cardoor[.]cnMQTT server host for DoFun system app TWCore
ThreatNoir Weekend Brief — August 23
Morning Review in IT Security — August 23, 2026
The cybersecurity landscape continues to face significant threats across multiple vectors on August 23, 2026. Today's briefing covers critical supply-chain attacks targeting automotive systems and open-source repositories, widespread exposure of cloud credentials, and active exploitation of enterprise communications platforms requiring immediate federal response.
Hackers Infect Android Car Head Units with Proxy Botnet Malware
A sophisticated supply-chain attack is actively targeting Android-based car head units through a trojanized device-update application. The malware leverages legitimate update mechanisms to compromise vehicles, enrolling them into a proxy botnet infrastructure or leveraging them for ad fraud operations. This attack demonstrates the expanding threat surface in connected vehicle ecosystems and the dangers of relying on update channels without proper verification. Source: Bleeping Computer
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers have identified fourteen malicious npm packages designed to distribute RedC2 4.0, an artificial intelligence-powered Linux backdoor with advanced command-and-control capabilities. The trojanized packages masquerade as legitimate calendar and streak utilities, executing a bundled binary as a detached background process when loaded. This campaign underscores the persistent vulnerability of the open-source software supply chain and the emerging threat of AI-enhanced malware infrastructure. Source: The Hacker News
Hundreds of Leaked AWS Keys Give Full Control Over Corporate Accounts
More than 9,300 Amazon Web Services access keys exposed publicly between August 2022 and August 2026 remain active and valid, granting attackers complete control over affected corporate cloud environments. The extended validity period of these credentials represents a critical risk window during which threat actors can maintain persistent access to sensitive infrastructure and data. Organizations must prioritize comprehensive auditing of their AWS credential exposure and implement immediate rotation protocols. Source: Bleeping Computer
CISA Orders Feds to Patch Actively Exploited TrueConf Server Flaws
The U.S. Cybersecurity and Infrastructure Security Agency has mandated that federal agencies prioritize patching two actively exploited vulnerabilities in TrueConf Server, a self-hosted communications platform. The vulnerabilities CVE-2026-72529 and CVE-2026-72530 are being actively weaponized in the wild, with attackers deploying backdoor malware to compromised systems. The active exploitation status and federal mandate underscore the severity of these flaws and the urgency of immediate remediation across all affected deployments. Source: Bleeping Computer
Today's threat landscape reflects a coordinated escalation across supply-chain vectors, cloud infrastructure, and enterprise communications platforms. Organizations must implement immediate defensive measures including supply-chain verification, credential rotation, and vulnerability management protocols to mitigate these active threats.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- RedC2 4.0AI-powered Linux backdoor
- RedShell Linux beaconLinux variant of the RedC2 4.0 beacon
- Critical missing authentication flaw allowing remote script execution.
- Critical flaw allowing unauthenticated remote code execution via code injection.
- Exploitation of CVE-2026-72529 and CVE-2026-72530 allows arbitrary script/command execution.
- backdoor malwareDeployed by Head Mare group via trojanized TrueConf client installers.