A cybersecurity professional uses a tennis analogy to challenge the common notion that defenders must be perfect while attackers only need one success. By referencing Roger Federer's career statistics, the author illustrates that winning a match, much like cybersecurity, doesn't always equate to winning every single point. The key lies in winning the crucial points and understanding the strategic nuances of the game.

A China-linked threat actor, UAT-7810, is actively expanding its network of Operational Relay Boxes (ORBs) by exploiting known vulnerabilities in unpatched Ruckus and ASUS routers. The group is deploying a new set of custom malware, including updated versions of the "LONGLEASH" and "DOGLEASH" backdoors, to establish covert infrastructure for other advanced persistent threat (APT) groups.
These ORB networks are designed to obscure the origins of secondary threat actors, allowing them to route malicious traffic through seemingly legitimate nodes. By compromising edge devices such as wireless routers, UAT-7810 creates a highly evasive and decentralized proxy network that can bypass conventional perimeter defenses.
The development of sophisticated, multi-platform tools like LONGLEASH indicates a significant investment by UAT-7810 in building resilient and difficult-to-dismantle infrastructure. This strategy creates substantial blind spots for defenders, making it harder to trace and mitigate attacks.
Security researchers emphasize that UAT-7810's reliance on exploiting n-day vulnerabilities highlights the critical need for organizations to ensure all edge devices, particularly Ruckus and ASUS routers, are fully patched. Defenders should also monitor network traffic for any unusual proxying behavior or unauthorized connections on devices that typically do not host complex services.
The ongoing activity of UAT-7810 underscores the continuous challenge in cybersecurity, where attackers only need to succeed once while defenders must maintain constant vigilance. This asymmetry is often compared to a tennis match, where winning individual points doesn't guarantee victory; rather, strategic decisions and adapting to an opponent's moves are crucial.
In a similar vein, cybersecurity operations involve thousands of judgment calls, where context and environmental understanding enable better decision-making. The goal is not perfection, which is often unattainable, but rather to make informed choices that improve defensive posture against persistent threats.
In other recent cybersecurity news, researchers have documented what they describe as the first instance of "agentic ransomware," though it functioned more as a wiper due to non-reversible encryption. This attack still required human involvement for tasks such as providing compromised credentials, provisioning command-and-control servers, and selecting victims.
Separately, six security flaws were discovered in Apple's AirDrop and Google's Quick Share. These vulnerabilities allow an attacker within wireless range, using only a laptop and no prior connection, to crash the sharing service on a Mac or iPhone configured to receive from anyone, without requiring any user interaction.
Additionally, a hidden authentication backdoor was identified in multiple firmware versions of Tenda routers. This flaw could grant an attacker administrative access to the device's web management panel. The CERT Coordination Center reported that the issue remains unaddressed as the manufacturer could not be reached.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed