A China-linked advanced persistent threat group, identified as UAT-7810, is reportedly expanding its network of proxy servers. This expansion is being facilitated by the deployment of new malware, according to research from Cisco Talos.

A China-linked advanced persistent threat (APT) group, identified as UAT-7810, has been observed expanding its network of compromised devices, known as Operational Relay Box (ORB) networks, and equipping it with new custom malware. Researchers at Cisco Talos assessed with high confidence that UAT-7810 is a China-nexus group. These ORB networks consist of hijacked routers and other devices that are rented out to other malicious actors to mask the origin of their cyberattacks.
UAT-7810 has been maintaining an ORB network called LapDogs since at least 2025. The group's primary function appears to be the creation of this infrastructure for other APT groups. By compromising a sufficient number of devices, UAT-7810 enables separate China-nexus APT groups to conceal their espionage activities targeting high-value entities.
To expand its network, UAT-7810 has been exploiting known but unpatched vulnerabilities in edge devices. This tactic relies on organizations failing to implement security updates. Specifically, the group has targeted flaws in Ruckus wireless routers since 2025 and, earlier this year, began exploiting a vulnerability in ASUS routers to incorporate them into the network.
In addition to expanding its infrastructure, UAT-7810 has developed a new, upgraded backdoor malware named LONGLEASH. This tool is an evolution of a previous malware and now includes proxying capabilities, allowing it to relay commands to other infected machines.
Cisco Talos also uncovered two previously unknown backdoors. DOGLEASH is designed to execute commands on compromised Linux devices. The second is JARLEASH, a Java-based tool used for managing the group's servers. Comments within a configuration file for JARLEASH were written in Simplified Chinese, which Talos noted as an indicator of Chinese-speaking operators.
The researchers also identified a test program developed by UAT-7810 that targets MIPS-based devices. This suggests the group is actively refining its tools to support the diverse hardware that comprises its ORB network. Cisco Talos stated that its tracking indicates the group's malware and servers remain active.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed