LIVE · cybersecurity feed
Live wire
ASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE Publication

backdoor news

12 stories
CVE-2026-93836high

Ninja Forms plugin flaw exploited to hack WordPress sites

Cybersecurity researchers have identified an active exploitation campaign targeting two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, leveraging stored cross-site scripting (XSS) vulnerabilities to compromise websites. The attacks, first observed on October 4 against WPC Product Bundles for WooCommerce users and then on October 5 against Ninja Forms users, involve the…

iothigh

ClingSTUN Malware Turns IoT Devices Into Proxy Nodes

A recently discovered Linux backdoor, named ClingSTUN, has been observed actively compromising Internet of Things (IoT) devices. The malware reportedly exploits a significant number of known vulnerabilities, specifically 24 distinct flaws, to gain initial access to these devices. Once compromised, ClingSTUN employs a novel technique involving legitimate public STUN servers to obfuscate its…

backdoorhigh

Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel

Cisco Talos researchers have identified a new Rust-based backdoor, dubbed Antino, which a China-linked threat actor known as UAT-11587 is using to conduct espionage against government and policy organizations in Asia. The backdoor uniquely leverages Microsoft 365 services, specifically Outlook and OneDrive, for its command-and-control (C2) communications, allowing its traffic to blend in with…

phishinghigh

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian state-sponsored hacking group, Star Blizzard, has reportedly targeted over 100 organizations with sophisticated phishing campaigns designed to deliver backdoor malware. The attacks, which commenced in January, leverage fake event invitations to deceive recipients into installing a backdoor known as CosmicPulse on Windows systems. The primary targets of these campaigns are organizations…

malwarehigh

New Malware Uses Fake CAPTCHAs to Deploy Backdoor

A newly identified malware variant, dubbed TerminalFix by Microsoft, has been observed leveraging deceptive Cloudflare CAPTCHAs to trick users into executing malicious commands. This particular variant is notable for its method of operation, which involves manipulating users into running harmful instructions through Windows Terminal or PowerShell.

npmhigh

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

A recent report indicates that security researchers have uncovered 14 malicious npm packages designed to deploy a Linux backdoor identified as RedC2 4.0. These packages were reportedly masquerading as legitimate utilities related to calendar and streak tracking functionalities within the npm ecosystem. The discovery highlights an ongoing threat vector targeting developers and systems reliant…

malwarehigh

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Cybersecurity researchers have reported the discovery of a novel loader framework, dubbed HollowFrame, which has been observed deploying a sophisticated Rust-based backdoor known as Matryoshka. The initial vector for these attacks is a spear-phishing campaign specifically targeting a law firm, indicating a focused and potentially high-value target. The attack chain is initiated when a…

malwarehigh

China-Linked Daxin Malware Active on Manufacturer's Network Since 2013

Researchers have identified the China-linked Daxin rootkit and a previously unknown backdoor, dubbed Stupig, active on the network of a Taiwan-based subsidiary of a multinational high-tech manufacturer. The discovery suggests a highly stealthy intrusion that may have persisted undetected for 13 years, with compilation timestamps on both malware artifacts dating back to early 2013.

CVE-2026-11405critical

Tenda Firmware Vulnerability Allows Unauthenticated Admin Access

A critical vulnerability has been identified in the firmware of Tenda devices, allowing attackers to gain administrative access without authentication. The flaw, tracked as CVE-2026-11405, affects the web management interface of the affected devices.

apthigh

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

Cybersecurity researchers have identified an expansion in the arsenal of a China-linked advanced persistent threat (APT) group, known for its operations under the name LapDogs. This threat actor has reportedly introduced new malware components, specifically focusing on compromising small office/home office (SOHO) routers. The newly identified backdoors have been named LongLeash, DogLeash, and…

vulnerabilityhigh

Hidden backdoor in Tenda router firmware grants admin access

A security vulnerability has been discovered in the firmware of several Tenda router models, creating a hidden backdoor that could allow unauthorized administrative access. The issue, tracked as CVE-2026-11405, stems from an undocumented authentication mechanism within the device's web server.

CVE-2026-11405high

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

A significant security vulnerability has been discovered in the firmware of several Tenda router models, potentially exposing users to unauthorized administrative access. The CERT Coordination Center (CERT/CC) has issued a warning about this hidden backdoor, which allows attackers to bypass normal authentication procedures and gain control over the router's web interface.