FILTERING BY: CLEAR FILTER

Head Mare APT Exploits TrueConf Server Vulnerabilities to Deploy PhantomCore and PhantomGraph

The Head Mare APT group is conducting a targeted campaign against strategic Russian sectors by exploiting vulnerabilities KLCERT-26-057 and KLCERT-26-058 in unpatched TrueConf video conferencing servers. By compromising these servers, attackers successfully trojanize the official TrueConf client installers hosted on the platform. This facilitates a sophisticated supply-chain-style delivery mechanism where participants downloading the installer to join conferences inadvertently deploy the PhantomCore and PhantomGraph backdoors onto their endpoints. This technique effectively transforms a trusted communication infrastructure into a malware distribution hub, leading to full system compromise within critical industries including energy, transport, and software development.

Zbtlink ENDLESSDOORS Supply Chain Compromise CVE-2026-66747

Research has uncovered "ENDLESSDOORS," a critical supply chain compromise affecting approximately 20 Zbtlink router models distributed globally via Amazon, AliExpress, and Alibaba. Tracked as CVE-2026-66747, the vulnerability consists of a factory-installed firmware backdoor that grants remote attackers unauthenticated root shell access to the device. Because the backdoor is embedded during the manufacturing process, it provides high persistence and bypasses standard user configuration security. This allows for full administrative control over the device, enabling total network traffic interception and facilitating lateral movement within the local network environment.


LINK COPIED TO CLIPBOARD