Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Users of Zbtlink and white-labeled ZBT routers
Incident: Discovery of two factory-installed firmware implants (CVE-2026-74232, CVE-2026-74233) in ZBT routers.
Impact: Unauthenticated remote attackers can execute arbitrary commands as root, exfiltrate credentials, and hijack DNS.
Attacker: Unidentified threat actors
Analysis: Research has uncovered two distinct implants, SPEAKINGSTONE and DARKLANTERN, embedded in ZBT router firmware. One acts as a phone-home C2 beacon for surveillance, while the other opens a backdoor for direct inbound attacks. Both vulnerabilities provide unauthenticated root access, enabling complete device takeover and network exfiltration.
Recommendations: Replace affected ZBT and white-labeled routers with trusted hardware; Implement strict egress and ingress filtering on UDP ports 10000 and 9992; Audit network edge devices for unauthorized firmware implants and beacons
Source: The Hacker News / VulnCheck
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source