Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Microsoft and Uber alum raises $3M for YC-backed Munify, a neobank for the Egyptian diaspora

    August 29, 2025

    6G Wireless Will Use Aerial Base Stations

    August 29, 2025

    NATO To Reach 2% Goal

    August 29, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Microsoft and Uber alum raises $3M for YC-backed Munify, a neobank for the Egyptian diaspora
    • 6G Wireless Will Use Aerial Base Stations
    • NATO To Reach 2% Goal
    • Trillion with a ‘T’? That’s a lot of dollars, Nvidia.
    • I took this MagSafe battery pack on vacation, but now it’s an everyday carry
    • The Download: Humans in space, and India’s thorium ambitions
    • What’s really happening with the hires at Meta Superintelligence Labs
    • KI greift erstmals autonom an
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»New botnet hijacks AI-powered security tool on Asus routers
    Security

    New botnet hijacks AI-powered security tool on Asus routers

    TechurzBy TechurzMay 30, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    WLAN-Router
    Share
    Facebook Twitter LinkedIn Pinterest Email


    GreyNoise said its in-house AI tool, SIFT, flagged suspicious traffic aimed at disabling and exploiting a TrendMicro-powered security feature, AiProtection, enabled by default on Asus routers.

    Trojanizing the safety net

    Asus’ AiProtection, developed with TrendMicro, is a built-in, enterprise-grade security suite for its routers, offering real-time threat detection, malware blocking, and intrusion prevention using cloud-based intelligence.

    After gaining administrative access on the routers, either by brute-forcing or exploiting known authentication bypass vulnerabilities of “login.cgi” — a web-based admin interface, the attackers exploit an authenticated command injection flaw (CVE-2023-39780) to create an empty file at /tmp/BWSQL_LOG.

    Doing this activates the BWDPI (Bidirectional Web Data Packet Inspection) logging feature, a component of Asus’ AiProtection suite aimed at inspecting incoming and outgoing traffic. With logging turned on, attackers can feed crafted (malicious) payloads into the router’s traffic, as BWDPI is not meant to handle arbitrary data.

    In this particular case, the attackers use this to enable SSH on a non-standard port and add their own keys, creating a stealthy backdoor. “Because this key is added using the official Asus features, this config change is persisted across firmware upgrades,” GreyNoise researchers said. “If you’ve been exploited previously, upgrading your firmware will NOT remove the SSH backdoor.”

    While GreyNoise did not specify a particular CVE used as an authentication bypass for initial access, Asus recently acknowledged a critical authentication bypass vulnerability, tracked as CVE-2025-2492, affecting routers with the AiCloud feature enabled.

    AIpowered Asus botnet hijacks Routers Security Tool
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleX’s new DM feature, XChat, is rolling out in beta
    Next Article Fueling seamless AI at scale
    Techurz
    • Website

    Related Posts

    Security

    I took this MagSafe battery pack on vacation, but now it’s an everyday carry

    August 29, 2025
    Security

    KI greift erstmals autonom an

    August 29, 2025
    Security

    Changing these 10 settings on my OnePlus phone gave it a big performance boost

    August 29, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    You Can Now Get Starlink for $15-Per-Month in New York, but There’s a Catch

    July 11, 20257 Views

    Non-US businesses want to cut back on using US cloud systems

    June 2, 20257 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    You Can Now Get Starlink for $15-Per-Month in New York, but There’s a Catch

    July 11, 20257 Views

    Non-US businesses want to cut back on using US cloud systems

    June 2, 20257 Views
    Our Picks

    Microsoft and Uber alum raises $3M for YC-backed Munify, a neobank for the Egyptian diaspora

    August 29, 2025

    6G Wireless Will Use Aerial Base Stations

    August 29, 2025

    NATO To Reach 2% Goal

    August 29, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.