RST TI Report Digest: 13 Jul 2026
ID: 2078705f-fd9d-5fb6-b900-08ccc6b93b2c
STIX ID: report--2078705f-fd9d-5fb6-b900-08ccc6b93b2c
Feed Name: RST Cloud Blog
Threat Score
Cisco Talos reports that UAT-7810, a China-nexus APT, is building Operational Relay Box (ORB) networks and expanding its malware toolkit (LONGLEASH, updated SHORTLEASH, DOGLEASH, JARLEASH) to support secondary actors; the campaign exploits unpatched devices including Ruckus routers and CVE-2025-2492, targets multiple CPU architectures, shows overlap with UAT-5918, and includes extensive IOCs (IPs, URLs, and numerous SHA-256 hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
