Chinese hackers develop LONGLEASH malware to expand ORB network
2026-07-07T19:23:27Z•2c61e3cb003708a6c0bf03f7c96976763c2313eccaf977448b9f8d5c2079b4bf
APTAdobe ColdFusionBeyondTrustCI/CDCVE-2026-48282EtherRATGitHub ActionsJanuscapeLONGLEASHRuckusTendaUAT-7810VM escapeauthentication bypassbackdoorexploitationphishingremote accessrouterssocial engineeringvirtualizationvulnerability
What happened
A batch of high-impact security stories: Chinese-linked actors (tracked as UAT-7810) are deploying new LONGLEASH malware to co-opt internet-facing networking gear (notably unpatched Ruckus routers) to expand an ORB relay network; multiple Tenda router firmware versions contain a hidden authentication backdoor that can grant administrative web-panel access; a 16‑year‑old Linux kernel vulnerability dubbed “Januscape” enables VM escape to execute code on hosts (Intel/AMD); BeyondTrust disclosed critical authentication‑bypass flaws in its Remote Support and Privileged Remote Access products; Adobe
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 2c61e3cb003708a6c0bf03f7c96976763c2313eccaf977448b9f8d5c2079b4bf
- Enrichment time
- 2026-07-07T19:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.