LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host
apthigh

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

A China-linked advanced persistent threat (APT) group, identified as LapDogs, has reportedly enhanced its malicious toolkit. Security researchers have observed the deployment of three new backdoors: LongLeash, DogLeash, and JarLeash, which are designed to compromise small office/home office (SOHO) routers.

zeroday.news ·

Cybersecurity researchers have identified an expansion in the arsenal of a China-linked advanced persistent threat (APT) group, known for its operations under the name LapDogs. This threat actor has reportedly introduced new malware components, specifically focusing on compromising small office/home office (SOHO) routers. The newly identified backdoors have been named LongLeash, DogLeash, and JarLeash.

These additions signify a growing sophistication and a broadening attack vector for the LapDogs group. The focus on SOHO routers suggests an intent to gain persistent access into networks that may serve as entry points for larger corporate infrastructures or provide access to sensitive data.

The deployment of these new backdoors indicates a continuous effort by the APT to refine its tools and evade detection. The specific functionalities and exploitation methods of LongLeash, DogLeash, and JarLeash are likely being analyzed by security firms to understand the full scope of the threat.

While the exact motivations behind the LapDogs campaign remain under investigation, APT groups often engage in espionage, intellectual property theft, or disruptive cyber activities. The targeting of SOHO routers could be a strategic move to establish a foothold within organizations or to leverage these devices for further network pivoting.

Further details regarding the technical capabilities of these new backdoors and the specific vulnerabilities they exploit are expected to be released as the investigation progresses. This development underscores the persistent threat posed by nation-state-backed actors and the importance of securing network infrastructure, including edge devices like SOHO routers.

aptmalwarebackdoorrouterchina
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),

security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.

breach

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.