Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Dozens of Red Hat packages backdoored through its official NPM channel
    • Microsoft Build 2026 Kicks Off Today: Live Updates on Copilot AI and Dev Tools
    • From Regex to Vision Models: Which RAG Technique Fits Which Problem
    • Rehumanizing global health care with agentic AI
    • Robots-Blog | Praxisprojekt mit fischertechnik an der Hochschule Hof in Bayern
    • Ancient giant octopuses were apex predators, study finds
    • Barcelona’s Zazume raises €2.5 million to scale its AI-powered rental management platform
    • How to Shop Like a Pro During Amazon Prime Day (2026)
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Tuesday, June 2
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Google finds custom backdoor being installed on SonicWall network devices
    News

    Google finds custom backdoor being installed on SonicWall network devices

    Editor Times FeaturedBy Editor Times FeaturedJuly 16, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    Researchers from the Google Risk Intelligence Group stated that hackers are compromising SonicWall Safe Cellular Entry (SMA) home equipment, which sit on the fringe of enterprise networks and handle and safe entry by cell units.

    The focused units are finish of life, that means they not obtain common updates for stability and safety. Regardless of the standing, many organizations proceed to depend on them. That has left them prime targets by UNC6148, the title Google has given to the unknown hacking group.

    “GTIG recommends that each one organizations with SMA home equipment carry out evaluation to find out if they’ve been compromised,” a report revealed Wednesday stated, utilizing the abbreviation for Google Risk Intelligence Group. “Organizations ought to purchase disk pictures for forensic evaluation to keep away from interference from the rootkit anti-forensic capabilities. Organizations might have to interact with SonicWall to seize disk pictures from bodily home equipment.”

    Missing specifics

    Many key particulars stay unknown. For one factor, the assaults are exploiting leaked native administrator credentials on the focused units, and thus far, nobody is aware of how the credentials have been obtained. It’s additionally not identified what vulnerabilities UNC6148 is exploiting. It’s additionally unclear exactly what the attackers are doing after they take management of a tool.

    The dearth of particulars is basically the results of the performing on Overstep, the title of customized backdoor malware UNC6148 is putting in after preliminary compromise of the units. Overstep permits the attackers to selectively take away log entries, a method that’s hindering forensic investigation. Wednesday’s report additionally posits that the attackers could also be armed with a zero-day exploit, that means it targets a vulnerability that’s at the moment publicly unknown. Potential vulnerabilities UNC6148 could also be exploiting embrace:

    • CVE-2021-20038: An unauthenticated distant code execution made doable by a reminiscence corruption vulnerability.
    • CVE-2024-38475: An unauthenticated path traversal vulnerability in Apache HTTP Server, which is current within the SMA 100. It may be exploited to extract two separate SQLite databases that retailer consumer account credentials, session tokens, and seed values for producing one-time passwords.
    • CVE-2021-20035: An authenticated distant code execution vulnerability. Safety agency Arctic Wolf and SonicWall reported in April that this vulnerability was underneath energetic exploitation.
    • CVE-2021-20039: An authenticated distant code execution vulnerability. There have been stories that this vulnerability was underneath energetic exploitation to put in ransomware in 2024.
    • CVE-2025-32819: An authenticated file deletion vulnerability that may be exploited to trigger a focused machine to revert the built-in administrator credentials to a password in order that attackers can acquire administrator entry.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Dozens of Red Hat packages backdoored through its official NPM channel

    June 2, 2026

    CFTC seeks injunction in Kalshi Rhode Island dispute

    June 2, 2026

    Florida crackdown targets illegal machines in Sarasota

    June 2, 2026

    Hawthorne bankruptcy dispute targets Illinois racing funds

    June 2, 2026

    Kalshi debuts regulated crypto perpetual futures

    June 2, 2026

    Manchester gambling raid sparks wider enforcement focus

    June 2, 2026

    Comments are closed.

    Editors Picks

    Dozens of Red Hat packages backdoored through its official NPM channel

    June 2, 2026

    Microsoft Build 2026 Kicks Off Today: Live Updates on Copilot AI and Dev Tools

    June 2, 2026

    From Regex to Vision Models: Which RAG Technique Fits Which Problem

    June 2, 2026

    Rehumanizing global health care with agentic AI

    June 2, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    ANZ bank has killed off its venture arm, 1835i

    October 1, 2025

    2026 Rivian R1S review: Balanced luxury electric SUV

    May 16, 2026

    Kalshi class action lawsuit claims its running a rigged sportsbook

    November 29, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.