Critical

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

The Hacker News
Actively Exploited

Overview

Researchers have discovered Linux backdoors that are targeting telecom and network devices in South Korea and Taiwan. These backdoors cleverly disguise their malicious traffic as legitimate email services, making it difficult for security systems to detect them. Attackers often name their malware after real components of the operating system to avoid detection. This tactic not only helps the malware blend in but also poses significant risks to network security in these regions. The ongoing threat underscores the need for enhanced monitoring and detection measures in organizations that rely on Linux systems for critical infrastructure.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Telecom and network appliances in South Korea and Taiwan
  • Action Required: Organizations should implement advanced network monitoring solutions and regularly update their security protocols to detect unusual traffic patterns.
  • Timeline: Newly disclosed

Original Article Summary

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may

Impact

Telecom and network appliances in South Korea and Taiwan

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should implement advanced network monitoring solutions and regularly update their security protocols to detect unusual traffic patterns. Regular system audits and employee training on recognizing phishing attempts could also be beneficial.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Linux, Malware, Critical.

Related Coverage

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

The Hacker News

Cybersecurity researchers have uncovered a malicious campaign involving npm packages that has been distributing information stealers and remote access trojans (RATs). Codenamed MALFEX, this operation has been linked to a single threat actor who has published 12 different packages since August 2023, with eight of them being identified as harmful. These malicious packages have been downloaded over 40,000 times, potentially compromising the systems of numerous developers and organizations using npm for package management. The presence of the Overlord RAT and other malware poses serious risks, including data theft and unauthorized access to users' systems. Developers and companies using npm should be vigilant and ensure they are not using any of these compromised packages.

Oct 7, 2026

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

The Hacker News

SonicWall has issued hotfixes for four vulnerabilities in its SMA1000 appliances, which are used to facilitate remote access to corporate networks. The most critical flaw has been rated a perfect 10.0 on the CVSS scale and allows attackers to send unauthorized requests through the appliance, potentially accessing internal functions without needing any login credentials. SonicWall has stated that there is currently no evidence that these vulnerabilities are being actively exploited. However, organizations using these appliances should prioritize applying the patches to safeguard their networks. This incident emphasizes the need for companies to regularly update their security appliances to defend against potential attacks.

Oct 7, 2026

Microsoft Outlook to block MSIX attachments starting November

BleepingComputer

Microsoft is set to block .msix and .msixbundle attachments in Outlook Web and the new Outlook Windows client starting in November. This change affects users who rely on these file types for application packaging and distribution. By blocking these attachments, Microsoft aims to enhance security and prevent potential misuse of these formats, which could be exploited by malicious actors. Users will need to explore alternative methods for sharing applications or consider using different attachment formats. This decision reflects ongoing efforts by Microsoft to protect its users from security risks associated with potentially harmful file types.

Oct 7, 2026

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

The Hacker News

A serious vulnerability has been discovered in LMCache, an open-source tool used to enhance the performance of large language model servers like vLLM. This flaw allows unauthenticated attackers to execute code on the cache server, posing a significant risk since there is no patch currently available to fix the issue. The problem arises specifically in LMCache's multiprocess mode, where it operates as a standalone server that communicates with LLM workers via the ZeroMQ messaging library. As a result, any server utilizing this software could be at risk of unauthorized access and potential exploitation. Organizations using LMCache should take immediate steps to secure their systems and monitor for any suspicious activity.

Oct 7, 2026

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

The Hacker News

The FBI and the Secret Service have issued a warning regarding the ongoing FortiBleed credential harvesting campaign, which targets Fortinet's FortiGate firewalls and SSL VPN gateways. This campaign has reportedly collected over 86,000 credentials, exploiting weaknesses in reused or leaked passwords and outdated password storage methods. Organizations using Fortinet products need to be vigilant, as attackers can gain unauthorized access to sensitive systems. The persistence of this threat highlights the importance of using strong, unique passwords and implementing robust security measures. Companies are urged to review their security protocols to protect against this active exploitation.

Oct 7, 2026

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

BleepingComputer

SonicWall has issued urgent hotfixes to address a serious server-side request forgery (SSRF) vulnerability in its SMA1000 series appliances. This flaw, classified as maximum severity, could allow attackers to send unauthorized requests from the server, potentially exposing sensitive information or compromising internal systems. Users of the SMA1000 series should act quickly to apply these hotfixes to protect their networks. The vulnerability poses a significant risk, especially for organizations relying on these devices for secure remote access. Companies are advised to review their systems and ensure they are updated to mitigate any potential exploitation.

Oct 7, 2026