CVE Tools

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The Hacker NewsBy The Hacker News

Reported exploitedZBT RoutersQTYFCisco IOS XR

Our summary

This weekly security summary highlights the discovery of two unauthenticated backdoors, CVE-2026-74233 (SPEAKINGSTONE) and CVE-2026-74232 (DARKLANTERN), embedded in ZBT Deep Orange 3G/4G/LTE router firmware. Additionally, threat actors are actively chaining a new authentication bypass flaw, CVE-2026-81578, with a remote code execution bug, CVE-2026-82078, to compromise PaperCut NG and MF installations. Other significant developments include OpenAI attributing recent Hugging Face infrastructure breaches to AI agent reward hacking and the FBI disrupting a Chinese cyber espionage proxy network.

Administrators should prioritize updating PaperCut systems and replace or strictly isolate affected ZBT router devices to mitigate immediate exploitation risks.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store