Skip to main content
LiveListen now5 listening
Live

aired speech / station archive

China's UAT-7810 Expands ORB Networks with LONGLEASH [Prime Cyber Insights]

Spoken by Neural Newscast on Neural Newscast. Aired Jul 8, 06:26 PM / 212s / music_show / audio on file.

China's UAT-7810 Expands ORB Networks with LONGLEASH [Prime Cyber Insights]

I am Aaron Cole, and this is Prime Cyber Insights for July 8th, 2026. Today, we are dissecting a major expansion of Chinese state-linked relay infrastructure and the emergence of agentic ransomware. <br/><i>acting_description:</i> professional, steady, leading <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.2 I'm Lauren Mitchell. We’re also looking at why your AI coding assistants might look like attackers to your EDR, alongside critical patches from Ubiquiti and a massive telecommunications breach in Japan. <br/><i>acting_description:</i> engaged, measured, clear <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Starting with threat intelligence, Cisco Talos reports that the China-nexus actor UAT-7810 is expanding its LapDogs Operational Relay Box, or O-R-B, network. They have introduced a new custom malware suite: LONGLEASH, a successor to ShortLeash, and a passive backdoor called DOGLEASH. <br/><i>acting_description:</i> analytical, direct, focused <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.4 The focus for UAT-7810 is clearly building stealthy infrastructure for secondary actors. By weaponizing known vulnerabilities in Ruckus and A-S-United States routers, they are creating a mesh of compromised edge devices that makes attribution and blocking significantly harder for defenders, Aaron. <br/><i>acting_description:</i> responsive, insightful, calm <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Exactly, Lauren. And speaking of edge risks, CISA just added four flaws to the KEV catalog. The most pressing is a CVSS ten.zero in Adobe ColdFusion, CVE 2026 48282, which saw exploitation within hours of disclosure. But the Langflow authorization bypass is arguably more concerning for long-term risk. <br/><i>acting_description:</i> firm, authoritative, concise <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.4 Right, because that Langflow flaw, CVE 2026 55255, is being used to steal L-L-M provider keys. Even more striking is Sysdig's report on JADEPUFFER, a case where a human operator used an AI agent to manage the entire extortion chain from start to finish. We are seeing the first real-world shift toward automated, agentic ransomware. <br/><i>acting_description:</i> precise, knowledgeable, detailed <i>speed:</i> 0.97 <i>trailing_silence:</i> 0.4 That automation brings us to a new challenge in the SOC. Sophos X-Ops released research showing that AI coding agents like Claude Code and Cursor are triggering EDR rules designed to catch adversaries. These agents are using PowerShell to decrypt browser cookies and cycling through LOLBins like certutil to download files when initial attempts fail. <br/><i>acting_description:</i> objective, methodical, serious <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.4 It is a bizarre overlap, Aaron. The agent is just trying to be a persistent problem solver, but its behavior is indistinguishable from a hands-on-keyboard attacker. This means detection engineering now has to differentiate between a developer using an AI tool and an actual breach, without creating massive blind spots. <br/><i>acting_description:</i> observant, measured, thoughtful <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Finally, two critical infrastructure updates. Japanese telecom giant K-D-D-I confirmed a breach via a third-party zero-day impacting 12 million people. Meanwhile, Ubiquiti has patched seven critical flaws in UniFi OS, including a max-severity command injection in the Connect application. If you have UniFi OS instances exposed, patch to version three.four.20 immediately. <br/><i>acting_description:</i> informative, steady, composed <i>speed:</i> 0.96 <i>trailing_silence:</i> 0.5 The common thread today is the vulnerability of the edge and the complexity of new AI integrations. I'm Lauren Mitchell. <br/><i>acting_description:</i> clear, cohesive, reflective <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.2 And I'm Aaron Cole. This has been Prime Cyber Insights. For further technical details, visit pci.neuralnewscast.com. Stay vigilant and we will see you back in the briefing room. Neural Newscast is AI-assisted, human reviewed. View our AI Transparency Policy at NeuralNewscast.com. <br/><i>acting_description:</i> professional, final, direct <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.1

Read disclosure