{"id":52157,"date":"2023-06-01T14:14:21","date_gmt":"2023-06-01T14:14:21","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34682\/Researchers-Tell-Owners-To-Assume-Compromise-Of-Unpatched-Zyxel-Firewalls.html"},"modified":"2023-06-01T14:14:21","modified_gmt":"2023-06-01T14:14:21","slug":"researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/","title":{"rendered":"Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls"},"content":{"rendered":"<figure class=\"intro-image intro-left\"> <img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/05\/system-hacked-800x450.jpg\" alt=\"Researchers tell owners to \u201cassume compromise\u201d of unpatched Zyxel firewalls\"><figcaption class=\"caption\">\n<div class=\"caption-credit\">Getty Images<\/div>\n<\/figcaption><\/figure>\n<aside id=\"social-left\" class=\"social-left\" aria-label=\"Read the comments or share this article\"> <a class=\"comment-count icon-comment-bubble-down\" href=\"https:\/\/arstechnica.com\/information-technology\/2023\/05\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/?comments=1\"> <\/p>\n<h4 class=\"comment-count-before\">reader comments<\/h4>\n<p> <span class=\"comment-count-number\">25<\/span> <span class=\"visually-hidden\"> with <\/span> <\/a> <\/aside>\n<p> <!-- cache hit 12:single\/related:99e03b9ad214db4ef2f1c28dfb1472dd --><!-- empty --><\/p>\n<p>Firewalls made by Zyxel are being wrangled into a destructive botnet, which is taking control of them by exploiting a recently patched vulnerability with a severity rating of 9.8 out of a possible 10.<\/p>\n<p>\u201cAt this stage if you have a vulnerable device exposed, assume compromise,\u201d officials from Shadowserver, an organization that monitors Internet threats in real time, <a href=\"https:\/\/twitter.com\/Shadowserver\/status\/1662560845702807552\">warned<\/a> four days ago. The officials said the exploits are coming from a botnet that\u2019s similar to Mirai, which harnesses the collective bandwidth of thousands of compromised Internet devices to knock sites offline with distributed denial-of-service attacks.<\/p>\n<p>According to <a href=\"https:\/\/dashboard.shadowserver.org\/statistics\/honeypot\/monitoring\/vendor\/?category=anomaly&amp;statistic=unique_ips&amp;d1=2023-05-21&amp;d2=2023-05-31\">data from Shadowserver<\/a> collected over the past 10 days, 25 of the top 62 Internet-connected devices waging \u201cdownstream attacks\u201d\u2014meaning attempting to hack other Internet-connected devices\u2014were made by Zyxel as measured by IP addresses.<\/p>\n<figure class=\"image shortcode-img full full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/05\/attacking-devices.jpg\" width=\"1410\" height=\"820\"><\/figure>\n<h2>A 9.8-severity vulnerability in default configurations<\/h2>\n<p>The software bug used to compromise the Zyxel devices is tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-28771\">CVE-2023-28771<\/a>, an unauthenticated command-injection vulnerability with a severity rating of 9.8. The flaw, which Zyxel <a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls\">patched<\/a> on April 25, can be exploited to execute malicious code with a specially crafted IKEv2 packet to UDP port 500 on the device.<\/p>\n<p>The critical vulnerability exists in default configurations of the manufacturer\u2019s firewall and VPN devices. They include Zyxel ZyWALL\/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35.<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<table class=\"table table-width\" border=\"0\">\n<tbody class=\"advisory_bg\">\n<tr>\n<th>Affected series<\/th>\n<th>Affected version<\/th>\n<th>Patch availability<\/th>\n<\/tr>\n<tr>\n<td>ATP<\/td>\n<td>ZLD V4.60 to V5.35<\/td>\n<td>ZLD V5.36<\/td>\n<\/tr>\n<tr>\n<td>USG FLEX<\/td>\n<td>ZLD V4.60 to V5.35<\/td>\n<td>ZLD V5.36<\/td>\n<\/tr>\n<tr>\n<td>VPN<\/td>\n<td>ZLD V4.60 to V5.35<\/td>\n<td>ZLD V5.36<\/td>\n<\/tr>\n<tr>\n<td>ZyWALL\/USG<\/td>\n<td>ZLD V4.60 to V4.73<\/td>\n<td>ZLD V4.73 Patch 1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>On Wednesday, the Cybersecurity and Infrastructure Security Agency <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/05\/31\/cisa-adds-one-known-exploited-vulnerability-catalog\">placed<\/a> CVE-2023-28771 on its list of known exploited vulnerabilities. The agency has given federal agencies until June 21 to fix any vulnerable devices in their networks.<\/p>\n<p>Security researcher Kevin Beaumont has also been <a href=\"https:\/\/cyberplace.social\/@GossiTheDog\/110428080243894672\">warning<\/a> of widespread exploitation of the vulnerability since last week.<\/p>\n<p>\u201cThis #Zyxel vuln is being mass exploited now by Mirai botnet,\u201d he wrote on Mastodon. \u201cA fuck ton of SMB VPN boxes are owned.\u201d<\/p>\n<p>Measurements from the Shodan search engine show <a href=\"https:\/\/www.shodan.io\/search?query=title%3A%22USG+FLEX%22%2C%22ATP100%22%2C%22ATP200%22%2C%22ATP500%22%2C%22ATP700%22%2C%22ZyWALL+USG%22\">almost 43,000 instances<\/a> of Zyxel devices exposed to the Internet.<\/p>\n<p>\u201cThis number only includes devices that expose their web interfaces on the WAN, which is not a default setting,\u201d Rapid7 said, using the abbreviation for wide area network, the part of a company\u2019s network that can be accessed over the Internet. \u201cSince the vulnerability is in the VPN service, which is enabled by default on the WAN, we expect the actual number of exposed and vulnerable devices to be much higher.\u201d<\/p>\n<p>A VPN\u2014short for virtual private network\u2014doesn&#8217;t need to be configured on a device for it to be vulnerable, Rapid7 said. Zyxel devices have long been a favorite for hacking because they reside at the edge of a network, where defenses are typically lower. Once infected, attackers use the devices as a launch pad for compromising other devices on the Internet or as a toe-hold that can be used to spread to other parts of the network they belong to.<\/p>\n<p>While most of the focus is on CVE-2023-28771, Rapid7 warned of two other vulnerabilities\u2014CVE-2023-33009 and CVE-2023-33010\u2014that Zyxel <a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls\">patched<\/a> last week. Both vulnerabilities also carry a 9.8 severity rating.<\/p>\n<p>With infections from CVE-2023-28771 still occurring five weeks after Zyxel fixed it, it\u2019s clear many device owners aren\u2019t installing security updates in a timely manner. If the poor patching hygiene carries over to the more recently fixed vulnerabilities, there likely will be more Zyxel compromises occurring soon.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34682\/Researchers-Tell-Owners-To-Assume-Compromise-Of-Unpatched-Zyxel-Firewalls.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":52158,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[10102],"class_list":["post-52157","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinehackerflawbackdoor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-01T14:14:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/05\/system-hacked-800x450.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls\",\"datePublished\":\"2023-06-01T14:14:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/\"},\"wordCount\":607,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls.jpg\",\"keywords\":[\"headline,hacker,flaw,backdoor\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/\",\"name\":\"Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls.jpg\",\"datePublished\":\"2023-06-01T14:14:21+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/06\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls.jpg\",\"width\":800,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,flaw,backdoor\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerflawbackdoor\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/","og_locale":"en_US","og_type":"article","og_title":"Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-06-01T14:14:21+00:00","og_image":[{"url":"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/05\/system-hacked-800x450.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls","datePublished":"2023-06-01T14:14:21+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/"},"wordCount":607,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls.jpg","keywords":["headline,hacker,flaw,backdoor"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/","url":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/","name":"Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls.jpg","datePublished":"2023-06-01T14:14:21+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/06\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls.jpg","width":800,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/researchers-tell-owners-to-assume-compromise-of-unpatched-zyxel-firewalls\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,flaw,backdoor","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerflawbackdoor\/"},{"@type":"ListItem","position":3,"name":"Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52157","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52157"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52157\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/52158"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52157"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52157"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}