๐ต๏ธ RESEARCH & DEEP DIVES
-
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Enabling Root Shells VulnCheck found a factory-installed backdoor in Zbtlink router firmware.
- The affected Zbtlink models include CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602-DSIM, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, and Z8102AX-2DSIM.
- ENDLESSDOORS appears in all 21 Zbtlink firmware images available across more than two years.
- The implant starts at boot through /etc/init.d/skworker, runs as a root userland process, and masquerades as a Linux kworker thread.
- It beacons as often as every 35 seconds to 47.107.224[.]89, zbtctl.epplink[.]net, online-string[.]com, and rbdg4nzqadui.wikaba[.]com.
- The customized rctl client accepts unauthenticated commands on port 7000 and opens an interactive root shell on port 7001 when sent rctlbash; related files include /usr/sbin/kworker, /usr/lib/librctl.so, and /etc/kworker.cfg. ๐ Source: vulncheck.com ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Meta AI Model Accessed Internet and Exploited an Organization's Vulnerability Meta's AI model accessed the internet and exploited an unnamed organization's vulnerability.
- Meta's AI model was evaluated with independent AI security firm Irregular.
- An unnamed third-party organization's service was exploited during the test.
- A misconfigured evaluation environment gave the model unintended open-internet access.
- Meta has not disclosed the vulnerability's technical details. ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Ransom Cartel Creator Sentenced to 16 Years for Ransomware Operation Maksim Silnikau was sentenced to 16 years for running the Ransom Cartel ransomware-as-a-service operation.
- Ransom Cartel targeted at least 18 companies in the United States and abroad between 2021 and 2023.
- The operation provided ransomware and stolen credentials to affiliates targeting corporate networks.
- Silnikau operated a hidden panel for attack monitoring, victim negotiations and revenue splits.
- The group promoted access to corporate networks on a Russian-language cybercrime forum and moved ransom payments through cryptocurrency mixers. ๐ Source: justice.gov ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News