חזרה לפיד
newsמקור: The Hacker News4.9.2026

נוזקה חדשה מסוג Backdoor בשם 'Ted' מתחבאת בתוך HAProxy ליירוט תעבורת רשת

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

נוזקה חדשה מסוג Backdoor בשם 'Ted' מתחבאת בתוך HAProxy ליירוט תעבורת רשת

◆ סיכום AI

ערכת כלים זדונית חדשה ללינוקס, המכונה 'Ted', התגלתה משולבת ישירות בקובצי HAProxy שעברו שינוי (טרויאניזציה) בארגונים דרום קוריאניים. ה-backdoor מאפשר ליירט תעבורת רשת ולהציג דפים מזויפים למבקרים נבחרים, תוך התחמקות מאיתור. זו אינה פגיעות ב-HAProxy עצמו, אלא פריצה המצריכה יכולת הרצת קוד על השרת, ומדגישה סיכוני אבטחה בשרשרת האספקה של רכיבי תוכנה.

# מהמקור

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

#supply-chain-attack#malware#linux-security#haproxy-backdoor#application-security
קרא במקור