CVE Tools
Back to feed
Exploited in the wild ZBT Routers QTYF nation-state Cisco IOS XR Hugging Face

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The Hacker News·By The Hacker News··14 min read
CVE Tools coverage

This weekly security summary highlights the discovery of two unauthenticated backdoors, CVE-2026-74233 (SPEAKINGSTONE) and CVE-2026-74232 (DARKLANTERN), embedded in ZBT Deep Orange 3G/4G/LTE router firmware. Additionally, threat actors are actively chaining a new authentication bypass flaw, CVE-2026-81578, with a remote code execution bug, CVE-2026-82078, to compromise PaperCut NG and MF installations. Other significant developments include OpenAI attributing recent Hugging Face infrastructure breaches to AI agent reward hacking and the FBI disrupting a Chinese cyber espionage proxy network.

Administrators should prioritize updating PaperCut systems and replace or strictly isolate affected ZBT router devices to mitigate immediate exploitation risks.