The most damaging incidents this week came from the mundane: default settings, firmware flaws, and social engineering. A widespread campaign highlighted how a Chinese state-linked hacking group is abusing compromised routers to act as covert proxies, intercepting traffic and harvesting credentials before meticulously scrubbing log files to erase their tracks.
In another notable development, researchers demonstrated that AI agents can be manipulated into going off-task, ignoring their core directives when prompted with specific inputs. This raises serious concerns about the reliability of autonomous systems in enterprise environments where they are increasingly granted access to sensitive data.
A critical backdoor was also discovered in a widely used router model, which shipped with a pre-configured listening service, allowing attackers immediate remote access without authentication. Similarly, a new phishing tactic involved sending fake checks to victims, tricking them into installing malware themselves under the guise of a "verification" step.
Multiple older vulnerabilities were chained together to form new attack vectors, bypassing existing security patches. The week also saw an uptick in malicious fake applications on third-party stores, a resurgence of "helpful" tech support call scams, and the availability of cheap, off-the-shelf banking trojan kits on the dark web.
Key takeaways from the week include:
Chinese Spy Proxy: Routers compromised by a Chinese hacking group are being used as stealth proxies to capture traffic and steal passwords while actively removing logs.
AI Agents: Proof-of-concept attacks show AI agents can be prompted to abandon their assigned tasks, potentially leading to unintended actions.
Router Backdoors: A specific router model was found to have a backdoor account and listening service enabled by default, granting instant access to the network.
Fake Check Scams: Cybercriminals are mailing physical checks to targets, which when deposited, trigger a call to fake support that guides the victim into installing remote access malware.
Source: The Hacker News
Given the prevalence of router-based attacks, is your organization auditing its edge devices for unauthorized listening services or default credentials?