Attention: You are using an outdated browser, device or you do not have the latest version of JavaScript downloaded and so this website may not work as expected. Please download the latest software or switch device to avoid further issues.
| 30 Aug 2026 | |
| Written by Gabi Gerber | |
| Attacks & Threats |
| Hacking Topics, Security Operation Center |
A Chinese manufacturer has been planting backdoors inside of white-label routers sold in high volume around the globe.
Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) sells gobs of routers every year, if public evidence is to be believed. The 15-year-old company is the bestselling router manufacturer on Chinese e-commerce giant Alibaba.com, which lists its total annual output at 3.57 million units. Typically, those units are then sold to customers by companies other than ZBT, in countries like the Philippines, India, Canada, Australia, Germany, Bulgaria, Austria, Russia, and the US. According to its marketing, ZBT has exported its products to more than 50 countries and regions. More here
Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them. More...
Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot… More...
A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval de… More...
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure … More...
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phi… More...
Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them. More...
Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot… More...
A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval de… More...
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure … More...
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phi… More...