[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTaFxEON4HcR6mYQHrRbcFdB8kSVAfub7mXR9mSruPD4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"a97d74e0-eedc-4e88-af78-4a18575a36de","china-linked-apt-targets-unpatched-soho-routers-with-new-backdoor-suite","82402ce3-fbd3-49ea-bc83-f86570a336ed","China-Linked APT Targets Unpatched SOHO Routers with New Backdoor Suite","UAT-7810 is exploiting known, unpatched vulnerabilities in SOHO routers such as Ruckus devices to deploy sophisticated backdoors including LongLeash, DogLeash, and JarLeash. The root cause is a failure to apply available patches to internet-facing network appliances, leaving well-documented attack surfaces open to exploitation. SOHO routers are frequently overlooked in enterprise patch cycles despite being critical network entry points. This matters because compromised routers provide persistent, stealthy footholds that enable long-term espionage operations, often going undetected for extended periods.","**Immediate actions:**\n- Audit all SOHO and edge routers for firmware versions and apply vendor-released security patches immediately.\n- Conduct a vulnerability scan targeting internet-facing network appliances to identify devices running outdated or end-of-life firmware.\n- Isolate any routers suspected of compromise from the broader network pending forensic investigation.\n\n**Long-term improvements:**\n- Establish a formal patch management policy that explicitly includes network appliances, routers, and OT\u002FIoT devices.\n- Maintain a continuously updated asset inventory covering all network edge devices to ensure no appliance is excluded from patch cycles.\n- Implement network segmentation to ensure SOHO routers cannot directly reach sensitive internal systems or data repositories.\n\n**Detection measures:**\n- Deploy network traffic monitoring and anomaly detection on all edge devices to identify unusual outbound connections indicative of backdoor activity.\n- Collect and centralize syslog data from all routers and network appliances into a SIEM for correlation and alerting.\n- Subscribe to threat intelligence feeds tracking APT TTPs to receive early warning of campaigns targeting your router models.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 1: Inventory and Control of Enterprise Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-40: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST SC-7: Boundary Protection","NIST RA-5: Vulnerability Monitoring and Scanning","MITRE ATT&CK T1190: Exploit Public-Facing Application","MITRE ATT&CK T1542: Pre-OS Boot \u002F Implant","ISO\u002FIEC 27001 A.12.6: Management of Technical Vulnerabilities","ITIL: Change and Release Management","published","2026-07-08T16:20:24.485331+00:00","2026-07-08T16:20:24.368+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.securityweek.com\u002Fchina-linked-apt-expands-arsenal-with-new-leash-backdoors\u002F","china-linked-apt-expands-arsenal-with-new-leash-backdoors-4492dd","China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]