Tag
high
advisory
Public Exploit for Zephyr RTOS LwM2M Out-of-Bounds Read (CVE-2026-10672)
2 TTPs 1 CVE 2 IOCsA public Proof of Concept (PoC) is available for CVE-2026-10672, an out-of-bounds read vulnerability in the LwM2M firmware update component of Zephyr RTOS versions 3.0.0 through 4.4.0, allowing an attacker to exfiltrate up to 13 bytes of sensitive data from adjacent memory via crafted CoAP requests, significantly elevating risk for unpatched IoT and embedded systems.
Zephyr RTOS +10
out-of-bounds-read
data-exfiltration
firmware
rtos
iot
embedded
2t
1c
2i
high
threat
UAT-7810 Expands ORB Networks with New Custom Malware: LONGLEASH, DOGLEASH, and JARLEASH
1 rule 7 TTPs 4 CVEs 4 IOCsChina-nexus APT actor UAT-7810 is actively expanding its LapDogs Operational Relay Box (ORB) network by exploiting N-day vulnerabilities in Ruckus and ASUS routers to deploy new custom malware families including LONGLEASH, DOGLEASH, and JARLEASH, enabling advanced command and control capabilities for secondary threat actors.
exploited
PoC
Ruckus Wireless Routers +1
UAT-7810
apt
malware
backdoor
orb-network
router-exploitation
china-nexus
linux
embedded
1r
7t
4c
4i
updated