese state-sponsored hacking group dubbed “Camaro Dragon” that used a malicious firmware implant for some TP-Link routers to carry out a sequence of targeted cyberattacks against European foreign affairs entities. Check Point said while it only found the malicious firmware on TP-Link devices, “the firmware-agnostic nature of the implanted components indicates that a wide range of devices and vendors may be at risk.” In a report published in October 2024, Microsoft said it was tracking a network of compromised TP-Link small office and home office routers that has been abused by multiple distinct Chinese state-sponsored hacking groups since 2021. Microsoft found the hacker groups were leveraging the compromised TP-Link systems to conduct “password spraying” attacks against Microsoft accounts. Password spraying involves rapidly attempting to access a large number of accounts (usernames/email addresses) with a relatively small number of commonly used passwords. TP-Link rightly points out that most of its competitors likewise source components from China. The company also correctly notes that advanced persistent threat (APT) groups from China and other nations have leveraged vulnerabilities in products from their competitors, such as Cisco and Netgear. But that may be cold comfort for TP-Link customers who are now wondering if it’s smart to continue using these products, or whether it makes sense to buy more costly networking gear that might only be marginally less vulnerable to compromise. Almost without exception, the hardware and software that ships with most consumer-grade routers includes a number of default settings that need to be changed before the devices can be safely connected to the Internet. For example, bring a new router online without changing the default username and password and chances are it will only take a few minutes before it is probed and possibly compromised by some type of Internet-of-Things botnet. Also, it is incredibly common for the firmware in a brand new router to be dangerously out of date by the time it is purchased and unboxed. Until quite recently, the idea that router manufacturers should make it easier for their customers to use these products safely was something of an anathema to this industry. Consumers were largely left to figure that out on their own, with predictably disastrous results. But over the past few years, many manufacturers of popular consumer routers have begun forcing users to perform basic hygiene — such as changing the default password and updating the internal firmware — before the devices can be used as a router. For example, most brands of “mesh” wireless routers — like Amazon’s Eero, Netgear’s Orbi series, or Asus’s ZenWifi — require online registration that automates these critical steps going forward (or at least through their stated support lifecycle). For better or worse, less expensive, traditional consumer routers like those from Belkin and Linksys also now automate this setup by heavily steering customers toward installing a mobile app to complete the installation (this often comes as a shock to people more accustomed to manually configuring a router). Still, these products tend to put the onus on users to check for and install available updates periodically. Also, they’re often powered by underwhelming or else bloated firmware, and a dearth of configurable options. Of course, not everyone wants to fiddle with mobile apps or is comfortable with registering their router so that it can be managed or monitored remotely in the cloud. For those hands-on folks — and for power users seeking more advanced router features like VPNs, ad blockers and network monitoring — the best advice is to check if your router’s stock firmware can be replaced with open-source alternatives, such as OpenWrt or DD-WRT. These open-source firmware options are compatible with a wide range of devices, and they generally offer more features and configurability. Open-source firmware can even help extend the life of routers years after the vendor stops supporting the underlying hardware, but it still requires users to manually check for and install any available updates. Happily, TP-Link users spooked by the proposed ban may have an alternative to outright junking these devices, as many TP-Link routers also support open-source firmware options like OpenWRT. While this approach may not eliminate any potential hardware-specific security flaws, it could serve as an effective hedge against more common vendor-specific vulnerabilities, such as undocumented user accounts, hard-coded credentials, and weaknesses that allow attackers to bypass authentication. Regardless of the brand, if your router is more than four or five years old it may be worth upgrading for performance reasons alone — particularly if your home or office is primarily accessing the Internet through WiFi. NB: The Post’s story notes that a substantial portion of TP-Link routers and those of its competitors are purchased or leased through ISPs. In these cases, the devices are typically managed and updated remotely by your ISP, and equipped with custom profiles responsible for authenticating your device to the ISP’s network. If this describes your setup, please do not attempt to modify or replace these devices without first consulting with your Internet provider.
krebsonsecurity.comNov 9, 2025extracted
ThreatsDay Bulletin: AI Tools in Malware, Botnets, GDI Flaws, Election Attacks & More
Cybercrime has stopped being a problem of just the internet — it’s becoming a problem of the real world. Online scams now fund organized crime, hackers rent violence like a service, and even trusted apps or social platforms are turning into attack vectors. The result is a global system where every digital weakness can be turned into physical harm, economic loss, or political leverage. Understanding these links is no longer optional — it’s survival. For a full look at the most important security news stories of the week, keep reading. Hidden flaws resurface in Windows coreDetails have emerged about three now-patched security vulnerabilities in Windows Graphics Device Interface (GDI) that could enable remote code execution and information disclosure. These issues – CVE-2025-30388, CVE-2025-53766, and CVE-2025-47984 – involve out-of-bounds memory access triggered through malformed enhanced metafile (EMF) and EMF+ records that can cause memory corruption during image rendering. They are rooted in gdiplus.dll and gdi32full.dll, which process vector graphics, text, and print operations. They were addressed by Microsoft in the Patch Tuesday updates in May, July, and August 2025 in gdiplus.dll versions 10.0.26100.3037 through 10.0.26100.4946 and gdi32full.dll version 10.0.26100.4652. "Security vulnerabilities can persist undetected for years, often resurfacing due to incomplete fixes," Check Point said. "A particular information disclosure vulnerability, despite being formally addressed with a security patch, remained active for years due to the original issue receiving only a partial fix. This example underscores a basic conundrum for researchers: introducing a vulnerability is often easy, fixing it can be difficult, and verifying that a fix is both thorough and effective is even more challenging." Syndicate staffed by fake workers net millionsThree Chinese nationals, Yan Peijian, 39, Huang Qinzheng, 37, and Liu Yuqi, 33, were convicted and sentenced to a little over two years in prison in Singapore for their involvement in hacking into overseas gambling websites and companies for the purposes of cheating during gameplay and stealing databases of personally identifiable information for trade. The three individuals, part of a group of five Chinese nationals and one Singaporean man, were originally arrested and charged in September 2024. "The three accused persons were tasked by the syndicate's group leader to probe sites of interest for system vulnerabilities, conduct penetration attacks, and exfiltrate personal information from the compromised systems," the Singapore Police Force said. "Further investigations revealed that the syndicate possessed foreign government data, including confidential communications." The three defendants were also found to be in possession of tools like PlugX and "hundreds of different remote access trojans" to conduct cyber attacks. According to Channel News Asia, the three men entered the country on fake work permits in 2022 and worked for a 38-year-old Ni-Vanuatu citizen named Xu Liangbiao. They were paid about $3 million for their work. Xu, the alleged leader, is said to have left Singapore in August 2023. His present whereabouts are unknown. AI speeds triage but human skill still neededCheck Point has demonstrated a way by which ChatGPT can be used for malware analysis and flip the balance when it comes to taking apart sophisticated trojans like XLoader, which is designed such that its code decrypts only at runtime and is protected by multiple layers of encryption. Specifically, the research found that cloud-based static analysis with ChatGPT can be combined with Model Context Protocol (MCP) for runtime key extraction and live debugging validation. "The use of AI doesn't eliminate the need for human expertise," security researcher Alexey Bukhteyev said. "XLoader's most sophisticated protections, such as scattered key derivation logic and multi-layer function encryption, still require manual analysis and targeted adjustments. But the heavy lifting of triage, deobfuscation, and scripting can now be accelerated dramatically. What once took days can now be compressed into hours." RondoDox goes from DVRs to enterprise-wide weaponThe malware known as RondoDox has witnessed a 650% increase in exploitation vectors, expanding from niche DVR targeting to enterprise. This includes more than 15 new exploitation vectors targeting LB-LINK, Oracle WebLogic Server, PHPUnit, D-Link, NETGEAR, Linksys, Tenda, TP-Link devices, as well as a new command-and-control (C2) infrastructure on compromised residential IP. Once dropped, the malware proceeds to eliminate competition by killing existing malware such as XMRig and other botnets, disabling SELinux and AppArmor, and running the main payload that's compatible with the system architecture. DHS pushes sweeping biometric rule for immigrationThe U.S. Department of Homeland Security (DHS) has proposed an amendment to existing regulations governing the use and collection of biometric information. The agency has put forth requirements for a "robust system for biometrics collection, storage, and use related to adjudicating immigration benefits and other requests and performing other functions necessary for administering and enforcing immigration and naturalization laws." As part of the plan, any individual filing or associated with a benefit request or other request or collection of information, including U.S. citizens, U.S. nationals, and lawful permanent residents, must submit biometrics, regardless of their age, unless DHS otherwise exempts the requirement. The agency said using biometrics for identity verification and management will assist DHS's efforts to combat trafficking, confirm the results of biographical criminal history checks, and deter fraud. The DHS is taking comments on the proposal until January 2, 2026. Researchers uncover large-scale AWS abuse networkCybersecurity researchers have discovered a new large-scale attack infrastructure dubbed TruffleNet that's built around the open-source tool TruffleHog, which is used to systematically test compromised credentials and perform reconnaissance across Amazon Web Services' (AWS) environments. "In one incident involving multiple compromised credentials, we recorded activity from more than 800 unique hosts across 57 distinct Class C networks," Fortinet said. "This infrastructure was characterized by the use of TruffleHog, a popular open-source secret-scanning tool, and by consistent configurations, including open ports and the presence of Portainer," an open-source management UI for Docker and Kubernetes that simplifies container deployment and orchestration. In these activities, the threat actors make calls to the GetCallerIdentity and GetSendQuota APIs to test whether the credentials are valid and abuse the Simple Email Service (SES). While no follow-on actions were observed by Fortinet, it's assessed that the attacks originate from a possibly tiered infrastructure, with some nodes dedicated to reconnaissance and others reserved for later stages of the attack. Also observed alongside the TruffleNet reconnaissance activity is the abuse of SES for Business Email Compromise (BEC) attacks. It's currently not known if these are directly connected to each other. The development comes as Fortinet revealed that financially motivated adversaries are targeting a broad range of sectors but relying on the same low-complexity, high-return methods, typically gaining initial access through compromised credentials, external remote services like VPNs, and exploitation of public-facing applications. These attacks are often characterized by the use of legitimate remote access tools for secondary persistence and leveraging them for data exfiltration to their infrastructure. FIN7 deploys stealthy SSH backdoor for persistencePRODAFT has revealed that the financially motivated threat actor known as FIN7 (aka Savage Ladybug) has deployed since 2022 a "Windows specific SSH-based backdoor by packaging a self-contained OpenSSH toolset and an installer named install.bat." The backdoor provides attackers with persistent remote access and reliable file exfiltration using an outbound reverse SSH tunnel and SFTP. Cloudflare fends off massive DDoS surge on election dayWeb infrastructure company Cloudflare said Moldova's Central Election Commission (CEC) experienced significant cyber attacks in the days leading to the country's Parliament election on September 28. The CEC also witnessed a "series of concentrated, high-volume (DDoS) attacks strategically timed throughout the day" on the day of the elections. Attacks also targeted other election-related, civil society, and news websites. "These attack patterns mirrored those against the election authority, suggesting a coordinated effort to disrupt both official election processes and the public information channels voters rely on," it said, adding it mitigated over 898 million malicious requests directed at the CEC over a 12-hour period between 09:06:00 UTC and 21:34:00 UTC. Silent Lynx exploits diplomacy themes to breach targetsThe threat actor tracked as Silent Lynx (aka Cavalry Werewolf, Comrade Saiga, ShadowSilk, SturgeonPhisher, and Tomiris) has been observed targeting government entities, diplomatic missions, mining firms, and transportation companies. In one campaign, the adversary singled out organizations involved in Azerbaijan-Russian diplomacy, using phishing lures related to the CIS summit held in Dushanbe around mid-October 2025 to deliver the open-source Ligolo-ng reverse shell and a loader called Silent Loader that's responsible for running a PowerShell script to connect to a remote server. Also deployed is a C++ implant named Laplas that's designed to connect to an external server and receive additional commands for execution via "cmd.exe." Another payload of note is SilentSweeper, a .NET backdoor that extracts and runs a PowerShell Script that acts as a reverse shell. The second campaign, on the other hand, aimed at China-Central Asia relations to distribute a RAR archive that led to the deployment of SilentSweeper. The activity has been codenamed Operation Peek-a-Baku by Seqrite Labs. Doctor Web, in an independent analysis, said it investigated a phishing attack mounted by the threat actor targeting a government-owned organization within the Russian Federation to deliver reverse shell backdoors with the goal of collecting confidential information as well as network configuration data. Cyber gangs blend digital and physical extortion across EuropeEuropean organizations witnessed a 13% increase in ransomware over the past year, with entities in the U.K., Germany, Italy, France, and Spain most affected. A review of data leak sites over the period September 2024–August 2025 has revealed that the number of European victims has increased annually to 1,380. The most targeted sectors were manufacturing, professional services, technology, industrials, engineering, and retail. Since January 2024, over 2,100 victims across Europe have been named on extortion leak sites, with 92% involving file encryption and data theft. Akira (167), LockBit (162), RansomHub (141), INC, Lynx, and Sinobi were the most successful ransomware groups over the period. CrowdStrike said it's also seeing a surge in violence-as-a-service offerings across the continent with the goal of securing big payouts, including physical cryptocurrency theft. Cybercriminals connected to The Com, a loose-knit collective of young, English-speaking hackers, and a Russia-affiliated group called Renaissance Spider have coordinated physical attacks, kidnapping, and arson through Telegram-based networks. Renaissance Spider, which has been active since October 2017, is also said to have emailed fake bomb threats to European entities, likely aiming to undermine support for Ukraine. There have been 17 of these kinds of attacks since January 2024, out of which 13 took place in France. Fake ChatGPT and WhatsApp apps exploit user trustCybersecurity researchers have discovered apps that use the branding of established services like OpenAI's ChatGPT and DALL-E, and WhatsApp. While the fake DALL-E Android app ("com.openai.dalle3umagic") is used for ad traffic generation, the ChatGPT wrapper app connects to legitimate OpenAI APIs while identifying itself as an "unofficial interface" for the artificial intelligence chatbot. Although not outright malicious, impersonation without transparency can expose users to unintended security risks. The counterfeit WhatsApp app, named WhatsApp Plus, masquerades as an upgraded version of the messaging platform, but contains stealthy payloads that can harvest contacts, SMS messages, and call logs. "The flood of cloned applications reflects a deeper problem: brand trust has become a vector for exploitation," Appknox said. "As AI and messaging tools dominate the digital landscape, bad actors are learning that mimicking credibility is often more profitable than building new malware from scratch." Phishers weaponize trusted email accounts post-breachThreat actors are continuing to launch phishing campaigns after their initial compromise by leveraging compromised internal email accounts to expand their reach both within the compromised organization as well as externally to partner entities. "The follow-on phishing campaigns were primarily oriented towards credential harvesting," Cisco Talos said. "Looking forward, as defenses against phishing attacks improve, adversaries are seeking ways to enhance these emails’ legitimacy, likely leading to the increased use of compromised accounts post-exploitation." Asia-wide phishing surge uses multilingual luresRecent phishing campaigns across East and Southeast Asia have been found to leverage multilingual ZIP file lures and shared web templates to target government and financial organizations. "These operations are characterized by multilingual web templates, region-specific incentives, and adaptive payload delivery mechanisms, demonstrating a clear shift toward scalable and automation-driven infrastructure," Hunt.io said. "From China and Taiwan to Japan and Southeast Asia, the adversaries have continuously repurposed templates, filenames, and hosting patterns to sustain their operations while evading conventional detection. The strong overlap in domain structures, webpage titles, and scripting logic indicates a shared toolkit or centralized builder designed to automate payload delivery at scale. This investigation links multiple clusters to a unified phishing toolkit used across Asia." Remote kill-switch fears spark probe into Chinese busesAuthorities in Denmark have launched an investigation following a discovery that electric buses manufactured by the Chinese company Yutong had remote access to the vehicles' control systems and allowed them to be remotely deactivated. This has raised security concerns that the loophole could be exploited to affect buses while in transit. "The testing revealed risks that we are now taking measures against," Bernt Reitan Jenssen, chief executive of the Norwegian public transport authority Ruter, was quoted as saying. "National and local authorities have been informed and must assist with additional measures at a national level." Cloudflare scrubs botnet domains from global rankingsCloudflare has scrubbed domains associated with the massive AISURU botnet from its top domain rankings. According to security journalist Brian Krebs, AISURU's operators are using the botnet to boost their malicious domain rankings, while simultaneously targeting the company's domain name system (DNS) service. China delivers harsh verdict in cross-border scam crackdownA court in China has sentenced five members of a Myanmar crime syndicate to death for their roles in running industrial-scale scamming compounds near the border with China. The death sentences were handed out to the syndicate boss Bai Suocheng and his son Bai Yingcang, as well as Yang Liqiang, Hu Xiaojiang, and Chen Guangyi. Five others were sentenced to life. In all, 21 members and associates of the syndicate were convicted of fraud, homicide, injury, and other crimes. According to Xinhua, the defendants ran 41 industrial parks to facilitate telecommunications and online fraud at scale. The harsh penalty is the latest in a series of actions governments across the world have taken to combat the rise of cyber-enabled scam centers in Southeast Asia, where thousands are trafficked under the pretext of well-paying jobs, and are trapped, abused, and forced to defraud others in criminal operations worth billions. In September 2025, 11 members of the Ming crime family arrested during a 2023 cross-border crackdown were sentenced to death. Massive global credit card scam busted in €300M stingA coordinated law enforcement operation against a massive credit card fraud scheme dubbed Chargeback has led to the arrest of 18 suspects. The arrested individuals are German, Lithuanian, Dutch, Austrian, Danish, American, and Canadian nationals. "The alleged perpetrators are suspected of setting up an intricate scheme of fake online subscriptions to dating, pornography, and streaming services, among others, which were paid for by credit card," Eurojust said. "Among those arrested are five executive officials from four German payment service providers. The perpetrators deliberately kept monthly credit card payments to their accounts below the maximum of EUR 50 to avoid arousing suspicion among victims about high transfer amounts." The illicit scam is estimated to have defrauded at least €300 million from over 4.3 million credit card users with 19 million accounts in 193 countries between 2016 and 2021. The total value of attempted fraud against card users amounts to more than €750 million. Europol said the suspects used numerous shell companies, primarily registered in the U.K. and Cyprus, to conceal their activities. Every hack or scam has one thing in common — someone takes advantage of trust. As security teams improve their defenses, attackers quickly find new tricks. The best way to stay ahead isn’t to panic, but to stay informed, keep learning, and stay alert. Cybersecurity keeps changing fast — and our understanding needs to keep up.
thehackernews.comNov 6, 2025extracted
Come installare una VPN sul router, guida passo passo
L’implementazione di un client VPN a livello di router rappresenta una soluzione avanzata per la gestione centralizzata della sicurezza e della privacy di una rete domestica o di piccole dimensioni. Tale configurazione garantisce che tutto il traffico in uscita dalla rete sia automaticamente cifrato e instradato attraverso il server VPN selezionato. Indice degli argomenti Installare una VPN direttamente sul router significa estendere la protezione a tutta la rete domestica o aziendale in modo automatico e continuo. Invece di configurare la VPN singolarmente su ogni dispositivo, il traffico Internet di tutti i terminali collegati al router – computer, smartphone, smart TV, console, dispositivi IoT – viene instradato attraverso il tunnel criptato della VPN. Questo approccio centralizzato offre un livello di sicurezza superiore e garantisce che ogni connessione sia protetta fin dal punto di accesso alla rete. Si tratta di una soluzione particolarmente utile per famiglie, uffici o ambienti in cui si utilizzano molti dispositivi diversi, perché assicura protezione anche a quelli che non permettono l’installazione diretta di una VPN, come alcune smart TV o dispositivi con sistemi operativi chiusi. Una VPN installata sul router agisce come un filtro di sicurezza unico per tutto il traffico in entrata e in uscita. Tutti i dispositivi connessi alla rete beneficiano automaticamente della crittografia dei dati e della modifica dell’indirizzo IP, senza dover installare o attivare nulla manualmente. Ciò riduce il rischio di dimenticanze o configurazioni errate e protegge anche i dispositivi che normalmente non supportano applicazioni VPN dedicate. Per esempio, una smart TV o una console di gioco, che di solito non consentono l’uso di software di sicurezza, possono così accedere a contenuti in streaming internazionali e navigare con la stessa protezione di un computer. Questa impostazione centralizzata è particolarmente apprezzata anche da chi desidera mantenere una rete domestica uniforme e più semplice da gestire. Molti utenti scelgono di acquistare router già configurati per l’uso con una VPN, una soluzione che elimina le difficoltà tecniche e garantisce un funzionamento immediato. I cosiddetti router preconfigurati sono dispositivi venduti con la VPN già integrata nel firmware, in modo che la connessione protetta sia attiva non appena il router viene collegato alla rete. Provider come NordVPN, Surfshark ed ExpressVPN offrono questa possibilità in collaborazione con produttori specializzati, come Asus, Linksys e Netgear. Questi modelli sono pensati per garantire prestazioni elevate, con processori in grado di gestire la crittografia senza rallentare la connessione. Per esempio, NordVPN propone una linea di router compatibili con il protocollo NordLynx, basato su WireGuard, che assicura connessioni rapide e stabili. Surfshark offre supporto nativo a OpenVPN e WireGuard, mentre ExpressVPN fornisce router dotati del proprio firmware Lightway, sviluppato per connettersi quasi istantaneamente e mantenere una velocità costante. In tutti i casi, questi router permettono di collegare più dispositivi contemporaneamente, superando i limiti delle app tradizionali e garantendo protezione continua per tutta la rete domestica o aziendale. Quando il router in uso non dispone del supporto VPN integrato, è possibile installare un firmware di terze parti per aggiungere manualmente questa funzionalità. Le opzioni più diffuse sono DD-WRT e Tomato, due sistemi open source che sostituiscono il software originale del router e ne ampliano le capacità. Entrambi permettono di configurare protocolli VPN come OpenVPN e WireGuard, offrendo un controllo più approfondito su crittografia, gestione del traffico e priorità di connessione. DD-WRT è particolarmente apprezzato per la compatibilità con un’ampia gamma di modelli e per la sua stabilità, mentre Tomato è più intuitivo e adatto a chi desidera un’interfaccia semplice e chiara. Tuttavia, l’installazione di un firmware alternativo richiede cautela: è necessario verificare che il router sia compatibile e seguire scrupolosamente le istruzioni del produttore, poiché un errore nella procedura può compromettere il funzionamento del dispositivo. Una volta configurato correttamente, il router diventa un vero e proprio hub di sicurezza, capace di gestire connessioni VPN multiple e di mantenere prestazioni elevate. Configurare manualmente una VPN su un router può sembrare complesso, ma seguendo un processo chiaro è possibile completare l’installazione in pochi minuti. La procedura varia leggermente a seconda del provider VPN e del modello di router, ma i principi di base restano gli stessi: accedere al pannello di controllo, importare i file di configurazione, inserire le credenziali e verificare la connessione. Il primo passo consiste nell’accedere all’interfaccia di gestione del router tramite browser, digitando l’indirizzo IP del dispositivo – solitamente 192.168.0.1 o 192.168.1.1 – e autenticandosi con le credenziali amministrative. È consigliabile verificare che il router disponga dell’ultima versione del firmware, poiché gli aggiornamenti possono introdurre nuove opzioni per la configurazione VPN o migliorare la stabilità della connessione. A questo punto, bisogna individuare la sezione dedicata alla VPN o alla connessione avanzata, dove sarà possibile importare le impostazioni del provider. Dopo aver effettuato l’accesso al pannello, occorre recuperare i file di configurazione forniti dal servizio VPN scelto. Questi file contengono le informazioni necessarie per stabilire la connessione, come gli indirizzi dei server, le chiavi di crittografia e i parametri di sicurezza. La maggior parte dei provider, tra cui NordVPN, Surfshark ed ExpressVPN, mette a disposizione un’area dedicata nel proprio sito da cui scaricare i file .ovpn per OpenVPN o i file .conf per WireGuard. Alcuni servizi consentono anche di generare automaticamente configurazioni personalizzate, selezionando il server e il protocollo preferiti. Una volta scaricati, i file vanno conservati sul computer da cui si effettuerà la configurazione del router. A questo punto è necessario tornare al pannello di controllo del router e caricare i file di configurazione precedentemente scaricati. Il router importerà automaticamente le impostazioni relative al server, alla porta di connessione e al tipo di protocollo. In seguito, bisognerà inserire manualmente le credenziali del proprio account VPN, generalmente il nome utente e la password associati al servizio. Alcuni modelli permettono anche di attivare opzioni aggiuntive, come la connessione automatica all’avvio o la selezione di un server alternativo in caso di disconnessione. Una volta salvate le impostazioni, il router avvierà la connessione alla VPN e instraderà tutto il traffico della rete attraverso il tunnel cifrato. Dopo la configurazione è importante verificare che la VPN sia effettivamente attiva. Per farlo, basta collegarsi a Internet da un qualsiasi dispositivo connesso al router e visitare un sito che mostri l’indirizzo IP, come whatismyip.com. Se l’indirizzo visualizzato corrisponde a quello del server VPN e non a quello del provider Internet, la configurazione è avvenuta con successo. Alcuni router visualizzano anche lo stato della connessione VPN direttamente nella loro interfaccia, indicando se il tunnel è attivo o interrotto. In caso di problemi di connessione o cali di velocità, si possono testare diversi server o protocolli, poiché le prestazioni possono variare a seconda della distanza geografica e del carico dei nodi. Una volta completata la verifica, la rete sarà interamente protetta e ogni dispositivo collegato potrà navigare in modo sicuro e anonimo, senza necessità di ulteriori configurazioni individuali. Ogni provider VPN ha un proprio metodo per l’installazione su router che varia in base ai protocolli supportati, alla compatibilità del dispositivo e al tipo di firmware utilizzato. Sebbene il principio di base sia sempre lo stesso – proteggere tutta la rete instradando il traffico attraverso un tunnel criptato – le procedure e le funzionalità offerte possono essere diverse. NordVPN, Surfshark ed ExpressVPN sono tra i servizi che offrono la configurazione più intuitiva e documentata, con guide dettagliate e supporto tecnico dedicato per ogni modello di router compatibile. 🌍 Server: 7.000+ server in 118 paesi 📱 Massimo dispositivi: 10 📍 IP dedicato: ✔ 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: IKEv2/IPsec, OpenVPN, NordLynx 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Panama 🔥 Offerte attive: SCONTO fino al 63% NordVPN offre una delle configurazioni più complete e flessibili, compatibile con un’ampia gamma di router come Asus, Netgear, TP-Link e quelli basati su firmware DD-WRT o AsusWRT. La configurazione standard avviene tramite il protocollo OpenVPN, che garantisce un equilibrio ottimale tra sicurezza e velocità, ma negli ultimi anni il provider ha introdotto anche il supporto a WireGuard tramite la sua versione ottimizzata, NordLynx, disponibile su alcuni router di nuova generazione. Per configurare NordVPN, è necessario accedere al pannello di controllo del router, importare i file di configurazione forniti dal sito ufficiale e inserire le credenziali del proprio account. La piattaforma offre anche guide passo passo per ogni marca di router, semplificando la procedura anche agli utenti meno esperti. Una volta completata l’installazione, la connessione sarà protetta automaticamente per tutti i dispositivi collegati alla rete. NordVPN permette inoltre di scegliere server specializzati, come quelli dedicati al traffico P2P o al doppio instradamento (Double VPN), che aumentano il livello di anonimato. Il piano NordVPN Base garantisce una VPN sicura e veloce, progettata per proteggere la connessione e mantenere privata la navigazione. È la scelta ideale per chi desidera una protezione essenziale della rete, senza funzionalità aggiuntive. Anche questa versione prevede una garanzia di rimborso entro 30 giorni. Il piano NordVPN Plus, il più richiesto, offre un livello di sicurezza superiore. Oltre alla VPN, integra un sistema anti-malware e di protezione durante la navigazione, un blocco automatico di pubblicità e tracker e un password manager con scanner di violazioni, che segnala eventuali fughe di dati personali. Il piano NordVPN Ultimate rappresenta l’opzione più completa. Include tutte le funzioni del Plus e aggiunge uno spazio cloud crittografato da 1 terabyte per l’archiviazione sicura dei file, oltre a un’assicurazione cyber con copertura fino a 5.000 euro per il rimborso dei danni derivanti da truffe informatiche o furti d’identità. L’offerta di NordVPN Black Friday attiva fino al 10 dicembre 2025 si basa sulla fornitura di un servizio di VPN (Virtual Private Network), che mira a garantire sicurezza e privacy online, unita a funzionalità avanzate che migliorano l’esperienza di navigazione. Le funzionalità che rendono NordVPN un servizio di sicurezza completo sono: Crittografia di nuova generazione: - Utilizza la crittografia avanzata AES-256, lo standard più sicuro. - Crea un “tunnel” crittografato per i dati, proteggendoli da occhi indiscreti, specialmente quando usiamo reti Wi-Fi pubbliche non sicure. Rigida politica di No-Log: - NordVPN non raccoglie né memorizza le attività online (larghezza di banda utilizzata, log di traffico, indirizzi IP, dati di navigazione). Questo assicura che le nostre attività rimangano private e non possano essere condivise. Configurazione VPN facile: - Permette di connettersi a un server VPN con pochi click. - Un algoritmo basato sull’AI sceglie automaticamente il server migliore e più veloce, in base alle condizioni della nostra rete. Copertura globale e velocità: - Offre una vasta rete di oltre 8.400 server in 165 località - Garantisce velocità sorprendenti e larghezza di banda illimitata (nessun rallentamento o interruzione). Oltre alla VPN di base, l’offerta include strumenti avanzati per una protezione totale: Threat Protection Pro™ (anti-malware integrato): - Uno strumento di sicurezza integrato nell’app NordVPN. - Funziona anche quando la VPN è disattivata. - Protegge da download pericolosi, siti di phishing, pubblicità invadenti e tracker online. Avvisi sulle credenziali trapelate (Dark Web Monitor): - Scansiona automaticamente il dark web alla ricerca di eventuali fughe di dati personali. - Ti invia una notifica immediata se le tue credenziali sono state compromesse. Streaming più sicuro: - Consente di guardare contenuti in streaming senza limiti di larghezza di banda o velocità su tutti i dispositivi. - Inoltre, ci aiuta a mantenere l’accesso ai contenuti e ai siti che usiamo abitualmente anche quando siamo all’estero. Copertura multi-dispositivo: - Un singolo account copre fino a 10 dispositivi contemporaneamente. - Compatibile con tutti i principali sistemi operativi e browser. - Possibilità di installazione sul router per proteggere l’intera rete domestica. Kill Switch: - Una funzionalità di sicurezza che disattiva l’accesso a internet se la connessione VPN dovesse cadere, prevenendo la fuga accidentale del nostro indirizzo IP reale e dei tuoi dati. L’offerta attuale è focalizzata sul Black Friday e include: Sconto esclusivo Black Friday: 74% di sconto sul piano più 3 mesi extra di servizio. Garanzia di Rimborso di 30 Giorni: permette di provare il servizio senza rischi. E’ possibile aggiungere due servizi all’ abbonamento VPN: NordPass gestore di password: permette di generare e archiviare password complesse in modo sicuro, sincronizzandole e inserendole automaticamente. NordLocker , archiviazione Cloud cifrata: offre uno spazio cloud per archiviare documenti, foto e file con crittografia end-to-end, garantendone il backup e la sicurezza. Questa tabella compara i prezzi per i tre piani in base alle diverse durate, evidenziando l’offerta iniziale più vantaggiosa (quella da 2 anni, più 3 mesi extra, che corrisponde a 27 mesi totali). 🌍 Server: 3200+ in 100 paesi 📱 Massimo dispositivi: illimitati 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: OpenVPN, IKEv2, Shadowsocks, Wireguard e L2TP 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Paesi Bassi 🔥 Offerte attive: SCONTO fino all’83% + 3 mesi gratis 🔥 Surfshark è compatibile con la maggior parte dei router che supportano i protocolli OpenVPN o WireGuard, e offre un’interfaccia di configurazione semplice anche su firmware come DD-WRT, AsusWRT e OpenWRT. Per installarla, basta scaricare i file di configurazione dal proprio account Surfshark, scegliere il server desiderato e caricare le impostazioni nel pannello di controllo del router. La piattaforma consente di utilizzare un numero illimitato di dispositivi connessi contemporaneamente, e questa caratteristica diventa particolarmente vantaggiosa quando la VPN è installata direttamente sul router, poiché tutti i dispositivi della rete beneficiano della stessa protezione senza restrizioni. Surfshark offre inoltre la possibilità di configurare DNS personalizzati e di attivare funzioni avanzate come il CleanWeb, un sistema integrato che blocca pubblicità, tracker e siti malevoli a livello di rete. Una volta completata la configurazione, la connessione VPN si attiverà automaticamente a ogni riavvio del router, garantendo una protezione costante e senza interventi manuali. Il piano Starter comprende la VPN di Surfshark, progettata per garantire una navigazione sicura e privata, insieme all’Alternative ID, una funzione che genera indirizzi email alternativi per proteggere l’identità digitale e ridurre lo spam. A questi si aggiungono l’antivirus, un sistema di alert che segnala eventuali violazioni di dati, il motore di ricerca privato Search e il servizio Incogni, che consente la rimozione automatica dei dati personali dai database pubblici. Il piano Surfshark One offre le stesse caratteristiche del pacchetto Starter ma con un livello di servizio più avanzato, che assicura prestazioni potenziate e aggiornamenti costanti, in particolare nella protezione in tempo reale contro malware e minacce informatiche. La versione Surfshark One+ rappresenta l’offerta premium della gamma. Oltre a tutte le funzioni già incluse, prevede strumenti avanzati per la gestione e la tutela dell’identità digitale, una copertura più ampia per la rimozione dei dati personali online e un’assistenza dedicata in caso di violazioni o furti di dati. Inoltre Surfshark offre: VPN rapida e sicura: crittografa la connessione internet per navigare in modo anonimo e sicuro. - Oltre 3200 server basati su sola RAM in 100 paesi (migliore velocità e privacy). - Dispositivi Illimitati: si possono connettere tutti i dispositivi che si vogliono con unico account. Alternative ID (Alt ID): permette di generare un’e-mail mascherata per iscriversi ai servizi online, evitando che la nostra email reale venga esposta e riempiendosi di spam. CleanWeb: funzionalità che blocca annunci, tracker e pop-up per il consenso dei cookie durante la navigazione. L’offerta principale è sul piano a 24 mesi che include 3 mesi extra gratuiti ed è quella che offre il maggiore risparmio. Questa opzione offre il massimo risparmio e la tariffa mensile più bassa. La durata totale dell’abbonamento è di 27 mesi. Questa opzione offre una durata minore ma include comunque i 3 mesi extra gratuiti. La durata totale dell’abbonamento è di 15 mesi. Questa è l’opzione più flessibile, ma anche la più costosa, in quanto non include sconti per l’impegno a lungo termine. Il pagamento è fatturato mensilmente. Ecco un confronto sulle funzionalità incluse nei tre piani, indipendentemente dalla durata dell’abbonamento scelta: 🌍 Server: 3000 server in 105 paesi 📱 Massimo dispositivi: 8 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS, Linux 🔐 Sicurezza: IKEv2, OpenVPN 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Isole Vergini Britanniche 🔥 Offerte attive: SCONTO fino al 49% + 3 mesi GRATIS ExpressVPN adotta un approccio diverso rispetto ai competitor, offrendo un proprio firmware dedicato, progettato per semplificare la gestione della VPN a livello di rete. Questo firmware può essere installato su vari modelli compatibili di Linksys, Netgear e Asus, e trasforma il router in un dispositivo completamente integrato con la piattaforma ExpressVPN. L’interfaccia utente è molto intuitiva e permette di cambiare server, attivare o disattivare la connessione e gestire lo split tunneling direttamente dal pannello del router, senza bisogno di passare dal computer. Oltre a questa opzione, ExpressVPN ha sviluppato Aircove, un router progettato interamente in-house, già predisposto per la connessione sicura e compatibile con il protocollo Lightway, che garantisce connessioni quasi istantanee e stabili anche in caso di passaggio tra reti Wi-Fi e 5G. Aircove rappresenta la soluzione ideale per chi desidera un dispositivo plug-and-play, in grado di offrire protezione immediata su tutta la rete domestica con la garanzia delle prestazioni tipiche di ExpressVPN. L’offerta si articola su tre livelli di abbonamento — Base, Avanzato e Pro — disponibili con formula mensile, annuale o biennale. Quest’ultima include 4 mesi aggiuntivi gratuiti e rappresenta la scelta più conveniente nel lungo periodo. Tutti i piani comprendono una VPN veloce e sicura, accompagnata da una garanzia di rimborso entro 30 giorni, pensata per chi desidera proteggere i propri dati, navigare in modo privato e accedere liberamente ai contenuti globali. Il piano Base è la soluzione più semplice ed economica. Con un costo di 3,49 dollari al mese per 28 mesi, pari a 97,72 dollari complessivi, consente di collegare fino a 10 dispositivi simultaneamente e offre una protezione “Lite” che blocca siti pericolosi e pubblicità di base. È l’opzione ideale per chi desidera una VPN affidabile senza funzioni avanzate. Il piano Avanzato, il più scelto dagli utenti, propone un equilibrio ottimale tra prezzo e prestazioni. Al costo di 4,49 dollari al mese (pari a 125,72 dollari per 28 mesi), aggiunge una protezione più estesa contro tracker e contenuti indesiderati, un gestore di password integrato, 3 giorni di eSIM illimitata e fino a 12 connessioni contemporanee. Inoltre, include uno sconto del 50% sul router Aircove, progettato per integrarsi con la VPN. È la soluzione consigliata per chi utilizza spesso Internet per lavoro o viaggi e cerca una protezione costante su più dispositivi. Il piano Pro è pensato per chi desidera il massimo livello di sicurezza, flessibilità e personalizzazione. Costa 7,49 dollari al mese, per un totale di 209,72 dollari nei 28 mesi, e comprende tutte le funzioni del piano Avanzato, con in più 14 connessioni simultanee, 5 giorni di eSIM illimitata, uno sconto del 75% su Aircove e un indirizzo IP dedicato, ideale per professionisti, gamer o aziende che necessitano di un’identità di rete stabile e sicura. Le versioni annuali e mensili mantengono la stessa struttura di servizi, ma presentano prezzi più elevati rispetto all’opzione biennale, che resta la più vantaggiosa in termini di risparmio complessivo. Molti servizi VPN prevedono un limite massimo di dispositivi che possono essere connessi contemporaneamente sotto un unico abbonamento. Installando la VPN direttamente sul router, questo vincolo viene superato, poiché per il provider tutta la rete domestica o aziendale risulta come un solo dispositivo connesso. In pratica, è possibile proteggere senza limiti computer, tablet, smartphone e dispositivi smart con un’unica configurazione. Questo è un vantaggio notevole per le famiglie numerose o per chi gestisce più dispositivi connessi nello stesso momento, poiché consente di sfruttare al massimo l’abbonamento senza dover acquistare piani aggiuntivi. Nonostante i vantaggi evidenti, l’installazione di una VPN sul router presenta anche alcuni limiti da considerare. Dal punto di vista tecnico, la configurazione iniziale può essere più complessa rispetto all’uso di un’app su singolo dispositivo e richiede un router compatibile. Inoltre, una volta attiva, la VPN copre indistintamente tutti i dispositivi connessi: questo significa che non è possibile escluderne uno senza disattivare la connessione protetta per tutti. Un altro aspetto da tenere presente è che il traffico VPN richiede un certo carico di elaborazione e, su router meno potenti, può comportare un leggero calo di velocità. Tuttavia, con modelli recenti e server VPN di alta qualità, questa differenza è spesso impercettibile. Per molti utenti, i benefici in termini di sicurezza e praticità superano ampiamente questi piccoli compromessi. Non tutti i router sono in grado di gestire una connessione VPN nativa ed è fondamentale verificarne la compatibilità prima di procedere con l’installazione. I modelli più recenti e di fascia medio-alta supportano protocolli come OpenVPN, WireGuard o L2TP/IPSec, che permettono una configurazione stabile e sicura. Alcuni marchi, come Asus, Netgear o TP-Link, integrano già il supporto VPN nel firmware, consentendo una configurazione diretta tramite l’interfaccia web del dispositivo. In altri casi, potrebbe essere necessario installare un firmware alternativo, come DD-WRT o AsusWRT-Merlin, che aggiunge funzioni avanzate di rete e sicurezza. È sempre consigliabile consultare la scheda tecnica del router o il sito del produttore per accertarsi che siano supportati i protocolli desiderati. In alternativa, alcuni provider VPN offrono router preconfigurati con la propria rete, una soluzione ideale per chi preferisce evitare procedure tecniche e ottenere una connessione sicura e pronta all’uso su tutta la rete domestica. Una volta installata la VPN sul router, è possibile accedere a funzioni avanzate che permettono di personalizzare ulteriormente l’esperienza di navigazione. Tra queste, lo split tunneling e la possibilità di scegliere server dedicati rappresentano due strumenti fondamentali per ottimizzare velocità, sicurezza e gestione del traffico di rete. Queste funzioni sono particolarmente utili per chi utilizza la VPN sia per scopi professionali che personali e desidera mantenere un equilibrio tra privacy e prestazioni. Lo split tunneling consente di decidere quali dispositivi o applicazioni devono utilizzare la connessione VPN e quali, invece, devono collegarsi direttamente a Internet. Questa funzione è utile in contesti in cui non tutte le attività richiedono crittografia o cambio di IP. Per esempio, si può impostare che la VPN protegga solo i dispositivi aziendali o i servizi di streaming esteri, lasciando invece che il traffico locale, come stampanti o smart home, utilizzi la connessione standard per evitare rallentamenti. Sul router, lo split tunneling si configura facilmente tramite l’interfaccia del firmware, che consente di selezionare manualmente i dispositivi da includere o escludere. ExpressVPN e NordVPN integrano questa opzione in modo nativo, mentre Surfshark la offre tramite impostazioni avanzate. Utilizzare lo split tunneling permette di ottimizzare la banda, mantenendo la velocità della rete domestica e garantendo al tempo stesso la sicurezza per le connessioni più sensibili. La scelta del server VPN è uno degli elementi che più influiscono sulle prestazioni della connessione. In generale, più il server è vicino alla propria posizione geografica, minore sarà la latenza e maggiore la velocità di navigazione. Tuttavia, molti provider offrono anche server ottimizzati per specifici usi: streaming, torrent, gaming o attività professionali che richiedono connessioni stabili e crittografate. NordVPN, ad esempio, consente di selezionare server specializzati per P2P o per una maggiore privacy con il doppio instradamento, mentre ExpressVPN e Surfshark utilizzano un sistema automatico che collega l’utente al nodo più veloce disponibile in base al carico di rete e alla distanza. In alcuni casi, è possibile testare la velocità dei server direttamente dal pannello di controllo o tramite strumenti integrati, verificando ping, jitter e banda disponibile. Scegliere un server ottimale consente di mantenere prestazioni elevate anche con la VPN attiva, assicurando un equilibrio tra sicurezza, rapidità e affidabilità della connessione su tutti i dispositivi collegati al router.
cybersecurity360.itNov 3, 2025extracted
Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors
Malware campaigns distributing the RondoDox botnet have expanded their targeting focus to exploit more than 50 vulnerabilities across over 30 vendors. The activity, described as akin to an "exploit shotgun" approach, has singled out a wide range of internet-exposed infrastructure, including routers, digital video recorders (DVRs), network video recorders (NVRs), CCTV systems, web servers, and various other network devices, according to Trend Micro. The cybersecurity company said it detected a RondoDox intrusion attempt on June 15, 2025, when the attackers exploited CVE-2023-1389, a security flaw in TP-Link Archer routers that has come under active exploitation repeatedly since it was first disclosed in late 2022. RondoDox was first documented by Fortinet FortiGuard Labs back in July 2025, detailing attacks aimed at TBK digital video recorders (DVRs) and Four-Faith routers to enlist them in a botnet for carrying out distributed denial-of-service (DDoS) attacks against specific targets using HTTP, UDP, and TCP protocols. "More recently, RondoDox broadened its distribution by using a 'loader-as-a-service' infrastructure that co-packages RondoDox with Mirai/Morte payloads – making detection and remediation more urgent," Trend Micro said. RondoDox's expanded arsenal of exploits includes nearly five dozen security flaws, out of which 18 don't have a CVE identifier assigned. The 56 vulnerabilities span various vendors such as D-Link, TVT, LILIN, Fiberhome, Linksys, BYTEVALUE, ASMAX, Brickcom, IQrouter, Ricon, Nexxt, NETGEAR, Apache, TBK, TOTOLINK, Meteobridge, Digiever, Edimax, QNAP, GNU, Dasan, Tenda, LB-LINK, AVTECH, Zyxel, Hytec Inter, Belkin, Billion, and Cisco. "The latest RondoDox botnet campaign represents a significant evolution in automated network exploitation," the company added. "It's a clear signal that the campaign is evolving beyond single-device opportunism into a multivector loader operation." Late last month, CloudSEK revealed details of a large-scale loader-as-a-service botnet distributing RondoDox, Mirai, and Morte payloads through SOHO routers, Internet of Things (IoT) devices, and enterprise apps by weaponizing weak credentials, unsanitized inputs, and old CVEs. The development comes as security journalist Brian Krebs noted that the DDoS botnet known as AISURU is "drawing a majority of its firepower" from compromised IoT devices hosted on U.S. internet providers like AT&T, Comcast, and Verizon. One of the botnet's operators, Forky, is alleged to be based in Sao Paulo, Brazil, and is also linked to a DDoS mitigation service called Botshield. In recent months, AISURU has emerged as one of the largest and most disruptive botnets, responsible for some of the record-setting DDoS attacks seen to date. Built on the foundations of Mirai, the botnet controls an estimated 300,000 compromised hosts worldwide. The findings also follow the discovery of a coordinated botnet operation involving over 100,000 unique IP addresses from no less than 100 countries targeting Remote Desktop Protocol (RDP) services in the U.S., per GreyNoise. The activity is said to have commenced on October 8, 2025, with the majority of the traffic originating from Brazil, Argentina, Iran, China, Mexico, Russia, South Africa, Ecuador, and others. "The campaign employs two specific attack vectors – RD Web Access timing attacks and RDP web client login enumeration – with most participating IPs sharing one similar TCP fingerprint, indicating centralized control," the threat intelligence firm said.
thehackernews.comOct 13, 2025extracted
RondoDox botnet targets 56 n-day flaws in worldwide attacks
A new large-scale botnet called RondoDox is targeting 56 vulnerabilities in more than 30 distinct devices, including flaws first disclosed during Pwn2Own hacking competitions. The attacker focuses on a wide range of exposed devices, including DVRs, NVRs, CCTV systems, and web servers and have been active since June. The RondoDox botnet leverages what Trend Micro researchers call an “exploit shotgun” strategy, where numerous exploits are used simultaneously to maximize the infections, even if the activity is very noisy. Since FortiGuard Labs discovered RondoDox, the botnet appears to have expanded the list of exploited vulnerabilities, which included CVE-2024-3721 and CVE-2024-12856. Mass n-day exploitation In a report today, Trend Micro says that RondoDox exploits CVE-2023-1389, a flaw in the TP-Link Archer AX21 Wi-Fi router that was originally demonstrated at Pwn2Own Toronto 2022. Pwn2Own is a hacking competition organized twice a year by Trend Micro's Zero Day Initiative (ZDI), where white-hat teams demonstrate exploits for zero-day vulnerabilities in widely used products. The security researchers note that the botnet developer pay close attention to exploits demonstrated during Pwn2Own events, and move quickly to weaponize them, as Mirai did with CVE-2023-1389 in 2023. Below is a list of post-2023 n-day flaws RondoDox includes in its arsenal: Digiever – CVE-2023-52163 QNAP – CVE-2023-47565 LB-LINK – CVE-2023-26801 TRENDnet – CVE-2023-51833 D-Link – CVE-2024-10914 TBK – CVE-2024-3721 Four-Faith – CVE-2024-12856 Netgear – CVE-2024-12847 AVTECH – CVE-2024-7029 TOTOLINK – CVE-2024-1781 Tenda – CVE-2025-7414 TOTOLINK – CVE-2025-1829 Meteobridge – CVE-2025-4008 Edimax – CVE-2025-22905 Linksys – CVE-2025-34037 TOTOLINK – CVE-2025-5504 TP-Link – CVE-2023-1389 Older flaws, especially in devices that reached end of life, are a significant risk as they are more likely to remain unpatched. More recent ones in supported hardware are equally dangerous since many users tend to ignore firmware updates after setting up the devices. Trend Micro also found that RondoDox incorporates exploits for 18 command injection flaws that have not been assigned a vulnerability ID (CVE). They impact D-Link NAS units, TVT and LILIN DVRs, Fiberhome, ASMAX, and Linksys routers, Brickcom cameras, and other unidentified endpoints. To protect against RondoDox and other botnet attacks, apply the latest available firmware updates for your device and replace EoL equipment. It is also recommended to segment your network to isolate critical data from internet-facing IoTs, or from guest connections, and replace default credentials with secure passwords. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comOct 9, 2025extracted
Exium by NETGEAR brings unified SASE and firewall protection to SMEs and MSPs
Exium by NETGEAR brings unified SASE and firewall protection to SMEs and MSPs NETGEAR announced a tailored security solution for small and medium-sized enterprises (SMEs). Building on an acquisition made earlier this year, NETGEAR is delivering Exium, an all-in-one Secure Access Service Edge (SASE) and hybrid firewall solution designed for SMEs and the managed service providers (MSPs) that support them. SMEs face rising cybersecurity threats According to the Verizon Data Breach Investigations Report SMEs faced more than 3,000 cybersecurity incidents, nearly four times as many cybersecurity incidents as large enterprises, in 2025. Despite this increased risk, many security solutions remain overly complex or fragmented, making them difficult for smaller businesses to implement and manage effectively. Delivering on the vision for NETGEAR’s enterprise offering set forth by NETGEAR for Business President and GM Pramod Badjate, integration of the Exium SASE platform fills this gap by providing SMEs with a unified solution that combines advanced threat protection, AI-powered zero-trust network access (ZTNA), secure web gateway (SWG), SD-WAN, and firewall capabilities in a single, user-friendly platform. The platform allows SMEs to replace certain outdated, fragmented security systems with a cloud-managed solution. All features are managed through a centralized interface, simplifying network operations and security management. This helps enable businesses to protect data, users, and devices across multiple sites and remote locations with ease. “Small and medium businesses are just as exposed to cyberthreats as larger enterprises, if not more, but most security solutions are either too complicated or piecemeal for them to handle,” said Farooq Khan, VP of Software Security at NETGEAR. “By integrating Exium with our networking solutions, we’re offering SMEs easy-to-use, enterprise-grade protection. This helps empower them to counter modern threats confidently, lessening the burden on internal IT teams.” Built for Managed Service Providers The platform is optimized for MSPs, offering multi-tenant management and streamlined service delivery. This scalable, cost-effective security framework equips SMEs with the tools needed to help build a secure and resilient network infrastructure. With this solution, businesses can focus more on growth and innovation.
helpnetsecurity.comOct 1, 2025extracted
Il segreto per navigare in sicurezza: ecco come installare una VPN
Installare una VPN può sembrare complicato, ma in realtà è un processo abbastanza semplice, soprattutto se si utilizza un servizio VPN commerciale. Ecco una guida generale che aiuterà a capire i passaggi principali. Indice degli argomenti Una VPN, acronimo di Virtual Private Network, è una tecnologia che crea un “tunnel” crittografato tra il dispositivo dell’utente e un server remoto gestito dal provider VPN. Attraverso questo tunnel, tutti i dati vengono trasmessi in modo sicuro e protetto da occhi indiscreti, rendendo di fatto anonima la navigazione. La VPN maschera l’indirizzo IP reale dell’utente, sostituendolo con quello del server remoto a cui ci si connette, e consente di aggirare eventuali restrizioni territoriali imposte da piattaforme o governi. L’installazione di una VPN è consigliata in numerose situazioni: quando si vuole evitare il tracciamento da parte di inserzionisti e motori di ricerca, quando si lavora da remoto su reti pubbliche o aziendali sensibili, oppure per sbloccare contenuti digitali accessibili solo da specifiche aree geografiche. Navigando senza VPN l’indirizzo IP pubblico e molte informazioni sul comportamento online vengono registrate da siti web, provider di servizi internet (ISP), motori di ricerca e social network. La VPN impedisce che queste informazioni vengano raccolte, offrendo un maggiore livello di anonimato digitale. Nei Paesi con normative restrittive sulla libertà d’informazione, la VPN diventa uno strumento vitale per accedere a notizie, social media o comunicare in modo sicuro. Piattaforme come Netflix, Amazon Prime Video, BBC iPlayer o Hulu mostrano un catalogo diverso a seconda del Paese in cui ci si trova. Con una VPN è possibile simulare la connessione da un altro Stato e accedere a contenuti esclusivi non disponibili in Italia. Questo vale anche per eventi sportivi trasmessi in streaming, software disponibili solo in certi mercati, o servizi limitati da firewall aziendali o scolastici. I Wi-Fi pubblici presenti in bar, aeroporti o biblioteche non sono sicuri: chiunque sia connesso alla stessa rete potrebbe intercettare i dati trasmessi dagli altri utenti. Una VPN cripta completamente il traffico in entrata e in uscita dal dispositivo, proteggendo password, email, messaggi e transazioni bancarie da attacchi di tipo man-in-the-middle o sniffing. 1. Scegliere un servizio VPN Il primo passo è scegliere un provider VPN. Ci sono molti servizi disponibili, sia gratuiti che a pagamento. I servizi a pagamento offrono generalmente maggiore sicurezza, velocità e affidabilità. Quando si sceglie una VPN valutare: Affidabilità e sicurezza: Assicurarsi che sia una VPN con una solida politica di “no-log” (non registra le attività online) e che utilizzi protocolli di crittografia robusti. Velocità: Una buona VPN non dovrebbe rallentare in modo significativo la nostra connessione. Server disponibili: Un numero maggiore di server in diverse posizioni geografiche ci dà più opzioni per mascherare la nostra posizione. Prezzo: Confrontare i piani di abbonamento e scegliere quello più adatto alle nostre esigenze e al budget. 2. Iscriversi al servizio e scaricare l’app VPN Una volta scelto il provider, sottoscriviamo l’abbonamento e creiamo un account. Dopo aver completato l’iscrizione, avremo accesso alla nostra area utente da cui potremo scaricare il software o l’app del servizio per il nostro dispositivo (PC, Mac, smartphone, tablet, ecc.). 3. Installare l’applicazione VPN Su PC/MacOS: Scaricare il file di installazione (generalmente un file .exe per Windows o.dmg per macOS) e avviare il processo di installazione. Seguire le istruzioni sullo schermo, che di solito consistono nel cliccare su “Avanti” o “Installa” e accettare i termini di servizio. Su smartphone/tablet (Android/iOS): Andare su Google Play Store o all’App Store di Apple, cercare il nome del servizio VPN e scaricare l’app ufficiale. L’installazione è automatica. 4. Configurare e connettersi alla VPN Dopo l’installazione, aprire l’app VPN. Ci verrà chiesto di inserire le credenziali dell’account (nome utente e password) creati durante l’iscrizione. Una volta effettuato l’accesso, l’app ci mostrerà un elenco di server disponibili. A questo punto, possiamo: Scegliere un server specifico: Seleziona un paese o una città da cui vuoi far apparire la tua connessione. Usare la connessione rapida: Molte app offrono un’opzione “Connessione rapida” o “Server più veloce” che ti connette automaticamente al server più performante in base alla tua posizione. Clicca sul pulsante “Connetti” o “Accendi” e, dopo pochi istanti, la tua connessione sarà protetta dalla VPN. Metodi alternativi di installazione (più avanzati): Configurazione manuale: Alcuni sistemi operativi (come Windows, macOS, Android e iOS) permettono di configurare manualmente una VPN senza installare l’app del provider. Questo richiede l’inserimento di dati specifici forniti dal servizio VPN, come l’indirizzo del server, il tipo di protocollo e le credenziali. Installazione su router: Si può installare la VPN direttamente sul router. Questo è un processo più tecnico che richiede un router compatibile e una conoscenza specifica delle impostazioni di rete. La scelta della VPN giusta dipende da diversi fattori, tra cui le esigenze personali, il budget a disposizione, la compatibilità con i dispositivi in uso e il livello di sicurezza desiderato. Sul mercato esistono decine di servizi VPN, ognuno con caratteristiche diverse: alcuni puntano tutto sulla velocità, altri sulla privacy, altri ancora offrono funzionalità avanzate per lo streaming o il download peer-to-peer. Le VPN gratuite sono adatte per un utilizzo molto limitato e occasionale. Questi servizi offrono tipicamente una selezione ristretta di server (spesso sovraccarichi), una quantità di dati giornaliera limitata (es. 500 MB), e non sempre garantiscono protocolli di crittografia sicuri. Inoltre, alcuni provider gratuiti monetizzano raccogliendo e vendendo i dati degli utenti a terze parti. Le VPN a pagamento, invece, offrono maggiore affidabilità, una rete di server globale, politiche no-log certificate, supporto tecnico attivo 24/7, protocolli avanzati come OpenVPN, WireGuard o IKEv2, e funzionalità come lo split tunneling o il kill switch automatico in caso di caduta della connessione VPN. La velocità è fondamentale per chi utilizza la VPN per streaming HD, videoconferenze o download di file di grandi dimensioni. Alcune VPN offrono server ottimizzati per queste attività, con larghezza di banda illimitata. In termini di sicurezza, è importante che il provider usi crittografia AES-256, supporti protocolli sicuri e offra una politica “no-log” verificata da audit esterni. Infine, il numero e la distribuzione geografica dei server sono essenziali: più sono, maggiori sono le opzioni per simulare la connessione da vari Paesi e ottenere prestazioni ottimali. Di seguito tre soluzioni di VPN a pagamento utili per lo streaming con informazioni su caratteristiche, vantaggi, svantaggi e indicazioni sui piani. 🌍 Server: 7.000+ server in 118 paesi 📱 Massimo dispositivi: 10 📍 IP dedicato: ✔ 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: IKEv2/IPsec, OpenVPN, NordLynx 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Panama 🔥 Offerte attive: SCONTO fino al 63% NordVPN mette a disposizione una delle reti più estese al mondo, con oltre 7.000 server distribuiti in circa 120 paesi. Tra questi figurano server ottimizzati per il traffico P2P, accesso diretto alla rete Tor, doppia cifratura per una protezione multilivello e IP dedicati. La VPN utilizza protocolli all’avanguardia come NordLynx (derivato da WireGuard), OpenVPN e IKEv2/IPsec, a cui si è recentemente aggiunto NordWhisper: un nuovo protocollo capace di camuffare il traffico VPN da normale traffico HTTPS, utile per superare firewall e restrizioni di rete. La sicurezza si basa su cifratura AES-256 o ChaCha20 e su una rigorosa politica no-log, confermata da audit indipendenti, con l’ulteriore garanzia offerta da server RAM-only che eliminano ogni dato a ogni riavvio. L’offerta di NordVPN si basa su diversi pacchetti di abbonamento, che variano per durata (2 anni, 1 anno, 1 mese) e per i servizi inclusi. L’obiettivo principale è fornire un pacchetto di sicurezza online completo, che va oltre la semplice VPN. Tutti i piani includono una garanzia di rimborso di 30 giorni. I tre piani principali sono: Base: Include la VPN di base, sicura e veloce. Plus: Aggiunge alla VPN di base una serie di funzionalità per la protezione avanzata: un sistema anti-malware, un blocco per pubblicità e tracker, e un password manager con mascheramento dell’email. Ultimate: È il pacchetto più completo. Include tutto ciò che è presente nel piano Plus, aggiungendo un terabyte di spazio di archiviazione cloud criptato e un’assicurazione cyber che offre una copertura fino a 5000 € per perdite dovute a truffe informatiche e furto d’identità. iani di 2 anni iani di 1 anno NordVPN piani di 1 mese 🌍 Server: 3200+ in 100 paesi 📱 Massimo dispositivi: illimitati 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS 🔐 Sicurezza: OpenVPN, IKEv2, Shadowsocks, Wireguard e L2TP 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Paesi Bassi 🔥 Offerte attive: SCONTO fino all’83% + 3 mesi gratis 🔥 Surfshark è oggi una delle VPN più apprezzate per chi cerca un equilibrio tra prestazioni, sicurezza e accessibilità economica. La sua rete si compone di oltre 3.200 server distribuiti in più di 100 paesi, progettata per garantire connessioni rapide e affidabili. Il traffico dati viene protetto attraverso una crittografia AES 256 di livello militare, supportata dai protocolli più avanzati come WireGuard, OpenVPN e IKEv2. L’interfaccia delle applicazioni è particolarmente intuitiva, rendendo l’esperienza d’uso semplice su tutte le piattaforme: Windows, macOS, Linux, Android, iOS e anche tramite estensioni browser per Chrome, Firefox ed Edge. Sul fronte delle funzionalità, Surfshark si presenta con un pacchetto ricco e pensato per utenti attenti alla sicurezza. Sono inclusi strumenti come il kill switch automatico, la modalità MultiHop che instrada il traffico attraverso due server VPN concatenati, e l’obfuscation per rendere invisibile il traffico VPN ai sistemi di ispezione più rigidi. Il Bypasser, ovvero la funzione di split tunneling, consente di escludere app o siti specifici dalla protezione VPN. Altri strumenti includono la rotazione automatica degli indirizzi IP, il GPS spoofing per simulare la posizione geografica, e CleanWeb, una protezione DNS che blocca pubblicità, tracker e malware già a livello di rete. Un grande punto di forza è l’assenza di limiti sul numero di dispositivi connessi contemporaneamente: una caratteristica rara tra le VPN premium. Surfshark offre tre diversi pacchetti, Starter, One e One+ ognuno con funzionalità aggiuntive. La differenza di prezzo tra i pacchetti riflette i servizi inclusi oltre alla semplice VPN. Ecco una tabella comparativa per conoscere cosa si ottiene con ogni piano. Il pacchetto Starter è l’opzione base di Surfshark. È ideale per chi cerca una soluzione semplice ed efficace per la privacy online senza fronzoli aggiuntivi. Cosa include: VPN completa e sicura: È la funzionalità principale: permette di nascondere l’indirizzo IP, crittografare la connessione e accedere a contenuti bloccati geograficamente. Dispositivi illimitati: Si può installare e utilizzare la VPN su un numero illimitato di dispositivi (PC, smartphone, tablet, smart TV, ecc.) con un unico abbonamento. Blocco annunci e tracker (CleanWeb): Questa funzionalità integrata blocca pubblicità, pop-up e tracker, migliorando la velocità di navigazione e la privacy. Posizioni dei server: Accesso a oltre 3200 server in 100 paesi. Politica di no-log verificata: Surfshark ha una politica rigorosa per non registrare le attività online, verificata da audit indipendenti. Per chi è consigliato Surfshark: Utenti che cercano una VPN di alta qualità a un prezzo accessibile. Persone che vogliono proteggere la propria navigazione su Wi-Fi pubblici e sbloccare contenuti geo-limitati. Chiunque voglia un livello base di protezione da annunci e tracker online. Il pacchetto One è un’evoluzione del pacchetto Starter. Oltre alla VPN, include una serie di strumenti di sicurezza aggiuntivi per una protezione più completa. Cosa include: Tutte le funzionalità del pacchetto Starter. Antivirus: Una protezione per i dispositivi contro virus, malware e tentativi di phishing. Alternative ID: Questa funzione ti permette di creare un’identità online e un’email “usa e getta” per proteggere i dati personali da spam e furti d’identità. Monitoraggio del dark web (Alert): Avvisa se le credenziali personali (come indirizzi email o password) sono trapelate in una violazione di dati. Surfshark Search: Un motore di ricerca privato che non traccia le ricerche e non mostra pubblicità. Per chi è consigliato: Utenti che vogliono una protezione completa per i loro dispositivi, non solo la VPN. Chi è preoccupato per il furto d’identità e vuole essere avvisato in caso di violazioni dei dati. Persone che cercano un’alternativa sicura ai motori di ricerca tradizionali. Il pacchetto One+ è l’offerta più completa e premium di Surfshark. Include tutte le funzionalità dei pacchetti Starter e One, con l’aggiunta del servizio Incogni per la rimozione dei dati personali. Cosa include: Tutte le funzionalità del pacchetto Starter e del pacchetto One. Rimozione dei dati personali (Incogni): Questo è il servizio distintivo del pacchetto One+. Surfshark si occupa per te di contattare i data broker (aziende che raccolgono e vendono dati personali) per richiedere la rimozione delle informazioni dai loro database. Per chi è consigliato: Utenti che desiderano la massima protezione e privacy online. Persone particolarmente attente alla propria impronta digitale e che vogliono eliminare i propri dati personali dal web. Chi cerca una soluzione all-in-one che non solo protegga attivamente ma agisca anche per rimuovere i dati già presenti online 🌍 Server: 3000 server in 105 paesi 📱 Massimo dispositivi: 8 🆓 Versione Free: Garanzia rimborso di 30 giorni 💻 Compatibilità: Windows, macOS, Android, iOS, Linux 🔐 Sicurezza: IKEv2, OpenVPN 👨💻 Assistenza 24/7: ✔ 🏢 Sede legale: Isole Vergini Britanniche 🔥 Offerte attive: SCONTO fino al 49% + 3 mesi GRATIS ExpressVPN è una delle VPN più conosciute sul mercato, e propone tre pacchetti Base, Avanzato e Pro in abbonamento della durata di 2 anni (+ 4 mesi gratis), 12 mesi (+ 3 mesi gratis) e 1 mese. L’elemento principale da considerare è che tutti i piani, indipendentemente dalla durata, includono le funzionalità essenziali di una VPN: Connessioni sicure e veloci: Utilizzo del protocollo proprietario Lightway. Crittografia avanzata: Per navigare in sicurezza, anche su Wi-Fi pubblici. Politica “zero-log”: Non viene registrata nessuna tua attività online. Accesso a server globali: In 105 paesi, per superare restrizioni geografiche e accedere a contenuti internazionali. Compatibilità estesa: Funziona su tutti i principali sistemi operativi e browser. Garanzia di rimborso: 30 giorni per provare il servizio senza rischi (per i nuovi utenti). La differenza principale tra i vari piani risiede nelle funzionalità aggiuntive che offrono e nel numero di dispositivi che si possono contemporaneamente. Questo è il piano più economico. Offre tutte le funzionalità essenziali della VPN per proteggere la privacy e accedere ai contenuti globali. È l’opzione perfetta se si ha bisogno solo delle funzioni base e si vogliono collegare fino a 10 dispositivi contemporaneamente. Questo piano è il più popolare e offre un ottimo equilibrio tra prezzo e funzionalità. Include tutto ciò che è nel piano Base più una serie di strumenti di sicurezza aggiuntivi come la protezione avanzata contro pubblicità, tracker e siti dannosi, e un gestore di password. Offre anche un piccolo bonus con una eSIM da 3 GB. Il piano Pro è l’opzione più completa e costosa, pensata per chi ha bisogno di un livello di protezione e flessibilità ancora maggiore. Oltre a tutte le funzioni dei piani precedenti, aggiunge la possibilità di collegare fino a 14 dispositivi e, soprattutto, include un IP dedicato, che può essere utile per alcune attività online specifiche. Lo sconto su Aircove (il router VPN dell’azienda) è il più alto, ed è inclusa anche una eSIM più grande da 5 GB. Per installare una VPN su un computer con sistema operativo Windows bisogna innanzitutto scegliere un provider compatibile con Windows 10 o 11. Una volta individuato il servizio è necessario accedere al sito ufficiale, effettuare la registrazione e procedere con il download del software. I principali fornitori offrono pacchetti di installazione in formato .exe, facili da gestire anche per utenti poco esperti. Dopo aver scaricato il file è sufficiente fare doppio clic per avviare il processo di installazione. Windows potrebbe mostrare una finestra di controllo dell’account utente per autorizzare le modifiche al sistema: è necessario concedere il permesso per procedere. L’installazione guidata propone in genere alcune opzioni come la scelta della cartella di destinazione o l’aggiunta di collegamenti rapidi. Una volta completata l’installazione il programma sarà disponibile nel menu Start e, nella maggior parte dei casi, si avvierà automaticamente. All’apertura dell’applicazione VPN verrà richiesto di effettuare l’accesso con le credenziali registrate in precedenza. Dopo l’autenticazione si potrà accedere all’interfaccia utente del client dove è possibile selezionare il server a cui connettersi. I server sono solitamente organizzati per Paese o per tipo di utilizzo (streaming, download, giochi online). Scegliendo il server più adatto alle proprie esigenze, sarà sufficiente cliccare su “Connetti” o su un pulsante equivalente per avviare la connessione sicura. Una volta connessi la VPN sostituirà l’indirizzo IP reale dell’utente con quello del server remoto criptando tutto il traffico in entrata e in uscita dal dispositivo. L’interfaccia del client indicherà lo stato della connessione, spesso accompagnata da un’icona nella barra delle applicazioni, visibile accanto all’orologio di sistema. Per disconnettersi, basterà riaprire il client e cliccare su “Disconnetti”. In caso di problemi durante la connessione il software include di solito strumenti di diagnostica e suggerimenti automatici. Se la VPN non riesce a stabilire la connessione è consigliabile provare a cambiare server, modificare il protocollo (passando ad esempio da OpenVPN a WireGuard), riavviare il PC o disattivare temporaneamente l’antivirus o il firewall di terze parti che potrebbero interferire. Alcuni provider offrono anche un’opzione “kill switch” per bloccare tutto il traffico di rete se la connessione VPN cade improvvisamente, garantendo così la protezione continua dei dati. Per scaricare e installare il software client di una VPN su un computer Windows è innanzitutto necessario accedere al sito ufficiale del provider VPN scelto facendo attenzione a non utilizzare link promozionali o fonti non attendibili per evitare software contraffatti o potenzialmente dannosi. Una volta giunti sulla pagina dedicata ai download è sufficiente selezionare la versione adatta al sistema operativo in uso: in questo caso, Windows. I provider più affidabili riconoscono automaticamente il sistema operativo e propongono il file corretto, generalmente con estensione .exe. Cliccando sul pulsante di download il file viene salvato nella cartella predefinita del browser, in genere “Download”. Terminato il download è necessario fare doppio clic sul file per avviare l’installazione guidata. Il sistema operativo mostrerà una finestra di dialogo per autorizzare le modifiche: l’utente deve confermare per permettere al programma di installarsi. La procedura guidata include alcuni passaggi standard come l’accettazione dei termini di servizio, la scelta della cartella di installazione e, in alcuni casi, la possibilità di selezionare componenti aggiuntivi o impostazioni avanzate. Durante l’installazione il client può scaricare file secondari o aggiornamenti necessari al corretto funzionamento. Una volta completata l’installazione l’icona dell’app comparirà nel menu Start e potrà essere avviata immediatamente. Alcuni provider configurano il client per partire automaticamente all’accensione del computer e offrono un primo avvio guidato utile per chi è alle prime armi. Da quel momento il software sarà pronto per essere utilizzato: basterà accedere con le proprie credenziali per connettersi in modo sicuro a un server VPN e proteggere il proprio traffico online. Una volta installato il software client della VPN sul tuo computer Windows il passo successivo consiste nella configurazione iniziale e nella connessione a un server. All’apertura dell’applicazione ti verrà generalmente richiesto di accedere utilizzando le credenziali del tuo account, ovvero l’email e la password create al momento della registrazione sul sito del provider VPN. Dopo l’autenticazione l’interfaccia principale del client si presenterà con una mappa interattiva o con un elenco di server suddivisi per Paese, regione o utilizzo consigliato. A questo punto si potrà scegliere il server a cui connettersi in base alle esigenze specifiche. Se si desidera aumentare la velocità di navigazione o minimizzare la latenza, conviene selezionare un server geograficamente vicino alla propria posizione attuale. Se invece si intende accedere a contenuti geo-bloccati in un altro Paese, come un catalogo di Netflix estero o un sito di news internazionale, si dovrà selezionare un server situato in quel Paese. Una volta selezionato il server è sufficiente cliccare sul pulsante “Connetti” o “Connect” presente nell’interfaccia del client. Il software stabilirà automaticamente il tunnel crittografato e, in pochi secondi, mostrerà lo stato della connessione attiva. Alcuni client forniscono anche informazioni aggiuntive, come il nuovo indirizzo IP assegnato, il protocollo in uso (WireGuard, OpenVPN, IKEv2, ecc.), la durata della sessione e la velocità di trasferimento dati in tempo reale. Durante l’utilizzo, la connessione VPN resta attiva in background e protegge tutte le attività di rete. Si può cambiare server in qualsiasi momento semplicemente interrompendo la connessione attuale e selezionandone uno nuovo. Al termine della sessione, basterà cliccare su “Disconnetti” per tornare alla connessione diretta. In alcuni software, si possono anche salvare i server preferiti, impostare la connessione automatica all’avvio del sistema o attivare funzionalità avanzate come il kill switch e lo split tunneling, che permettono di instradare solo parte del traffico attraverso la VPN. Quando si utilizza una VPN su Windows può capitare che la connessione non si stabilisca correttamente o che risulti instabile. Risolvere questi problemi comuni richiede un approccio graduale a partire dalla verifica degli elementi di base. Innanzitutto, è importante assicurarsi che la connessione a Internet funzioni regolarmente anche senza VPN: una rete debole, instabile o assente impedisce alla VPN di operare correttamente. Se la connessione Internet è attiva, il problema potrebbe riguardare il server selezionato. Alcuni server VPN possono essere temporaneamente offline o congestionati, specialmente durante le ore di punta, ed è quindi consigliabile provare a connettersi a un server diverso, magari più vicino geograficamente. Un altro aspetto da controllare è il protocollo VPN in uso. Molti client permettono di scegliere tra protocolli differenti come WireGuard, OpenVPN (nelle varianti UDP o TCP), IKEv2 o altri ancora. Se la connessione fallisce con un protocollo, modificarlo dalle impostazioni del client può risolvere il problema. Ad esempio, passare da UDP a TCP migliora la stabilità in reti soggette a filtraggio aggressivo. In alcuni contesti, soprattutto in reti aziendali o universitarie, l’amministratore di rete potrebbe bloccare alcuni protocolli o porte usate dalla VPN. In questi casi, l’attivazione della modalità “offuscata” (obfuscated mode) offerta da alcuni provider aiuta a bypassare i filtri e a ristabilire la connessione. Anche firewall e antivirus possono interferire con il corretto funzionamento della VPN. Se il client VPN non riesce a stabilire la connessione, potrebbe essere utile disattivare temporaneamente queste protezioni o aggiungere un’eccezione per il software VPN. Allo stesso modo, eventuali estensioni del browser o software di sicurezza di terze parti possono bloccare il traffico VPN: rimuoverli o disattivarli momentaneamente permette di isolare il problema. Un’altra causa possibile è l’obsolescenza del client stesso. È fondamentale assicurarsi di avere sempre installata la versione più recente del software VPN, poiché gli aggiornamenti risolvono spesso problemi di compatibilità e migliorano la stabilità della connessione. In situazioni più complesse, come disconnessioni continue o velocità estremamente basse, si può tentare un riavvio completo del sistema e del modem/router. Inoltre, controllare se il proprio provider Internet applica politiche di throttling o blocco delle VPN può essere utile: in tali casi, conviene contattare l’assistenza tecnica del provider VPN, che potrà consigliare impostazioni alternative o fornire server dedicati con protezioni anti-blocco. Installare una VPN su macOS è un processo relativamente semplice e alla portata di qualunque utente, anche senza particolari competenze tecniche. Il primo passaggio consiste nello scegliere un provider VPN affidabile, registrarsi al servizio e scaricare il client dedicato per macOS direttamente dal sito ufficiale. È fondamentale evitare fonti non ufficiali o versioni piratate del software, per non compromettere la sicurezza del proprio dispositivo. Una volta scaricato il file in formato .dmg, è sufficiente fare doppio clic su di esso per aprire l’immagine disco. All’interno si troverà l’icona del client VPN che dovrà essere trascinata nella cartella “Applicazioni”, come indicato dal sistema operativo. Questo passaggio installa l’applicazione nella posizione corretta e la rende accessibile tramite Launchpad o Spotlight. Dopo aver completato l’installazione, si può avviare l’app VPN direttamente da Applicazioni. Al primo avvio, macOS richiederà di autorizzare l’esecuzione del software, poiché proviene da uno sviluppatore esterno: sarà necessario confermare l’operazione, eventualmente inserendo la password dell’amministratore del sistema. Una volta aperta, l’applicazione richiederà le credenziali di accesso al servizio VPN, cioè l’email e la password create in fase di registrazione. A login effettuato, verrà mostrata l’interfaccia del client, solitamente dotata di una mappa o di un elenco di server VPN organizzati per area geografica o per tipo di utilizzo, come streaming, sicurezza o download. La connessione a un server VPN avviene con un semplice clic su “Connect” o sul tasto equivalente. Il software avvierà il collegamento e, in pochi secondi, stabilirà un tunnel crittografato che proteggerà tutto il traffico di rete in uscita e in entrata dal Mac. Durante la connessione, comparirà una notifica di sistema che segnala l’attivazione della VPN, visibile anche nella barra del menu in alto, da cui sarà possibile gestire la connessione in modo rapido. Alcune applicazioni richiedono di installare un profilo VPN o un’estensione di rete per completare la configurazione: in questo caso, macOS mostrerà un avviso e sarà sufficiente autorizzare l’installazione. Molti client VPN per Mac offrono funzionalità avanzate, come il kill switch, che disconnette automaticamente Internet in caso di caduta della VPN, o lo split tunneling, che consente di scegliere quali applicazioni devono utilizzare la connessione protetta. Queste opzioni sono accessibili dal menu impostazioni del client, spesso accompagnate da strumenti di diagnostica o da suggerimenti automatici in caso di problemi di connessione. Al termine dell’utilizzo, è possibile disconnettersi direttamente dal client o dalla barra dei menu, e la connessione tornerà immediatamente a essere quella del provider Internet standard. Installare una VPN su un dispositivo Android è un’operazione diretta e accessibile che può essere completata in pochi minuti anche da utenti senza esperienza tecnica. Il primo passo consiste nello scegliere un provider VPN affidabile, preferibilmente tra quelli che offrono un’app ufficiale compatibile con le ultime versioni di Android. Una volta scelto il servizio, è necessario aprire il Google Play Store, digitare il nome del provider VPN nella barra di ricerca e verificare che l’applicazione individuata sia quella ufficiale, riconoscibile dal nome del produttore e dalle recensioni degli utenti. Dopo aver identificato l’app corretta, si può procedere con il download e l’installazione toccando il pulsante “Installa”. Il sistema operativo avvierà automaticamente il processo, che richiede pochi istanti. Al termine dell’installazione, l’icona dell’app comparirà nel drawer delle applicazioni e sarà possibile avviarla con un semplice tocco. Al primo avvio, l’app VPN richiederà di accedere con le credenziali dell’account creato in fase di registrazione sul sito del provider. Una volta effettuato il login, verrà presentata l’interfaccia principale, che può variare da provider a provider, ma solitamente include un tasto centrale per connettersi rapidamente e una lista di server disponibili organizzata per Paese o per tipo di utilizzo. Toccando il tasto “Connetti” o selezionando un server specifico dall’elenco, l’app richiederà l’autorizzazione a creare una connessione VPN. Android mostrerà un avviso di sicurezza in cui l’utente dovrà acconsentire esplicitamente affinché l’app possa controllare il traffico di rete. Una volta autorizzata, la connessione verrà stabilita e un’icona a forma di chiave comparirà nella barra superiore del telefono, indicando che tutto il traffico internet sta passando attraverso il tunnel crittografato della VPN. Da questo momento ogni attività online sul dispositivo sarà protetta, comprese la navigazione web, l’uso di app di messaggistica, le transazioni bancarie o gli accessi a reti aziendali. L’app offre spesso funzionalità aggiuntive come la connessione automatica su reti Wi-Fi pubbliche, la selezione intelligente del server più veloce o opzioni per escludere alcune app dalla connessione VPN tramite lo split tunneling. La disconnessione può essere effettuata direttamente dall’app o abbassando la tendina delle notifiche, dove sarà presente il controllo rapido della VPN. Installare una VPN su un dispositivo iOS, come iPhone o iPad, è un processo lineare e ben integrato con l’ecosistema Apple. Il primo passo consiste nel selezionare un servizio VPN affidabile e compatibile con iOS, quindi accedere all’App Store direttamente dal dispositivo. All’interno dello store digitale, è necessario digitare il nome del provider VPN scelto nella barra di ricerca e selezionare l’app ufficiale, facendo attenzione a controllare il nome dello sviluppatore e la valutazione dell’app per garantirsi di scaricare la versione autentica. Una volta individuata l’applicazione corretta, si può procedere al download toccando il pulsante “Ottieni” o l’icona della nuvola con la freccia, se si tratta di un’app già scaricata in passato. Il sistema potrebbe richiedere l’autenticazione tramite Face ID, Touch ID o password dell’Apple ID. Completato il download, l’app apparirà sulla schermata principale e potrà essere aperta toccando l’icona corrispondente. All’apertura dell’app, verrà chiesto di effettuare il login con le credenziali del proprio account VPN. In alternativa, se non si dispone ancora di un account, molti provider permettono di crearne uno direttamente all’interno dell’app, attraverso una procedura guidata che include la registrazione tramite email e la scelta di un piano tariffario, spesso con periodo di prova gratuito. Una volta effettuato l’accesso, verrà mostrata l’interfaccia principale, solitamente molto intuitiva, con un pulsante centrale per avviare la connessione e un elenco di server da cui scegliere. Quando si tenta di connettersi per la prima volta, l’app richiederà di installare un profilo VPN sul dispositivo. iOS mostrerà una finestra di sistema che chiederà l’autorizzazione per configurare le impostazioni VPN, necessarie affinché il traffico internet possa essere instradato attraverso i server del provider. Autorizzando la richiesta, il profilo verrà aggiunto automaticamente e il sistema sarà pronto per gestire le connessioni VPN in modo sicuro e trasparente. Dopo aver selezionato un server e avviato la connessione, iOS mostrerà un’icona “VPN” nella barra di stato, segnalando che la connessione protetta è attiva. Da questo momento, tutte le comunicazioni in entrata e in uscita saranno criptate e passeranno attraverso il tunnel sicuro stabilito dalla VPN. In qualsiasi momento sarà possibile disconnettersi dall’interno dell’app oppure tramite le impostazioni generali del dispositivo, dove è presente una voce dedicata alla gestione delle connessioni VPN. Installare una VPN direttamente sul router rappresenta una soluzione centralizzata e molto efficace per proteggere tutti i dispositivi connessi alla rete domestica o aziendale, senza la necessità di configurare ogni singolo device. Questa opzione è particolarmente utile in ambienti in cui si utilizzano dispositivi che non supportano nativamente l’installazione di app VPN, come smart TV, console di gioco, dispositivi IoT o decoder. Il principio di base è che, configurando la VPN a livello di router, l’intera rete locale viene instradata attraverso il tunnel crittografato, rendendo anonimo e sicuro il traffico proveniente da ogni dispositivo collegato. Per procedere con l’installazione, è fondamentale verificare innanzitutto che il proprio router supporti nativamente le connessioni VPN. Alcuni modelli recenti, in particolare quelli marchiati Asus, Netgear o Linksys, includono già un’interfaccia grafica che permette la configurazione di protocolli come OpenVPN o WireGuard. In alternativa, è possibile installare firmware personalizzati come DD-WRT, Tomato o OpenWRT, che aggiungono funzionalità avanzate, tra cui proprio il supporto VPN. L’installazione di questi firmware, però, richiede maggiore dimestichezza tecnica e va eseguita con attenzione, poiché eventuali errori potrebbero compromettere il funzionamento del router. Una volta verificata la compatibilità, si può accedere al pannello di amministrazione del router digitando il relativo indirizzo IP nel browser, solitamente 192.168.1.1 o 192.168.0.1, ed effettuando il login con le credenziali di amministratore. All’interno del pannello, si accede alla sezione dedicata alla VPN, dove è possibile caricare il file di configurazione fornito dal proprio provider. Questo file contiene tutti i parametri necessari per stabilire la connessione, compresi l’indirizzo del server, le chiavi di autenticazione e le opzioni crittografiche. Dopo aver completato la configurazione e salvato le impostazioni, sarà sufficiente attivare la connessione VPN dal pannello del router. Una volta stabilita, tutti i dispositivi collegati, sia via Wi-Fi che tramite cavo Ethernet, inizieranno a navigare sotto la protezione della VPN, senza alcuna configurazione aggiuntiva da parte degli utenti. Il vantaggio principale di questo approccio è l’automazione: la VPN resterà attiva anche quando il router viene riavviato o quando nuovi dispositivi si connettono alla rete, garantendo una protezione continua. Questa soluzione è ideale non solo per chi desidera massimizzare la sicurezza della rete, ma anche per utenti che vogliono accedere a contenuti geo-limitati su dispositivi che non supportano app VPN, come alcune smart TV. Va tuttavia considerato che instradare tutto il traffico attraverso il router può ridurre leggermente la velocità di connessione, specialmente se il router ha un processore poco potente. Per questo motivo, è consigliabile utilizzare router di fascia medio-alta o modelli progettati appositamente per il traffico VPN. Installare una VPN direttamente sul router offre numerosi vantaggi, soprattutto in contesti in cui si desidera proteggere in modo continuo e centralizzato l’intera rete domestica o aziendale. Il principale beneficio consiste nel fatto che tutti i dispositivi connessi al router, siano essi computer, smartphone, tablet, console di gioco, smart TV o dispositivi IoT, vengono automaticamente instradati attraverso la connessione VPN, senza dover installare o configurare manualmente applicazioni su ciascuno di essi. Questo approccio semplifica enormemente la gestione della sicurezza, soprattutto in ambienti con numerosi device o in famiglie in cui non tutti gli utenti hanno familiarità con la tecnologia. Un ulteriore vantaggio è la protezione automatica e costante della connessione. A differenza delle VPN installate su singoli dispositivi, che richiedono l’attivazione manuale o rischiano di essere disattivate per errore, una VPN installata sul router resta attiva finché il dispositivo è acceso e connesso. Questo garantisce un livello di sicurezza elevato e continuo, utile in particolare per chi desidera una protezione costante da tracciamenti, attacchi informatici o censura geografica. Dal punto di vista della privacy, questa configurazione consente di mantenere nascosto l’indirizzo IP reale di ogni dispositivo della rete, presentando al mondo esterno un unico indirizzo IP, ovvero quello assegnato dal server VPN. Questo rafforza l’anonimato e rende più difficile il tracciamento delle attività individuali online. Inoltre, configurare la VPN sul router permette anche di accedere a contenuti geo-limitati da dispositivi che normalmente non supportano l’uso di VPN, come ad esempio molte smart TV o dispositivi per lo streaming. Infine, l’installazione centralizzata riduce anche il carico operativo e i consumi di risorse sui singoli dispositivi, poiché è il router a gestire il processo di cifratura e instradamento del traffico. Questo può tradursi in un miglioramento delle prestazioni su device meno potenti e, al tempo stesso, semplifica enormemente la manutenzione, poiché eventuali modifiche o aggiornamenti della configurazione VPN si effettuano una sola volta, direttamente sul router, senza dover ripetere l’operazione su ogni singolo terminale. Durante l’installazione di una VPN, soprattutto se si è alle prime armi, possono emergere alcuni problemi comuni che rallentano o impediscono la configurazione corretta. Uno dei più frequenti è rappresentato dall’impossibilità di completare la connessione al server VPN, situazione che si verifica spesso quando il software client non riesce a stabilire un tunnel sicuro con l’infrastruttura del provider. In questo caso, è importante innanzitutto verificare che la propria connessione Internet sia attiva e stabile, poiché una rete lenta o intermittente può bloccare la fase di handshake crittografico necessaria per iniziare la comunicazione. Se la connessione di base funziona, il problema potrebbe dipendere dal server selezionato, che potrebbe essere temporaneamente offline o congestionato. Cambiare server manualmente, scegliendone uno meno trafficato o più vicino geograficamente, risolve nella maggior parte dei casi. Un’altra causa frequente di malfunzionamento riguarda il blocco da parte di software di sicurezza locali, come antivirus, firewall o antimalware, che a volte identificano il traffico VPN come potenzialmente sospetto. In questi casi, è utile disattivare temporaneamente il firewall o aggiungere un’eccezione specifica per il client VPN nelle impostazioni del programma di protezione. Alcuni provider VPN offrono anche una modalità “stealth” o “camouflage”, che rende il traffico criptato meno riconoscibile dai filtri automatici e ne facilita il passaggio su reti restrittive, come quelle scolastiche, aziendali o pubbliche. In altri casi, l’ostacolo può essere legato al protocollo scelto per la connessione. I client VPN moderni supportano solitamente più protocolli, come OpenVPN, WireGuard, IKEv2 o L2TP/IPSec, ognuno dei quali ha caratteristiche tecniche diverse. Alcuni protocolli, per esempio OpenVPN su UDP, possono essere bloccati da determinati provider Internet o da router con impostazioni conservative. Cambiare protocollo dalle impostazioni avanzate dell’app, passando da UDP a TCP o scegliendo WireGuard, spesso sblocca la situazione e consente il corretto funzionamento della VPN. Anche l’obsolescenza del software può generare errori: un client VPN non aggiornato potrebbe essere incompatibile con gli ultimi aggiornamenti del sistema operativo o con i server del provider. In questi casi, è sufficiente scaricare l’ultima versione dell’app dal sito ufficiale o dallo store dedicato e reinstallarla. Allo stesso modo, un sistema operativo non aggiornato può causare problemi di compatibilità con i certificati di sicurezza o con i driver di rete, ed è quindi consigliabile mantenere il dispositivo sempre aggiornato. Infine, in fase di installazione manuale su router o tramite configurazioni personalizzate è possibile incorrere in errori nella compilazione dei parametri come indirizzi server errati, porte bloccate o certificati incompleti. In queste situazioni, è utile consultare la documentazione ufficiale del provider VPN, confrontare le impostazioni con un tutorial verificato o contattare il supporto tecnico. Quando una VPN non riesce a connettersi, la prima cosa da fare è individuare se il problema dipende dalla rete locale, dal dispositivo, dal software VPN o dal provider stesso. Inizia sempre verificando che la connessione Internet funzioni correttamente senza VPN: se anche la navigazione normale è assente o instabile, la causa non è il servizio VPN ma un’interruzione o un problema tecnico del tuo operatore. Se invece la rete funziona e la VPN continua a non connettersi, allora è utile cambiare server, selezionandone uno alternativo tra quelli offerti dal provider. Talvolta i server possono risultare sovraccarichi o temporaneamente offline per manutenzione. Se il cambio di server non risolve, entra nelle impostazioni del client VPN e prova a modificare il protocollo di connessione. Molti provider consentono di passare da WireGuard a OpenVPN o a IKEv2, e questa semplice variazione spesso consente di superare eventuali blocchi imposti da reti aziendali, scolastiche o da provider che limitano specifici tipi di traffico. Se il problema persiste, valuta la possibilità che un antivirus o firewall installato sul tuo dispositivo stia bloccando la connessione. In quel caso, potresti disattivare temporaneamente questi software o creare un’eccezione per il client VPN nelle loro impostazioni. In alcuni contesti particolarmente restrittivi, come reti Wi-Fi pubbliche in hotel o aeroporti, oppure reti universitarie, può essere necessario attivare la modalità offuscata (spesso chiamata “obfuscated mode” o “stealth mode”) disponibile in molti client VPN avanzati. Questa funzione camuffa il traffico VPN per farlo sembrare normale traffico HTTPS e superare eventuali sistemi di filtraggio. Se stai usando la VPN su un router o tramite configurazione manuale, assicurati che i file di configurazione siano corretti, aggiornati e compatibili con il server scelto. Controlla anche che le porte richieste siano aperte nel router e che non ci siano restrizioni impostate dal firewall locale. Come ulteriore verifica, prova a connetterti da un altro dispositivo, oppure utilizza una connessione mobile per escludere che il problema sia legato alla tua rete principale. Infine, se nessuna di queste soluzioni funziona, consulta la documentazione ufficiale del tuo provider VPN o contatta il servizio clienti: molti offrono assistenza 24 ore su 24 e possono analizzare il log della connessione per identificare rapidamente l’origine del malfunzionamento. Quando la velocità della VPN risulta lenta è importante considerare diversi fattori che possono influenzare le prestazioni e intervenire in modo mirato per migliorarle. Uno dei primi elementi da esaminare è la distanza geografica dal server scelto. Connettersi a un server molto lontano, ad esempio in un altro continente, comporta un maggior numero di nodi di rete attraversati e quindi una latenza più alta. Per ottimizzare la velocità, è consigliabile selezionare un server geograficamente vicino o lasciar decidere automaticamente al client quale sia il nodo più performante in quel momento, se il provider offre questa funzione. Anche il tipo di protocollo utilizzato incide notevolmente. Alcuni protocolli, come WireGuard, sono progettati per offrire un’elevata velocità con un consumo minimo di risorse, mentre altri, come OpenVPN in modalità TCP, sono più sicuri ma meno efficienti sul piano della velocità. Se il client VPN lo consente, è utile sperimentare con protocolli diversi per trovare il miglior equilibrio tra sicurezza e prestazioni, scegliendo, ad esempio, WireGuard per streaming o download, e IKEv2 per la mobilità su rete mobile. Un altro elemento che può rallentare la connessione è la congestione dei server. In determinate fasce orarie, molti utenti possono connettersi contemporaneamente agli stessi nodi, provocando un sovraccarico. In questi casi, cambiare manualmente server, anche restando nello stesso Paese, può portare a un miglioramento significativo. Va poi considerata la qualità della propria rete locale. Una connessione Wi-Fi instabile, interferenze con altri dispositivi o una larghezza di banda ridotta possono impattare negativamente sull’esperienza VPN. Passare temporaneamente a una connessione via cavo Ethernet o posizionarsi più vicino al router può aiutare a stabilizzare la velocità. Anche il carico di lavoro del dispositivo gioca un ruolo: se si stanno eseguendo contemporaneamente più applicazioni che consumano banda, come upload automatici sul cloud o videochiamate, la VPN avrà meno risorse a disposizione. Chiudere i programmi non essenziali o pianificare attività pesanti al di fuori delle sessioni VPN permette di mantenere le prestazioni elevate. Alcuni provider consentono inoltre di configurare uno split tunneling, ossia la possibilità di instradare solo una parte del traffico attraverso la VPN: utilizzare questa funzione per limitare il traffico cifrato solo a specifiche app può ridurre notevolmente il carico. Infine, è utile verificare che il software VPN sia aggiornato all’ultima versione disponibile. Gli aggiornamenti spesso includono ottimizzazioni del motore di connessione e correzioni di bug che potrebbero compromettere la velocità. Se dopo aver seguito tutti questi passaggi la connessione continua a essere insoddisfacente, è opportuno contattare il servizio di assistenza del provider VPN per valutare eventuali limiti legati al piano sottoscritto o alla rete del fornitore.
cybersecurity360.itAug 5, 2025extracted
Router e dispositivi di rete non aggiornati: il cimitero digitale dove fioriscono gli attacchi
Router e dispositivi di rete non aggiornati: il cimitero digitale dove fioriscono gli attacchi Dai firmware marci ai Comuni in balia del primo script kiddie: il rischio derivante dai router e dai dispositivi di rete non aggiornati e “abbandonati” negli uffici delle aziende viene spesso sottovalutato. Un problema che non è solo tecnico, ma anche e soprattutto culturale. Ecco come affrontarlo e risolverlo C’è un gigantesco, sporco segreto che nessuno vuole ammettere. Un segreto fatto di router impolverati, firewall lasciati in modalità di default, interfacce di amministrazione raggiungibili da qualsiasi angolo del mondo. Una montagna di apparati installati anni fa, configurati alla buona, magari “per fare prima”, e poi lasciati lì. Come se, una volta accesi, dovessero cavarsela da soli. E invece non si cavano un bel niente. Restano lì, a marcire, esposti e vulnerabili, mentre il mondo intorno cambia, mentre gli attaccanti evolvono, mentre le tecnologie si aggiornano. Loro no. Loro restano fermi. Come trappole rovesciate: non catturano nulla, ma si fanno catturare. Indice degli argomenti Se pensate che per trovare questi dispositivi servano chissà quali strumenti, siete fuori strada. Non servono APT (Advanced Persistent Threat), non servono accessi privilegiati, non serve nemmeno un grande talento tecnico. Basta aprire Shodan, digitare due query e il gioco è fatto. I risultati sono imbarazzanti. Router MikroTik con firmware vecchi di sette anni. Zyxel con interfaccia di login in chiaro. Ubiquiti con porte di gestione pubbliche. TP-Link che espongono il pannello admin senza HTTPS. DrayTek, D-Link, Netgear e Cisco RV che rispondono come se fossimo ancora nel 2010. In mezzo a tutto questo, anche dispositivi industriali, firewall entry-level, access point installati in scuole, biblioteche, sedi comunali. Tutto visibile. Tutto attaccabile. Tutto schedato. Questa montagna di dispositivi abbandonati non è solo il risultato di scelte sbagliate. È il prodotto di una cultura IT tossica, pigra, approssimativa, dove l’unico parametro di valutazione è “funziona o no?”. Se accende le lucine e fa navigare, va bene. Punto. Non c’è patch management, non c’è monitoraggio, non c’è log centralizzato. Nessuno controlla, nessuno verifica, nessuno aggiorna. Perché tanto non è compito di nessuno. E il risultato è che intere reti aziendali o pubbliche poggiano su dispositivi dimenticati, insicuri, talvolta mai più toccati dal giorno dell’installazione. Paradossalmente, i router sono diventati i punti più deboli e più duraturi delle infrastrutture digitali. Resistono più degli switch, più dei server, più delle persone che li hanno installati. Quando parli con chi gestisce queste reti, ti senti rispondere sempre allo stesso modo. “Ma chi vuoi che ci attacchi?” “Non abbiamo dati sensibili” “Non siamo un obiettivo interessante” Eppure, è proprio quel tipo di target che oggi fa gola. Non tanto per il valore in sé, quanto per la facilità di compromissione. Chi attacca cerca ciò che è debole, mal configurato, non monitorato. E quei dispositivi, te lo garantisco, sono il sogno di qualsiasi attaccante: persistenti, trascurati, connessi a tutto il resto della rete. I criminali informatici lo sanno. Entrano da lì, si muovono in silenzio, mappano la rete interna, scaricano credenziali, stabiliscono ponti per attacchi futuri. Oppure li usano come base per colpire altri obiettivi, facendoti diventare parte di una catena di attacco senza nemmeno saperlo. Il dramma è che questi attacchi non lasciano segni visibili. Non fanno rumore, non bloccano la rete, non mostrano schermate nere. Semplicemente, qualcosa si insinua e resta lì. Aspetta il momento giusto. E quando succede il disastro – perché succede, sempre – la frase che si sente dire è: “Non capiamo come sia entrato”. È entrato dalla porta di servizio. Quella che hai lasciato aperta dieci anni fa. C’è chi prova a giustificare tutto con la mancanza di fondi. È una scusa comoda. “Siamo un piccolo Comune, non possiamo permetterci un SOC”. Ma qui non stiamo parlando di tecnologie d’élite. Stiamo parlando di tenere aggiornato un router. Di non esporre un’interfaccia web all’esterno. Di cambiare la password di default. È come dire che non hai i soldi per chiudere la porta a chiave. Non è questione di budget. È questione di responsabilità. Forse è arrivato il momento di fare nomi. Non per dare in pasto le aziende ai leoni, ma per creare un po’ di sano imbarazzo. Perché a volte solo quello funziona. Quando ti accorgi che il tuo IP è finito in una lista pubblica di dispositivi esposti, forse qualcosa ti si accende nella testa. Non è il massimo dell’etica, forse. Ma siamo arrivati al punto che il rischio di non fare nulla è peggiore di quello di disturbare qualcuno. Perché quando non dai fastidio a nessuno, nessuno si muove. Quello che serve è un cambio di passo. Non possiamo più convivere con questi zombie digitali. Serve una bonifica nazionale, serve cultura, serve formazione, serve obbligo di baseline di sicurezza anche per chi gestisce reti da quattro soldi. Io sono pronto a contribuire. Posso avviare un monitoraggio OSINT su scala nazionale, mappare per categoria, zona, vendor, portare numeri veri. Posso raccogliere dati da Shodan, aggregarli, renderli leggibili. E magari cominciare da lì a costruire la prima vera mappatura dell’abbandono digitale. Perché non si può costruire sicurezza sul nulla. E oggi, sotto a tanti progetti ambiziosi, c’è solo una montagna di dispositivi dimenticati. Se pensi che il tuo router sia troppo piccolo per essere un obiettivo, sei già un obiettivo. Se pensi che tanto non succederà nulla, stai già succedendo. E se pensi che basti aspettare, ti sbagli: gli attaccanti non aspettano mai. La sveglia è suonata. Sta a noi decidere se alzarci o restare nel letto a farci bucare.
cybersecurity360.itJul 29, 2025extracted