
Cybersecurity Threats Highlighted in SANS Stormcast: Phishing, Router Backdoors, AI Exploits, and PaperCut Vulnerability
The August 28, 2026, SANS Internet Storm Center Stormcast covered multiple cybersecurity threats, including polymorphic phishing pages that dynamically alter their obfuscated JavaScript code with each load, complicating detection—though some versions failed to render due to coding errors. Security researcher Jacob Baines identified two manufacturer-embedded backdoors in CBT-made routers sold under brands like Deep Orange, targeting China’s domestic market but available globally via Alibaba; one backdoor passively listens for UDP packets, while the other actively connects to cloud infrastructure (e.g., ac-link.com), enabling unauthenticated remote control. A survey by Elon Herz revealed that LMS.txt files, which instruct AI agents on website interactions, often contain malicious or accidental code that bots execute blindly, resembling a 'click-fix for bots' exploit. PaperCut issued a critical advisory for an actively exploited, unpatched vulnerability, advising users to restrict access to trusted IPs and monitor for suspicious .exe execution, suggesting potential remote code execution. The router backdoors, linked to 200–300 detected devices, were likely intended for surveillance or support but lacked authentication, raising concerns about manufacturer complicity. The phishing pages adapted content using victims’ email domains, while the PaperCut flaw’s severity remained undisclosed beyond indicators of compromise.