China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
VulnCheck has discovered two pre-installed firmware implants in ZBT routers that enable unauthenticated attackers to achieve root-level command execution on affected devices. The implants, designated CVE-2026-74232 and CVE-2026-74233 and named SPEAKINGSTONE and DARKLANTERN respectively, represent a significant supply-chain risk for organizations deploying these Shenzhen Zhibotong Electronics devices.
Two individuals have been charged in connection with TeamPCP's extensive global supply chain attack campaign that compromised over 1,000 organizations and resulted in the theft of approximately 500,000 credentials, with OpenAI among the affected victims. The attackers deployed a self-propagating worm dubbed Shai-Hulud in their operation, demonstrating the sophisticated nature of their coordinated hacking spree. This case highlights the significant reach and impact of organized cyber threats targeting critical infrastructure and technology companies worldwide.
Australian authorities have arrested alleged masterminds behind TeamPCP, a group responsible for developing the Shai-Hulud worm and conducting supply chain attacks. The operation was conducted in collaboration with the FBI, marking a significant enforcement action against the threat actor group.
Australian police have charged two men in connection with TeamPCP, a cybercrime operation that embedded malware in open-source code to steal over 500,000 credentials from more than 1,000 organizations globally. The alleged scheme exploited the trust developers place in open-source software to distribute credential-stealing malware at scale across multiple sectors.