An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.

Reports indicate that an unspecified number of ZBT-manufactured routers, distributed globally as white-label products, have been found to contain multiple pre-installed implants. These implants are reportedly integrated into the devices by the manufacturer.
The nature of these implants suggests they could facilitate unauthorized access or control over the affected routers. Such backdoors typically involve hidden functionalities or credentials that bypass standard security mechanisms, potentially allowing remote access to the device's configuration, network traffic, or even the ability to push further malicious updates. This class of vulnerability often exploits weaknesses in firmware design or manufacturing processes, where non-standard access points are intentionally or unintentionally left active.
ZBT, a manufacturer of networking equipment, appears to be the source of these devices. The "white-label" distribution model means these routers are sold under various brand names by different vendors, making it challenging for end-users to identify the original manufacturer and, consequently, the potential vulnerability. Products in this category commonly serve small businesses, home offices, and general consumer markets, where the expectation of robust security vetting by the reseller may vary.
The scope of this issue is currently unknown, as the reports do not specify the number of affected units or the extent of their global distribution. Given the white-label nature, the devices could be present in a wide array of environments, from individual homes to enterprise networks that have integrated these lower-cost networking solutions. The lack of specific model numbers or firmware versions also complicates the identification and remediation process for users.
Mitigation for this class of issue typically involves isolating the affected devices, if they can be identified, and replacing them with trusted hardware. For devices that cannot be immediately replaced, users are generally advised to ensure they are running the latest available firmware from their specific reseller, though in cases of manufacturer-embedded backdoors, firmware updates may not fully resolve the issue. Network segmentation and strict firewall rules can help limit the potential impact of a compromised router on the broader network.
This incident underscores the growing concerns about supply chain security in hardware manufacturing, particularly for devices originating from regions with complex geopolitical landscapes. The presence of manufacturer-installed backdoors highlights the inherent trust placed in hardware vendors and the potential for that trust to be exploited, raising questions about the due diligence performed by resellers and the broader implications for national and enterprise cybersecurity.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a