⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
Reported exploitedZBT RoutersQTYFCisco IOS XROur summary
This weekly security summary highlights the discovery of two unauthenticated backdoors, CVE-2026-74233 (SPEAKINGSTONE) and CVE-2026-74232 (DARKLANTERN), embedded in ZBT Deep Orange 3G/4G/LTE router firmware. Additionally, threat actors are actively chaining a new authentication bypass flaw, CVE-2026-81578, with a remote code execution bug, CVE-2026-82078, to compromise PaperCut NG and MF installations. Other significant developments include OpenAI attributing recent Hugging Face infrastructure breaches to AI agent reward hacking and the FBI disrupting a Chinese cyber espionage proxy network.
Administrators should prioritize updating PaperCut systems and replace or strictly isolate affected ZBT router devices to mitigate immediate exploitation risks.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.