Widely used #DaemonTools disk app #backdoored in month long supply-chain attack

Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed #malicious updates from the servers of its developer, researchers said Tuesday.
#security #supplychain

https://arstechnica.com/security/2026/05/widely-used-daemon-tools-disk-app-backdoored-in-monthlong-supply-chain-attack/

Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack

Daemon Tools users: It's time to check your machines for stealthy infections, stat.

Ars Technica

Popular #LiteLLM #PyPI package #backdoored to steal #credentials , auth #tokens

The #TeamPCP #hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package on PyPI & claiming to have stolen data from hundreds of thousands of devices during the attack.

LiteLLM is an open-source #Python library that serves as a gateway to multiple large language model ( #LLM ) providers via a single #API.
#privacy #security #supplychain

https://www.bleepingcomputer.com/news/security/popular-litellm-pypi-package-compromised-in-teampcp-supply-chain-attack/

Popular LiteLLM PyPI package compromised in TeamPCP supply chain attack

The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package on PyPI and claiming to have stolen data from hundreds of thousands of devices during the attack.

BleepingComputer
another interesting detail with this SBT #military #crypto #device #backdoored by the #nsa is that it contains a weird virtual machine, this handles templating of messages and fixed point math, and uses only 2 data "registers" and a pointer register.

some interesting details, the #nsa #backdoored #phillips device runs a 8051 mcu. there's a print subroutine, that pops the return address from the stack, and prints the litteral chars from that address onwards until it finds a byte which has the top bit set. then it returns to the address after this last char. of course this is no calling-convention that any disassembler knows, so it throws them off.

2/n

The #NSA with the help of #philips #backdoored (again!) a european military messaging #device in the 80ies, a few years ago the fine people of the #cryptomuseum published everything they knew about it - including a #firmware dump:
https://www.cryptomuseum.com/crypto/philips/ua8295/

back then i #reverseEngineered this, and last week finally cleaned it up, and publish it today:

https://rad.ctrlc.hu/nodes/rad.ctrlc.hu/rad:z46AkAERuXAzqZcDRKvE7byRbkga1

also on the bad site: https://github.com/stef/UA-8295-NSA

update: it's a thread: 1/n

UA-8295

#Cocaine in Private Jets and Sex Toys: What the #FBI Found on its Secretly #Backdoored #Chat App

Private jets loaded with cocaine landing at an airport in #Germany. A #trafficker stuffing a racing sail boat with drugs and entering a tournament to blend in with other racers before speeding off. Vacuum-sealed layers of #methamphetamine inside solar panels. And nearly 60 kilograms of drugs hidden inside a shipment of sex toys.

https://www.404media.co/cocaine-in-private-jets-and-sex-toys-what-the-fbi-found-on-its-secretly-backdoored-chat-app/

Cocaine in Private Jets and Sex Toys: What the FBI Found on its Secretly Backdoored Chat App

New leaked documents show how the FBI convinced a judge to let its partners collect a mass of encrypted messages from thousands of phones around the world.

404 Media

Sellers of Anom, the FBI's Secret #Backdoored Phone, Plead Guilty

The court records released as part of the plea deals also provide new insight into how some of the phone sellers discussed drug #trafficking on their #Anom devices as well.
#privacy #security #backdoor

https://www.404media.co/sellers-of-anom-the-fbis-secret-backdoored-phone-plead-guilty/

Sellers of Anom, the FBI's Secret Backdoored Phone, Plead Guilty

The pleas mean that “Afgoo,” the person who provided the FBI with the backdoored encrypted phone company in the first place, likely won’t have to testify and have their identity revealed in court.

404 Media
Government to Name ‘Key Witness’ Who Provided FBI With Backdoored Encrypted Chat App Anom

A lawyer has pushed to learn the identity of the person who first created Anom, which the FBI used to read tens of millions of messages sent by organized criminals. The confidential human source may testify in court, too.

404 Media

1.3 million #Android -based #TV boxes #backdoored; researchers still don’t know how
#backdoor #security #privacy

https://arstechnica.com/?p=2049773

1.3 million Android-based TV boxes backdoored; researchers still don’t know how

Infection corrals devices running AOSP-based firmware into a botnet.

Ars Technica