Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

In other news: Hackers breach Latvia's road traffic agency; US warns of AI attacks on Siemens PLCs; hacking tool enrolls an attacker's passkey to your account.

Share
Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

This newsletter is brought to you by Socket Security. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

A team of American academics have found source code overlaps between the products of a Chinese tech company and the country's Great Firewall traffic filtering and censorship system.

According to research presented at this year's USENIX security conference, the Chinese government is using the Geedge Networks Tiangou Secure Gateway (TSG) device as one of the Great Firewall's three known traffic filtering capabilities.

Researchers linked Geedge's device to the Great Firewall after more than 100,000 files leaked from Geedge's network last year.

The leak included databases for Geedge's Jira and Confluence portals, but also all its Git source code repositories, containing commit history going back to November 2024.

Researchers used the source code and commit history to reconstruct Geedge TSG firmware, which then allowed them to match TSG traffic filtering capabilities to some sections of the Great Firewall and its behavior.

Another major conclusion from studying the leaked files was that Geedge's TSG device is just as insecure and poorly coded as Western counterparts.

"Finally, TSG’s complexity and flexibility are a double-edged sword: while they pose a significant obstacle to circumvention, they also undermine code maintainability and correctness. We have witnessed firsthand the ad hoc and non-robust composition of TSG: core components such as SAPP and its protocol plugins are written in memory-unsafe C; the system continues to rely on transitional solutions like Stellar-on-SAPP; and code is copied from several third parties. The Jira tickets corroborate this patchwork development process; we detail an example of an upgrade to the AppSketch database causing SAPP to restart, underscoring a lack of code verification."

Researchers believe the leaked code, its poor quality, and abundance of bugs could be abused by Great Firewall circumvention tools in the future.

While the leak exposed the TSG source code, it also exposed Geedge's export business as well. Reports shortly after the leak last year confirmed the company was exporting its internet censorship tools to a bunch of other countries, such as Kazakhstan, Ethiopia, Pakistan, and Myanmar. [Additional coverage for this topic in InterSecLabs, Amnesty International, Justice for Myanmar

Risky Business Podcasts

The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and special guest co-host Dmitri Alperovitch at the helm!


Breaches, hacks, and security incidents

Hackers breach Latvia’s road traffic agency: Hackers have stolen the personal details of 1.2 million Latvian citizens from the country's road traffic agency. The stolen data includes personal information, payment receipts, license plate details going back to 2008. State officials have warned citizens to be on the look-out for possible scams. The CSDD leadership has resigned following the hack. [CSDD // CERT LV // Jauns // BNN News // The Record]

Sakura discloses breach: Japanese cloud service provider Sakura Internet says hackers have accessed the accounts of 583 customers of its server rental business. In addition, the hackers also stole data of 1.3 million companies and individuals stored in its sales management system. The incident took place earlier this month and Sakura has not yet attributed the intrusion. [Piyolog // Sakura Internet]

ClarityCheck leak: More than nine million biometric facial images have leaked because of a misconfigured server from reverse image search service ClarityCheck. [ExpressVPN]

T-Mobile cut cables to prevent hacks: T-Mobile staff had to physically cut an internet cable to a compromised system to prevent Chinese hacking group Salt Typhoon from moving further into its network. [Bloomberg]

TaxAct leak: Hackers have leaked 450,000 records from the alleged 2 million they stole from the TaxAct tax preparation software. [DataBreaches.net]

Applebee's franchise leak: Apple American Group, the largest Applebee’s franchise operator, has disclosed a security breach. [CyberInsider]

Alation reports breach: AI file and search indexing company Alation has disclosed a security breach that took place earlier this week. [TechCrunch]

AI, general tech, and privacy

Windows device recovery guide: Two years after the CrowdStrike IT outage of 2024, Microsoft has published a guide on how to quickly recover IT systems down from a mass-disruption. [Microsoft]

Bot traffic exploits RAM shortage: Scalping bots are now accounting for more than 90% of the traffic on online shops selling DDR5 RAM these days. [Jérôme Segura on LinkedIn]

YouTube updates view counts: Google is updating how view counts work on YouTube. Instead of a minimum watch time per video, a view count will be considered every video played from the first frame. This is expected to boost view counts, which have been declining on the platform. [Google]

Court delays Google-Spirit data acquisition: A bankruptcy court has put a hold on Google's acquisition of Spirit Airlines' data after a complaint from former employees who wanted to make sure PII information was removed from the dataset. [RuntimeWire]

Government, politics, and policy

Calls to designate AI as critical infrastructure: A US industry group named the Americans for Responsible Innovation is lobbying the Trump administration to designate AI as critical infrastructure. [ARI // CyberScoop]

In this Risky Business sponsor interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default.

Arrests, cybercrime, and threat intel

US warns of AI attacks on Siemens PLCs: CISA and the FBI have urged US organizations to secure Siemens programmable logic controllers. The agencies say threat actors are using AI to conduct reconnaissance and develop exploitation scripts. The attackers are specifically focusing on the Siemens S7 PLC series. CISA and the FBI have urged organizations to remove the PLCs from the internet and strengthen access controls. [CISA // FBI]

StubMaker expands to npm: StubMaker, a campaign of malicious RubyGems packages, has now expanded to npm. [OpenSourceMalware]

Rust supply chain attack: Hackers have compromised a popular Rust developer and injected malware in three of his Rust libraries in a supply chain attack on Thursday. The malicious libraries were live only for 23 minutes but one of the three was Arrayref, a library with almost 5 million weekly downloads. The Rust security team has since removed the malicious versions and locked the developer's account. According to cloud security firm Wiz, the attackers' infrastructure overlap with other North Korean operations. [Aikido // SafeDep // Semgrep // Socket Security // Step Security // Wiz]

Malicious Firefox add-ons steal crypto & creds: Mozilla has removed 77 malicious Firefox extensions from its add-ons store that stole crypto-wallet seed phrases and browser credentials. Most of the extensions mimicked crypto-wallets, Web3 tools, and sports score-keeping tools. According to Socket Security, they all shared the same backend infrastructure and source code components. [Socket Security]

Collaboration phishing explodes: Phishing carried out via collaboration platforms has quadrupled over the past calendar year, according to Palo Alto Networks. [Palo Alto Networks]

Peer2Profit feeds AstroProxy: Security researchers have linked the Peer2Profit passive income "app" to the backend of the AstroProxy residential proxy service. [Silent Push]

UAT-10147 profile: Cisco looks at an e-crime group that's been hacking internet-exposed Windows and Linux servers for SEO fraud and data theft. [Cisco Talos // Cisco Talos]

DOUBLOON DREDGER profile: The team at Sublime has published a profile of Doubloon Dredger, an e-crime group using the EvilTokens phishing service for device code phishing. [Sublime Security]

Hacker targets security researcher: A threat actor has targeted security researchers who attended the BlackHat and DEFCON security conferences. The attacker has posed as a marketing director at a cryptocurrency news outlet to trick victims into running malware. They were seen approaching several individuals who posted on Twitter about the two conferences. Security firm Huntress discovered the campaign after one of its researchers was targeted. [Huntress]

Malware technical reports

Manic Android banking trojan: Mobile security firm ThreatFabric has discovered a new Android banking trojan with a strong focus on Ukraine. Named Manic, the trojan can target Ukrainian banks, government agencies, identity services, and local messaging applications. ThreatFabric says the trojan sits at the interception of a banking trojan and spyware. Besides showing phishing overlays, it can also steal local credentials and exfiltrate data through a local WiFi mesh network. [ThreatFabric]

ToxicPanda 2.0: ToxicPanda, an Android banking trojan spotted in 2024, has now reached version 2.0. [Zimperium]

Grandoreiro goes to Mexico: After surviving a law enforcement takedown in 2024, the Grandoreiro banking malware has now been spotted being used to target Mexican banks. [Acronis]

Balonx Sistema PhaaS: Researchers have discovered a new phishing-as-a-service platform named Balonx Sistema that was built specifically for the Mexican market. Right now, it can target over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities. [Group-IB]

iAuthFlow toolkit enrolls an attacker's passkeys: A threat actor has developed and is selling a phishing toolkit that can automatically enroll an attacker's passkey into a victim's account after a successful phish. The passkey is meant to allow future access to the account in case the victim changes their password or revokes active sessions. The toolkit—named iAuthFlow v2—is sold on hacking forums for $10,000 and supports passkey enrollment on Google, Microsoft, LinkedIn, and iCloud. [AbnormalAI]

N4D Mesh Controller: DataDog looks at a Linux malware strain used to target MCP and other internet-exposed servers. [DataDog]

ErrTraffic: ErrTraffic, a MaaS that lets you build ClickFix-style lures appears to be enjoying a huge spike in popularity. [eSentire]

Clop's new custom web shell: ReliaQuest's John Dilgen and Connor Short have published a report on Clop's new mass exploitation campaign targeting PTC Windchill servers and the new custom web shell they've been deploying for initial access. [ReliaQuest]

PlikanLocker: Researchers have spotted a new ransomware strain that encrypts a user's files and communicates with a Telegram C2. [Point Wild]

More ValleyRAT: Looks like SilverFox is back to its old self despite the recent arrests in China of some of its members. There's a ton of campaigns spreading its signature ValleyRAT, including this one targeting Indian businesses with tax-related lures. [Himasnhu Anand]

In this Soap Box edition of the Risky Business podcast Patrick Gray chats with Socket founder Feross Aboukhadijeh about how to measure the reachability of vulnerabilities in applications. It's great to know there's a CVE in a library you're using, but it's even better if you can say whether or not that vulnerability actually impacts your application. 

APTs, cyber-espionage, and info-ops

APT37's NarwhalRAT: New IOCs have been published related to APT37's NarwhalRAT and its May campaigns. [WhoisXML API // CircleID // Blackorbird]

North Korean crypto-to-fiat activity: While we have a ton of reports on how North Korea hacks crypto-exchanges, RUSI takes a look at how these operations are converting the stolen crypto into fiat currency, a far-less glamourous part of their operation, but just as crucial. [RUSI]

Russia's new-age phishing ops: Google's Mandiant division looks at three Russian APTs and how their phishing operations are changing and moving towards targeting OAuth flows, IM account takeovers,  and device codes. [Google]

ITG27 (Mustang Panda): Like a good neighbour, China's trying to hack India's energy sector for espionage purposes. The attack has been linked to ITF27, IBM's name for Mustang Panda. [IBM]

SilkParasite: A suspected Chinese APT group has been seen hacking government bodies across Central Asia using an assortment of AI-assisted malware, such as DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, NodeEdgeRAT, and more. [Bitdefender]

Vulnerabilities, security research, and bug bounty

Security updates: Atlassian, Axis, BeyondTrust, Cisco, Citrix, Chrome, Rockwell Automation, Splunk.

Cloudflare saw no Spectre attacks: Internet infrastructure company Cloudflare has not seen any evidence of active exploitation of the Spectre CPU vulnerabilities over the last three years. The company has recently re-evaluated its defenses and rolled out new protections to account for new Spectre attack variants. Its primary defense is a feature called Dynamic Process Isolation that isolates malicious-looking scripts into their own processes. The feature will now also isolate any long-lived executions and I/O-heavy workloads, which are tell-tale signs of a Spectre attack. [Cloudflare]

Campaign targets Zimbra bug: Hackers are exploiting a recently patched vulnerability in Zimbra Collaboration Suite. The vulnerability was patched at the end of July. It allows attackers to run commands on the Zimbra server via a command injection in the SNMP monitoring component. The attacks were detected by CERT Poland. [CERT Polska // Zimbra patches]

GitLab bug enters exploitation: Threat actors started exploiting a recent GitLab vulnerability two days after disclosure. Attacks started after proof-of-concept code was posted online. The vulnerability allows unauthenticated attackers to remotely modify or delete GitLab projects or user data. [SecurityWeek // CSIRT Italia // CVE-2026-19478]

MLflow exploitation: And speaking of exploitation there's also an SSRF bug being exploited in MLflow AI servers, and two bugs in TrueConf, a video conferencing software widely used across Russia. [CISA // CISA // MLflow patches]

CDN Tsunami attack: Academics have discovered a new DDoS technique that can take websites and resources hosted on CDN infrastructure. The attack exploits CDN providers that support HTTP/3 connections from regular internet users but translate the traffic to the old HTTP/1 protocol internally. The CDN Tsunami attack works by sending a small amount of HTTP/3 traffic to the CDN, which then sends a huge amount of HTTP/1 data to its customers' sites. The research team says that only two CDNs have deployed mitigations since being notified. [arXiv]

Researchers lose access to OpenAI TAC: Several security researchers lost access to OpenAI's Trusted Access for Cyber (TAC) program this week due to an error. The TAC program grants researchers access to the company's frontier cyber models for research purposes. This includes access to models like ChatGPT Cyber. OpenAI didn't say what caused the error, but asked researchers to reapply and complete the verification process again. [TechCrunch]

Infosec industry

Threat/trend reports: EAST (PDF), FitchRatings, NCSI, and WhoisXML API have recently published reports and summaries covering various emerging threats and industry trends.

New tool—AWSHound: SpecterOps has open-sourced AWSHound, a tool that collects AWS IAM/authorization data and builds a BloodHound-like OpenGraph.

New tool—ADR: Uber has released ADR, an enterprise security system for AI agents, to help organizations secure employee-facing agents such as Cursor, Claude Code, and Codex.

Risky Business podcasts

In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about President Donald Trump's memo enlisting the US private sector to tackle cybercriminals.

In this episode of Risky Business Features, James Wilson chats with PortSwigger’s Director of Research James Kettle about using an LLM to develop genuinely new attack techniques.