:

CHINESE HACKERS DEPLOY LONGLEASH MALWARE

SECURITY DESK1 MIN READ
TUE, JUL 7, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Chinese threat actors tracked as UAT-7810 are actively developing the LONGLEASH malware to expand their Operational Relay Box (ORB) network. The campaign primarily targets unpatched Ruckus routers and other internet-facing networking devices.

UAT-7810 operators are leveraging LONGLEASH to compromise networking infrastructure and establish relay nodes within their ORB network. The malware targets vulnerabilities in Ruckus routers, exploiting devices that lack security patches. Operational Relay Boxes serve as intermediary nodes for command-and-control communications and lateral movement across compromised networks. By expanding their ORB infrastructure, the threat actors increase their operational flexibility and resilience. Security researchers recommend organizations immediately patch Ruckus devices and segment network access to limit exposure. Administrators should audit internet-facing networking equipment for unauthorized access and monitor for suspicious relay traffic. The campaign reflects broader trends of state-sponsored actors targeting network infrastructure to establish persistent footholds within target organizations.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A massive data breach at an unspecified car rental company exposed customer driver's licenses and personal information within hours of rental. The FBI is investigating the incident as data stolen from customers appears for sale online.

2H AGOIndustry Desk

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin exposes WordPress sites to remote code execution and complete takeover by unauthenticated attackers.

5H AGOIndustry Desk

An identity theft search site claimed to possess over 150 million driver's license photos stolen from a major ID verification service. The crime site has since been shut down.

5H AGOSecurity Desk

Iran-linked hackers have compromised approximately 100 American water utilities in a sustained campaign targeting critical infrastructure. The EPA is allocating $11 million in funding to strengthen cybersecurity defenses across water systems.

8H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.