Categories
News Review

50 biggest UK news websites: Top four commercial newsbrands neck and neck

Categories
News Review

Dear Abby: Is it rude to keep non-relatives out of my family reunion?

Dear Abby gives advice to a reader who isn’t sure about letting extra guests attend a family reunion.
Categories
News Review

Elon Musk reveals result of Tesla self-driving tests in Austin

Musk has returned to Tesla and his other businesses full-time after working with the White House on federal spending cuts.
Categories
News Review

Mother shoots convicted child molester as he tried to rape…

Categories
News Review

Paul Blackburn could be part of Mets’ six-man rotation starting next…

Paul Blackburn’s next appearance in a game likely will be in a Mets uniform, instead of for one of the organization’s minor league affiliates.
Categories
News Review

Ukraine-Russia war live: Trump gives Putin ‘deadline’ to end the war

Donald Trump appears to have set Vladimir Putin a deadline for ending the war in Ukraine.
Categories
News Review

Elon Musk announces departure from US President Trump’s administration

The tech mogul who helped bankroll US President Trump’s second run for the White House has left the administration. Elon Musk became a polarizing figure as t…

Categories
News Review

CNBC Daily Open: Trump’s ‘reciprocal’ tariffs face an uncertain future — and that’s good for markets and businesses

Trump’s been accused of walking back on his trade policies. Now, a federal court has struck down his “reciprocal” tariffs — the same ones he put on hold.
Categories
News Review

New AyySSHush botnet compromised over 9,000 ASUS routers, adding a persistent SSH backdoor.

GreyNoise researchers warn of a new AyySSHush botnet compromised over 9,000 ASUS routers, adding a persistent SSH backdoor.

GreyNoise discovered the AyySSHush botnet has hacked over 9,000 ASUS routers, adding a persistent SSH backdoor.

“Using an AI powered network traffic analysis tool we built called SIFT, GreyNoise has caught multiple anomalous network payloads with zero-effort that are attempting to disable TrendMicro security features in ASUS routers, then exploit vulnerabilities and novel tradecraft in ASUS AiProtection features on those routers.” states GreyNoise.

The threat intelligence firm uncovered a stealth campaign on March 18, 2025, where attackers gained persistent access to thousands of internet-exposed ASUS routers. Using subtle tactics, like auth bypasses and abuse of legit settings, the attackers avoid detection while keeping control, even after reboots or updates. Though attribution remains unclear, the campaign shows signs of a skilled, well-funded adversary building a covert botnet infrastructure.

“GreyNoise has identified an ongoing exploitation campaign in which attackers have gained unauthorized, persistent access to thousands of ASUS routers exposed to the internet.” reads the report published by GreyNoise. “The attacker’s access survives both reboots and firmware updates, giving them durable control over affected devices.”

The payloads observed by the experts only target ASUS RT-AC3100 or RT-AC3200 with an Out-Of-Box configuration.

GreyNoise also found a payload exploiting the authenticated command injection flaw CVE-2023-39780 in ASUS RT-AX55 v3.0.0.4.386.51598 to execute arbitrary system commands.

The attackers exploit the command injection flaw to add their SSH key and enable access on port 53282, ensuring persistent backdoor access across reboots and updates.

“This payload leverages built-in ASUS router features to enable SSH on both LAN and WAN, bind it to TCP/53282, and add an attacker-controlled public key.” ‍reads the full technical analysis published by GreyNoise.  “Because this key is added using the official ASUS features, this config change is persisted across firmware upgrades. If you’ve been exploited previously, upgrading your firmware will NOT remove the SSH backdoor.”

As of May 27, nearly 9,000 ASUS routers are confirmed compromised, based on Censys data. Despite the scale, only 30 related requests were observed over three months, highlighting how stealthy the campaign is.

GreyNoise published a list of four IP addresses associated with the botnet’s campaign as Indicators of Compromise.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, AyySSHush botnet)

The post New AyySSHush botnet compromised over 9,000 ASUS routers, adding a persistent SSH backdoor. first appeared on Audio Posts – audio-posts.com.

Categories
News Review

Russia Threatens the U.S. with War — Russian People Revolt in Moscow to Stop New War Decision!

🇺🇸 RUSSIA THREATENS WAR — TRUMP RESPONDS! | Ukraine Fights Back With AI Weapon | CIVIL UNREST IN MOSCOW🔥 May 26, 2025 — Russia launched its largest drone …