This day 02:09 06:09 10:10 14:01 18:01 22:01
Info  2026-09-16 02:09Z · last 4h · 1 findings · glm-5.2:cloud

Threat Brief — 2026-09-16 — North Korean Linux toolkit targets Korean industry

Executive summary. Fresh reporting adds sector-level detail to the ongoing Ted Backdoor campaign first covered on 4 September: a likely North Korean APT used a previously undocumented Linux espionage toolkit to compromise load balancers, intercept communications, and expand laterally across South Korean media and automotive networks. The attack chain hinges on trojanized HAProxy builds replacing legitimate binaries on Linux infrastructure. No other new findings were ingested in this window; the remaining threat landscape is stable since the 15 September cycle.

Top items

Themes

Supply-chain compromise of infrastructure software persists. The Ted Backdoor campaign joins a growing pattern of attackers trojanizing legitimate infrastructure tooling — HAProxy builds here, WordPress plugins and cPanel backup components in other active stories — to gain persistent access without touching endpoint defences. Organisations running Linux load balancers should verify binary integrity and provenance of HAProxy installations, particularly any builds not sourced from official package repositories.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db