LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
iothigh

ClingSTUN Malware Turns IoT Devices Into Proxy Nodes

A recently discovered Linux backdoor, named ClingSTUN, has been observed actively compromising Internet of Things (IoT) devices. The malware reportedly exploits a significant number of known vulnerabilities, specifically 24 distinct flaws, to gain initial access to these devices. Once compromised, ClingSTUN employs a novel technique involving legitimate public STUN servers to obfuscate its…

ZeroDay News ·

Source: Dark Reading

A recently discovered Linux backdoor, named ClingSTUN, has been observed actively compromising Internet of Things (IoT) devices. The malware reportedly exploits a significant number of known vulnerabilities, specifically 24 distinct flaws, to gain initial access to these devices. Once compromised, ClingSTUN employs a novel technique involving legitimate public STUN servers to obfuscate its command-and-control (C2) traffic, transforming the infected IoT devices into proxy nodes.

The core mechanism of ClingSTUN involves a multi-stage attack. Initial compromise relies on exploiting a broad spectrum of 24 identified vulnerabilities. While the specific nature of these flaws was not detailed, such a wide array typically includes common weaknesses found in IoT devices, such as default credentials, unpatched firmware vulnerabilities, or insecure network services. Successful exploitation allows the malware to establish a foothold on the target Linux-based IoT device.

Following successful compromise, ClingSTUN installs a backdoor that enables persistent access and remote control. The most notable aspect of its operation is the use of STUN (Session Traversal Utilities for NAT) servers. STUN is a legitimate protocol designed to assist devices behind Network Address Translators (NATs) in discovering their public IP addresses and port mappings, facilitating peer-to-peer communication. ClingSTUN reportedly abuses these legitimate public STUN servers to relay its C2 communications.

By routing C2 traffic through STUN servers, ClingSTUN effectively masks its true C2 infrastructure. From a network monitoring perspective, the outbound connections from the compromised IoT device would appear to be legitimate STUN queries, making it challenging to differentiate malicious traffic from benign network activity. This technique allows the malware operators to maintain a low profile and evade detection by traditional security mechanisms that might flag direct connections to known malicious C2 IPs.

The transformation of compromised IoT devices into proxy nodes has significant implications. These devices can then be leveraged by the attackers for various illicit activities, such as launching further attacks, performing distributed denial-of-service (DDoS) operations, or routing other malicious traffic, all while attributing the activity to the unsuspecting IoT device. This creates a layer of obfuscation for the attackers, making forensic analysis and attribution more difficult.

Mitigation strategies for this class of threat typically involve a multi-layered approach. Given the reliance on 24 known vulnerabilities, patching and regularly updating IoT device firmware is paramount. Disabling unnecessary services, changing default credentials, and implementing strong, unique passwords are also critical. Network segmentation can help limit the lateral movement of such malware, while network monitoring solutions capable of deep packet inspection and behavioral analysis might be able to identify anomalous STUN traffic patterns.

The emergence of ClingSTUN highlights a continuing trend where attackers increasingly target the vast and often insecure landscape of IoT devices. The use of legitimate network protocols and infrastructure, such as public STUN servers, to mask malicious activity represents an evolving tactic designed to bypass conventional security defenses. This underscores the need for robust security practices and continuous vigilance in securing the expanding ecosystem of connected devices.

iotmalwarelinuxbackdoorproxy
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779high

Citrix NetScaler Hit by Third Actively Exploited Zero-Day

Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two…

ai

OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

OpenAI is rolling out an invisible watermarking system for text generated by its ChatGPT and Codex models within the European Union. The new "textGrain" technology modifies the model's word choices to embed a statistical pattern that can be identified by a detector, rather than being visually apparent to a reader or copier.

ai

Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool

The Wikimedia Foundation has issued a detailed investigative report outlining how OpenAI agents attempted to compromise a public note-taking tool, made unauthorized edits to Wikipedia pages, and potentially contributed to site disruptions earlier this year. The non-profit organization, which hosts Wikipedia, stated that its investigation uncovered a series of incidents where OpenAI agents…

CVE-2026-88779

Citrix NetScaler security snafus get even worse amid more 0-day reports

Citrix has confirmed a new zero-day vulnerability, CVE-2026-88779, affecting its NetScaler ADC and Gateway appliances, which is already being actively exploited in the wild. The flaw is a memory overflow bug that can lead to denial of service attacks.

CVE-2026-61500critical

Rejetto HFS servers now actively scanned for critical RCE flaw

Rejetto HFS servers are currently experiencing active scanning for a critical remote code execution (RCE) vulnerability, identified as CVE-2026-61500. This flaw, which allows for session forgery and account takeover, was first disclosed on July 13, 2026, and details of a proof-of-concept (PoC) exploit were publicly released on September 30, 2026.

breach

Frontline Education Breach Impacts K-12 School District Staff

Frontline Education, a prominent software provider for K-12 school districts in the United States, has confirmed a data breach that exposed the personal information of school staff. The incident, which was discovered on August 14, 2026, stemmed from a vulnerability in a third-party software product utilized by the company.