Router maker Zyxel tells customers to replace vulnerable hardware exploited by hackers


Taiwanese hardware maker Zyxel says it has no plans to release a patch for two actively exploited vulnerabilities affecting potentially thousands of customers.

Threat intelligence startup GreyNoise warned late last month that a critical-rated zero-day vulnerability impacting Zyxel routers was being actively exploited. GreyNoise said the flaws allow attackers to execute arbitrary commands on affected devices, leading to complete system compromise, data exfiltration, or network infiltration.

Read more…
Source: TechCrunch News


Sign up for our Newsletter


Related:

  • Criminal multitool LilithBot arrives on malware-as-a-service scene

    October 10, 2022

    A Russia based threat group that set up a malware distribution shop earlier this year is behind a Swiss Army knife-like botnet that comes with a range of other malicious capabilities, from stealing information to mining cryptocurrency. That’s according to researchers at Zscaler’s ThreatLabz threat intelligence unit. It said the Eternity group – also known as ...

  • Iranian state-run live TV hacked by protesters

    October 9, 2022

    Iran’s state-run broadcaster was apparently hacked on air Saturday, with a news bulletin interrupted by a protest against the country’s leader. A mask appeared on the screen, followed by an image of Supreme Leader Ali Khamenei with flames around him. The group called itself “Adalat Ali”, or Ali’s Justice. Read more… Source: BBC News  

  • Pro-Iranian hackers attack Israeli gas company website

    October 9, 2022

    Iraqi hacker group “al-Tahara” attacked the websites for two natural gas companies. The first, Energean, is an international company which has done extensive business with Israel, having acquired the Karish and Tanin natural gas fields from Delek Drilling and Avner Oil in 2016. The second, Israel Natural Gas Lines, is a corporation owned by the Israeli ...

  • ADATA denies RansomHouse cyberattack, says leaked data from 2021 breach

    October 8, 2022

    Taiwanese chip maker ADATA denies claims of a RansomHouse cyberattack after the threat actors began posting stolen files on their data leak site. The RansomHouse gang added ADATA files to their data leak site on Tuesday, claiming they stole 1TB worth of documents in a 2022 cyberattack.The threat actors also leaked samples of allegedly stolen files, ...

  • Lloyd’s of London reboots after dodgy network activity detected

    October 7, 2022

    Lloyd’s of London has reset its IT systems and is probing a possible cyberattack against it after detecting worrisome network behavior this week. “Lloyd’s has detected unusual activity on its network and we are investigating the issue,” a spokesperson told The Register on Thursday. “As a precautionary measure, we are resetting the Lloyd’s network and systems. ...

  • TOP 10 unattributed APT mysteries

    October 7, 2022

    Targeted attack attribution is always a tricky thing, and in general, we believe that attribution is best left to law enforcement agencies. The reason is that, while in 90% of cases it is possible to understand a few things about the attackers, such as their native language or even location, the remaining 10% can lead ...