Chinese hackers develop LONGLEASH malware to expand ORB network

2026-07-07T19:23:27Z2c61e3cb003708a6c0bf03f7c96976763c2313eccaf977448b9f8d5c2079b4bf
APTAdobe ColdFusionBeyondTrustCI/CDCVE-2026-48282EtherRATGitHub ActionsJanuscapeLONGLEASHRuckusTendaUAT-7810VM escapeauthentication bypassbackdoorexploitationphishingremote accessrouterssocial engineeringvirtualizationvulnerability

What happened

A batch of high-impact security stories: Chinese-linked actors (tracked as UAT-7810) are deploying new LONGLEASH malware to co-opt internet-facing networking gear (notably unpatched Ruckus routers) to expand an ORB relay network; multiple Tenda router firmware versions contain a hidden authentication backdoor that can grant administrative web-panel access; a 16‑year‑old Linux kernel vulnerability dubbed “Januscape” enables VM escape to execute code on hosts (Intel/AMD); BeyondTrust disclosed critical authentication‑bypass flaws in its Remote Support and Privileged Remote Access products; Adobe

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
2c61e3cb003708a6c0bf03f7c96976763c2313eccaf977448b9f8d5c2079b4bf
Enrichment time
2026-07-07T19:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.