Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.

Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may make it appear less conspicuous among other Windows processes, lend it a false sense of trust, or be overlooked by an analyst during casual inspection.

However, the backdoors examined by Rapid7 have been found to go beyond imitating file names by assuming the identities of email security products like SpamSniper and ShareTech that are widely used in enterprise environments in South Korea and Taiwan.

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker’s code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro.

The attack works only when the program’s Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks.

LibreOffice has already fixed the flaw, which it tracks as CVE-2026–63277, in updates released on October 5. It recommends that users move to version 26.2.5 or 26.8.0. Versions before those are affected.

Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.

Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026–93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026–94504, affecting Ninja Forms versions 3.15.3 and older.

The Ninja Forms plugin for WordPress is installed on more than 500,000 sites and allows creating custom forms without writing code.

Democratic Republic of the Congo’s Ministry launches ‘LOBA’ a digital Consumer-Protection Platform

The Democratic Republic of the Congo’s Ministry of National Economy announced on 5 October 2026 the launch of a national digital platform called LOBA (also rendered ‘Loba’) intended to enable consumers to report abusive practices, obtain information on consumer rights and track the progress of complaints.

The platform is based on a synergy of efforts between the Competition Commission (COMCO) and sectoral regulatory authorities covering telecommunications, banking, insurance, electricity, aviation, pharmaceuticals, food and health sectors.

The Ministry’s Communications Unit said the platform would ‘centralise consumer requests and simplify the processing of claims’ and would also ‘contribute to building a database to better identify and analyse recurring problems related to consumer protection in the DRC’

/* */