← Back
Supply ChainDark Reading·1 hour ago

Chinese Routers Sold Worldwide Contain Backdoors

An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.

Read full article at Dark Reading

Related Articles

Supply ChainSecurity Affairs·7 hours ago

Australian Police Charge Two Over TeamPCP Credential Theft

Australian police have charged two men in connection with TeamPCP, a cybercrime operation that embedded malware in open-source code to steal over 500,000 credentials from more than 1,000 organizations globally. The alleged scheme exploited the trust developers place in open-source software to distribute credential-stealing malware at scale across multiple sectors.

Supply ChainHelp Net Security·2 days ago

AI supply chain risk is showing up in developer workflows first

AI supply chain risks are predominantly emerging in developer workflows and open-source package repositories rather than in more sophisticated attack vectors like poisoned model weights or compromised MCP servers, according to Zentera Systems CEO Dr. Jaushin Lee. Lee advocates for network segmentation as a more cost-effective risk mitigation strategy than tooling alone and recommends that software teams adopt semiconductor isolation practices to strengthen their defenses. He also addresses the limitations of self-hosted models in protecting against these evolving supply chain threats.

Supply ChainUnit 42·5 days ago

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are increasingly focusing on CI/CD pipelines and developer tools rather than application code itself, exploiting gaps in the software development lifecycle supply chain. Organizations need comprehensive visibility across their entire SDLC and implement rigorous security controls to defend these overlooked but critical infrastructure components.

Supply ChainThe Hacker News·6 days ago

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Researchers discovered 14 malicious npm packages disguised as calendar and streak utilities that deliver RedC2 4.0, an AI-powered Linux backdoor to infected systems. Upon installation, the trojanized packages extract and execute a bundled binary as a background process to establish command and control. This supply chain attack demonstrates how legitimate package repositories remain a vector for distributing sophisticated implants with AI-assisted capabilities.