China Upgrades the Backdoor It Uses to Spy on Telcos Globally
2026-03-30T14:54:48Z•6ffe11519e08257ec58b029819e07683d02541b816e148366a799e8f46bd0851
AI securityAPTBPFdoorCheckmarx KICSCisco firewallIoT/IP camera compromiseLangflowOT securityOracle Fusion Middleware RCETrivybackdoorinfostealerpoisoned packagespost-quantum cryptographyransomwarespyware marketsupply-chain attacktelco espionage
What happened
A batch of DarkReading stories highlights an intensifying threat landscape: China-linked APT Red Menshen has upgraded a stealthy BPFdoor backdoor to spy on telcos globally, while multiple critical flaws and supply-chain compromises are being actively exploited (e.g., Langflow code-injection, Oracle Fusion Middleware RCE, Trivy/Checkmarx KICS supply-chain incidents). Ransomware gangs targeted Cisco firewalls, infostealers and trojans spread via poisoned GitHub/npm packages, and abused IP cameras and commercial spyware markets expand. The collection also flags systemic risks from AI (agentic/LLM
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 6ffe11519e08257ec58b029819e07683d02541b816e148366a799e8f46bd0851
- Enrichment time
- 2026-03-30T14:54:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.