China Upgrades the Backdoor It Uses to Spy on Telcos Globally

2026-03-30T14:54:48Z6ffe11519e08257ec58b029819e07683d02541b816e148366a799e8f46bd0851
AI securityAPTBPFdoorCheckmarx KICSCisco firewallIoT/IP camera compromiseLangflowOT securityOracle Fusion Middleware RCETrivybackdoorinfostealerpoisoned packagespost-quantum cryptographyransomwarespyware marketsupply-chain attacktelco espionage

What happened

A batch of DarkReading stories highlights an intensifying threat landscape: China-linked APT Red Menshen has upgraded a stealthy BPFdoor backdoor to spy on telcos globally, while multiple critical flaws and supply-chain compromises are being actively exploited (e.g., Langflow code-injection, Oracle Fusion Middleware RCE, Trivy/Checkmarx KICS supply-chain incidents). Ransomware gangs targeted Cisco firewalls, infostealers and trojans spread via poisoned GitHub/npm packages, and abused IP cameras and commercial spyware markets expand. The collection also flags systemic risks from AI (agentic/LLM

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
6ffe11519e08257ec58b029819e07683d02541b816e148366a799e8f46bd0851
Enrichment time
2026-03-30T14:54:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.