Tag: router
-
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/
-
Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing
Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required. ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff. Since at least June 2026, threat actors have…
-
Next.js Patches Nine Security Flaws Enabling SSRF, Middleware Bypass, DoS, and Internal Endpoint Disclosure
The Next.js team has released security updates that address nine vulnerabilities affecting the App Router, Server Actions, rewrites, image optimization, caching, and middleware deployments. Organizations are urged to upgrade to Next.js versions 15.5.21 or 16.2.11 immediately, as these updates fix high- and moderate-severity flaws that could lead to server-side request forgery (SSRF), authentication bypass, denial…
-
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM) attack. This raises substantial concerns for both enterprise and home network security. The flaw, identified as CVE-2026-13385, impacts multiple branches of ASUS router firmware, including the widely used versions 3.0.0.4_386, 3.0.0.4_388,…
-
NSA Warns Russian State-Sponsored Hackers Exploiting Vulnerable Routers to Target Critical Infrastructure
Tags: access, advisory, cyber, cybersecurity, exploit, hacker, infrastructure, international, network, router, russia, threat, vulnerabilityThe U.S. National Security Agency (NSA) and international cybersecurity partners have issued a warning that Russian state-sponsored threat actors are actively exploiting vulnerable and poorly configured network routers to access organizations in critical infrastructure sectors. In a joint Cybersecurity Advisory (CSA) titled >>Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,<< released on July 13,…
-
The US government warns that Russia state hackers are coming after your router
With residential proxies all the rage, CISA urges router users to be vigilant. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router/
-
U.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cisco, cve, cybersecurity, exploit, flaw, infrastructure, kev, router, service, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabilities (KEV) catalog. Cisco IOS 12.4 running on Cisco 871 Integrated Services Routers contains multiple CSRF flaws in…
-
UK and EU impose sanctions on hacking groups linked to Kremlin
Tags: attack, credentials, group, hacker, hacking, infrastructure, intelligence, router, russia, theft, vulnerabilityHackers linked to Russian intelligence behind attack on Poland’s energy infrastructure, theft of credentials and using vulnerable routers to attack critical national infrastructure First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645662/UK-and-EU-impose-sanctions-on-hacking-groups-linked-to-Kremlin
-
Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory Warns
Cybersecurity agencies from 12 countries have warned that Russian state-backed hackers are actively targeting vulnerable routers using weak SNMP credentials First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russian-state-hackers-vulnerable/
-
FSB Center 16 Targets Routers Across Critical Sectors
At a glance Actor / group Russian FSB Center 16 (aka Berserk Bear, Dragonfly, Static Tundra) Activity SNMP First seen on securityonline.info Jump to article: securityonline.info/fsb-center-16-router-targeting/
-
US and allies warn of Russian critical infrastructure attacks
Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-and-allies-share-defense-tips-against-russian-hackers-targeting-critical-infrastructure/
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181
-
Hidden Backdoor in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-in-tenda-router-firmware-a-32181
-
Hidden backdoor in Tenda router firmware grants admin access
A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device’s web management panel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/
-
Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available
CERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-11405. The flaw gives anyone who knows the right password full administrative access to the device’s web…
-
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices’ web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday.”An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process First seen on thehackernews.com…
-
FBI Disrupts Widely Used NetNut Residential Proxy Service
2 Million Home Devices, Including Routers and Smart TVs, Tied to NetNut Botnet. The FBI and private-sector partners have disrupted NetNut, one of the world’s biggest and most popular residential proxy networks. Google researchers said it comprised 2 million secretly hijacked home devices and was often used to route and disguise cybercrime and cyberespionage activity.…
-
FCC Router Ban Risks Freezing Home Security Updates
Verizon Waiver Is Latest Carve-Out in a Rule Experts Say Undercuts Router Security. The FCC granted Verizon a one-year waiver from its foreign-router ban, the latest carve-out in a rule that critics say would strip millions of home routers of the security patches that keep them safe once temporary exemptions lapse. First seen on govinfosecurity.com…
-
RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow
RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, cameras, Android set-top boxes, and exposed servers, then uses them to flood targets with junk…
-
New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits
A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and enterprise servers through brute-force credential attacks and remote code execution vulnerabilities. RustDuck employs a multi-pronged infection strategy combining weak password attacks against Telnet and SSH services with exploitation of known RCE…
-
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.Researchers at QiAnXin’s XLab have tracked it since February 2026, and say the real story is not how big it is today, but…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 103
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers A VBScript campaign distributed through WhatsApp deploying RMM software Lost in relocation: analysis of a new loader distributing CASTLESTEALER…
-
Netzwerksicherheit und Quantentechnologie – Quantensicherheit im Router: QKD ohne Zusatzhardware
Tags: routerFirst seen on security-insider.de Jump to article: www.security-insider.de/quantensicherheit-im-router-qkd-ohne-zusatzhardware-a-f9c9b9627a937cd168767ff8fcacdc3a/
-
Botnetz AryStinger infiziert tausende Router weltweit
Das neu entdeckte Botnetz AryStinger hat weltweit über 4000 veraltete Router infiziert. Die Malware nutzt die Geräte als Proxys für Cyberangriffe. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/tausende-router-botnetz-arystinger
-
Botnetz AryStinger infiziert tausende Router weltweit
Das neu entdeckte Botnetz AryStinger hat weltweit über 4000 veraltete Router infiziert. Die Malware nutzt die Geräte als Proxys für Cyberangriffe. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/tausende-router-botnetz-arystinger
-
Botnetz AryStinger infiziert tausende Router weltweit
Das neu entdeckte Botnetz AryStinger hat weltweit über 4000 veraltete Router infiziert. Die Malware nutzt die Geräte als Proxys für Cyberangriffe. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/tausende-router-botnetz-arystinger
-
Botnetz AryStinger infiziert tausende Router weltweit
Das neu entdeckte Botnetz AryStinger hat weltweit über 4000 veraltete Router infiziert. Die Malware nutzt die Geräte als Proxys für Cyberangriffe. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/tausende-router-botnetz-arystinger
-
AryStinger Botnet Converts Legacy Routers to Global Proxies
Research Links 4,300 End-of-Life D-Link Routers to Attack Staging. The AryStinger botnet is exploiting decade-old vulnerabilities in outdated and unsupported routers, turning aging devices into a proxy network for scanning targets, hiding threat actor activity and laying the groundwork for future cyberattacks First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/arystinger-botnet-converts-legacy-routers-to-global-proxies-a-32045
-
AryStinger Botnet Converts Legacy Routers to Global Proxies
Research Links 4,300 End-of-Life D-Link Routers to Attack Staging. The AryStinger botnet is exploiting decade-old vulnerabilities in outdated and unsupported routers, turning aging devices into a proxy network for scanning targets, hiding threat actor activity and laying the groundwork for future cyberattacks First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/arystinger-botnet-converts-legacy-routers-to-global-proxies-a-32045

