Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a factory-shipped backdoor implanted in at least 20 Chinese router models from Zbtlink. According to a…
Cybersecurity researchers have disclosed details of a factory-shipped backdoor implanted in at least 20 Chinese router models from Zbtlink. According to a…
A high-severity path traversal vulnerability in the open-source developer platform Windmill, tracked as CVE-2026-29059 (CVSS 7.5), is under active exploitation. The flaw…
A public proof-of-concept (PoC) has been released for CVE-2026-55200, a critical vulnerability in the libssh2 client-side SSH library. The flaw, with a…
A high-severity path traversal vulnerability in Langflow, designated CVE-2026-5027 (CVSS 8.8), is being actively exploited in the wild. Discovered by Tenable, the…
A chain of three vulnerabilities in LiteLLM, a widely deployed open-source AI gateway, allows low-privilege users to escalate to full admin and…
VulnCheck is a cybersecurity company that disclosed the ENDLESSDOORS backdoor in Zbtlink routers. Their analysis revealed the implant's behavior, C2 infrastructure, and…