New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.

The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

A Philosopher’s One-Word Theory to Explain Why the World Feels So Weird

A Philosopher’s One-Word Theory to Explain Why the World Feels So Weird Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 31.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 34.12.86.3 — 2814 requests (recent log) 89.167.35.212 — 980 requests (recent log) 34.68.39.29 — 668 requests (recent

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and