The Load Balancer Kept Working While a Hidden Backdoor Stole Credentials

Two South Korean organisations kept serving traffic through HAProxy while a hidden plugin stole credentials, hijacked sessions and altered pages for selected visitors.
Vulnerabilities, defensive security, architecture and operational security.

Two South Korean organisations kept serving traffic through HAProxy while a hidden plugin stole credentials, hijacked sessions and altered pages for selected visitors.

A modified ScreenConnect client can transfer and run malware when a new support session connects. The first infection still needs social engineering, but one trusted remote session can become the bridge to the next PC.

ASUS Control Center can manage an entire fleet. One critical flaw can turn that reach against every server, PC and workstation connected to it, without requiring an account or a click.

Three MikroTik RouterOS vulnerabilities are now tied to active exploitation, although CISA has not linked CVE-2026-67277 to the documented MikroTrick chain. Patch immediately, then inspect exposed routers for compromise.

A clean patch report is no defence against StyleSmuggler. Sansec says attackers are using the unpatched flaw to install persistent backdoors on current Magento and Adobe Commerce releases.

Millions of messages a day used invisible Unicode characters to split high-signal finance words. Humans saw “funding.” Some security pipelines saw something else.

Four linked Cleo Harmony weaknesses let a low-privilege user cross SAML and token trust boundaries, become an administrator and reach operating-system command execution.

A PostgreSQL account trusted to replicate data could cross into the operating system. The flaw survived for 12 years, but exploitation still requires the powerful REPLICATION privilege.

FalconFlank turns CrowdStrike Falcon’s Office macro clean-up into a path from a low-privilege Windows account to SYSTEM. The public PoC has been independently reproduced.

A critical Cisco Nexus 9000 flaw exposes root-level remote code execution through TCP ports 43210 and 43211 on affected Silicon One switches.