North Korean Hackers Hide ‘Ted’ Backdoor Inside Trojanized HAProxy to Spy on South Korean Firms
Rapid7 researchers have uncovered a DPRK-linked Linux intrusion toolkit — built around a modified HAProxy binary dubbed Ted and a companion remote access tool called CurlRAT — that...
Over 14,000 Dahua Cameras Compromised With Backdoors That Survive Factory Resets
Researchers at Hunt.io say a 35-day campaign compromised more than 14,000 internet-connected Dahua cameras, planting hidden administrator accounts and abusing cloud recovery codes that persist even through password...
BlackTech’s Linux Backdoor Blends In by Routing Through Your Own Proxy Server
China-linked espionage group BlackTech has been spotted deploying a stealthy Linux variant of the BlueShell backdoor against Japanese organizations, tunneling command-and-control traffic through the victim's own proxy infrastructure....
PhantomEnigma: How a Malware Crew Turned Brazilian Government Sites Into Trusted Malware Hubs
A campaign tracked as PhantomEnigma has compromised more than 20 official Brazilian government websites, using them to host and deliver malware that passes email authentication checks and slips...
Tenda Router Backdoor (CVE-2026-11405) Lets Attackers Skip Login and Seize Full Admin Control
A hardcoded authentication backdoor in Tenda FH1201, W15E, AC10, AC5, and AC6 routers (CVE-2026-11405) lets attackers log in as admin with any username. The undocumented flaw sits in...
macOS.Gaslight: North Korea-Linked Rust Backdoor Exfiltrates Data via Telegram and Poisons AI Analysis Tools
A Rust-written macOS backdoor attributed to North Korean threat actors steals browser credentials, keychain files, and terminal history, exfiltrating everything via Telegram. The malware also embeds 38 prompt...
WordPress Sites Turned Into Spy Networks: Malware Hides C2 Commands in Steam Profile Comments Using Unicode Steganography
A sophisticated malware campaign has compromised approximately 1,900 WordPress sites using Steam Community profile pages as a covert C2 channel. The malware employs Unicode steganography to hide commands...
Malicious npm Package forge-jsxy Pushes 22 Versions in 22 Days to Steal Crypto Wallets and Deploy Persistent Backdoor
The npm package forge-jsxy quietly stole cryptocurrency wallet keys, browser credentials, and developer data across Windows, macOS, and Linux — publishing 22 malicious versions in 22 days, and...