LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
security

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Recent reports indicate the discovery of Linux backdoors actively targeting telecommunications and network appliances within South Korea and Taiwan. These sophisticated backdoors are designed to evade detection by masquerading their malicious traffic as legitimate email services and by impersonating benign system processes. This tactic allows the malware to blend into normal network activity…

ZeroDay News ·

Source: The Hacker News

Recent reports indicate the discovery of Linux backdoors actively targeting telecommunications and network appliances within South Korea and Taiwan. These sophisticated backdoors are designed to evade detection by masquerading their malicious traffic as legitimate email services and by impersonating benign system processes. This tactic allows the malware to blend into normal network activity and operating system operations, making it significantly harder for security tools and administrators to identify their presence.

The primary mechanism for evasion involves the backdoors adopting the names of legitimate operating system components or processes. This defense evasion technique is a common practice among threat actors, as naming malicious binaries after existing, trusted system files can help them avoid scrutiny. When a process appears to be a standard part of the operating system, it is less likely to trigger alerts or be flagged for suspicious behavior by host-based intrusion detection systems or security analysts.

Furthermore, the backdoors are reported to disguise their network communications as traffic originating from email services. This method of obfuscation leverages the high volume and expected nature of email-related network activity in many organizational environments. By mimicking protocols and patterns associated with email, the malicious traffic can effectively hide within the noise of legitimate communications, bypassing network-based detection systems that might otherwise flag unusual or unauthorized outbound connections.

The specific targets for these backdoors are telecom and network appliances. This focus suggests an intent to gain persistent access to critical infrastructure, potentially for surveillance, data exfiltration, or to establish a foothold for further attacks. Devices in this category often have direct access to sensitive network traffic and can serve as strategic points for lateral movement within an organization's network or even across different networks.

Mitigation strategies for this class of threat typically involve a multi-layered approach. Organizations should implement robust endpoint detection and response (EDR) solutions capable of behavioral analysis, which can identify anomalous process behavior even if the process name appears legitimate. Network segmentation and strict egress filtering can help restrict unauthorized outbound connections, while deep packet inspection can potentially identify malicious traffic patterns disguised as legitimate services. Regular patching and strong access controls for network appliances are also critical to prevent initial compromise.

This incident underscores the ongoing challenge of defending against advanced persistent threats that employ sophisticated evasion techniques. The targeting of critical network infrastructure in specific regions highlights the strategic nature of these attacks. It reinforces the need for continuous vigilance, advanced threat intelligence, and comprehensive security architectures that can detect and respond to threats designed to blend seamlessly into normal operational environments.

ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Wiretapping change sparks big privacy fight in the Golden State

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…

zero-day

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

Security researchers collectively uncovered 32 zero-day vulnerabilities on the first day of the Pwn2Own Ireland 2026 competition, earning a total of $388,500. The event, organized by the Zero Day Initiative (ZDI), aims to identify critical flaws in various products before malicious actors can exploit them.

phishing

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity researchers have uncovered a human-operated phishing platform designed to impersonate advertising portals for popular artificial intelligence (AI) chatbots. The platform specifically targets users by mimicking ad products for services such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. Its primary objective is to capture user credentials and…

vulnerability

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

Google has reportedly developed an artificial intelligence agent, named PageBreak, which has identified approximately 500 flaws within Google's own web applications. This development highlights an emerging trend in the cybersecurity industry: the application of AI and deterministic validation methods to automate the discovery of vulnerabilities, assess their exploitability, and provide a…

ai

Former NSA chief Nakasone says agency overhaul is ‘probably needed’

Former National Security Agency Director Paul Nakasone stated that a reported comprehensive reorganization of the agency is likely necessary to address rapidly evolving cyber threats and the competitive landscape in artificial intelligence (AI). Nakasone, who led the NSA and U.S. Cyber Command from 2018 to 2024, made these remarks on Tuesday at VulnCheck's ThreatCon1 conference.

security

Microsoft extends the Outlook naughty step with two more file types

Microsoft is implementing new security measures for Outlook, adding two file types, .msix and .msixbundle, to its default block list for attachments. These file types are associated with Windows application packages and bundles. The change is set to affect users of the New Outlook for Windows client and Outlook on the Web within Exchange Online.