threat-intel Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Chinese router manufacturer Zbtlink ships router firmware with a factory-installed backdoor, dubbed "ENDLESSDOORS," that automatically attempts to connect to command-and-control infrastructure every 35 seconds. This back… The Hacker News · Aug 6, 2026 High CHbackdoorrouterc2
threat-intel Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway A Chinese router vendor, Longchen, initially denied that its firmware contained backdoors, but subsequently paused downloads to address security concerns. This follows reports of potential vulnerabilities and a desire to… The Register · Aug 6, 2026 Medium CHUSsupply-chainrouterbackdoor
threat-intel State Department says Trump raised cyber scam compound issue with Xi U.S. President Donald Trump reportedly raised the issue of Southeast Asian cyber scam compounds with Chinese President Xi Jinping during a meeting with senior officials. State Department officials have revealed that Chin… The Record · Aug 6, 2026 High CHCALAcybercrimescamtransnational crime
threat-intel 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th) A threat actor successfully exploited a vulnerable SSH honeypot within 22 seconds, injecting a backdoor SSH key, changing the root password, and clearing host-based access restrictions. This rapid post-exploitation seque… SANS Internet Storm Center · Aug 6, 2026 High CHsshautomationpost-exploitation
threat-intel Prompt injection isn't the bug, AI agent frameworks are This article discusses the increasing risk of prompt injection attacks within AI agent frameworks, rather than the models themselves. The rise of open-source AI models, particularly from China, is prompting a reaction fr… The Register · Aug 5, 2026 Medium CHIRUSprompt injectionaillm
threat-intel Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says A House Committee investigation, spurred by the Salt Typhoon hack, revealed that Chinese telecommunications giants – China Mobile, China Unicom, and China Telecom – maintain a significant and deeply embedded presence in… The Record · Aug 5, 2026 High CHcybersecuritytelecomstate-sponsored
threat-intel IBM's agentic AI platform is under active attack - patch now IBM's agentic AI platform is currently under active attack, with vulnerabilities exploited to gain control of systems. Attackers are leveraging prompt injection techniques to manipulate other AI agents, highlighting a gr… The Register · Aug 5, 2026 High CVE-2026-9198CHIRprompt injectionai securityvulnerability
threat-intel Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Cybersecurity researchers have uncovered a network of underground services, including ‘Poison Claude,’ offering discounted access to Anthropic’s AI models (like Claude Opus) to users in China and elsewhere. These service… The Hacker News · Aug 5, 2026 High CHaisynthetic identityproxy
threat-intel London cops handed victim's new address and number to her stalker, watchdog says This article is a collection of security and technology news snippets from The Register. It covers a range of topics including a security watchdog investigation into police handing over a stalker's information, a Chinese… The Register · Aug 5, 2026 Medium CHUKcybersecurityvulnerabilityransomware
threat-intel The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict The article explores the growing intersection of cyber operations and geopolitical conflict, arguing that cyberspace has become a ‘fourth battlefield’ alongside traditional military domains. Nation-state cyber activity,… SecurityWeek · Aug 5, 2026 High CHNOUScyber espionagegeopoliticscyberwarfare
vulnerability CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities The CISA has issued a warning about three actively exploited vulnerabilities affecting IBM Langflow OSS, N-able N-central, and Apache Tomcat. These vulnerabilities – CVE-2026-9198, CVE-2026-18556, and CVE-2026-34486 – ar… SecurityWeek · Aug 5, 2026 High CVE-2026-9198CVE-2026-18556CVE-2026-18577CHcvepatchremote code execution
threat-intel OpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraud OpenAI has disrupted a network of scam centers in Cambodia that were using ChatGPT to facilitate investment fraud targeting Indian nationals. The scammers leveraged the AI chatbot for a wide range of tasks, including cre… The Record · Aug 4, 2026 High CACHUGaiscamcybercrime
threat-intel Bypassing AI guardrails is so easy a script kiddie can do it Recent developments highlight the increasing ease with which AI model guardrails can be bypassed, allowing even novice attackers to manipulate large language models. This vulnerability stems from the rapid release of ope… The Register · Aug 4, 2026 Medium CHIRaimlprompt injection
threat-intel This one time, at Hacker Summer Camp … This article covers a range of cybersecurity and technology news, including a Chinese AI model release, vulnerabilities in Joomla extensions, a Russian phishing campaign mimicking Signal support, and a significant acquis… The Register · Aug 4, 2026 Medium CHIRairansomwarephishing
threat-intel AI helps Microsoft bug hunters chase a record $20M payday Microsoft security researchers are experiencing a surge in zero-day attacks targeting on-prem SharePoint, fueled by a new wave of exploits leveraging vulnerabilities in third-party extensions. Simultaneously, Chinese act… The Register · Aug 4, 2026 High CHzero-dayphishingcybersecurity
threat-intel Tennessee congressional hopeful accused of shooting license plate cameras Several AI and open-source model developments are occurring, including Alibaba's release of its Qwen model and competition in the AI space. Simultaneously, security concerns are rising, with reports of phishing attacks i… The Register · Aug 4, 2026 Medium CHIRaiopen-sourcephishing
threat-intel CAF Bank reopens online service but warns of further outages This article is a collection of cybersecurity and technology news snippets. It covers a range of topics including a phishing campaign mimicking Signal support, a vulnerability impacting Joomla extensions, and a new X11 s… The Register · Aug 4, 2026 Medium CHIRphishingvulnerabilitycybersecurity
threat-intel Cloudflare has mostly ditched third party security tools, suggests not trying that at home This article is a collection of security-related news snippets from The Register. It covers a range of topics including AI model releases from China, vulnerabilities in Joomla extensions, acquisitions in the cybersecurit… The Register · Aug 4, 2026 Medium CHSWvulnerabilityransomwarecybersecurity
threat-intel 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users A sophisticated supply chain attack targeting Chinese-speaking developers using Alibaba tools has been discovered. Researchers found a set of malicious npm packages, including wrappers mimicking private Alibaba packages,… The Hacker News · Aug 3, 2026 High CHsupply chainmalwarenpm
threat-intel AI slop pollutes the CVE pipeline with fake vulns This article covers a range of cybersecurity and technology news, including a report on fake vulnerabilities polluting the CVE pipeline due to AI, a phishing campaign impersonating Signal support, and a discussion of var… The Register · Aug 3, 2026 Medium CHUKvulnerabilityphishingransomware