3 outlets·3 reports
Kaspersky says Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates (Dan Goodin/Ars Technica)

ThinkingNews Desk · how this was written
A month-long supply-chain attack has compromised Daemon Tools, a widely used disk-image mounting application. The backdoor was inserted through malicious updates pushed to users, allowing attackers to gain access to systems that install the software. The compromise is believed to have been carried out by a Chinese hacking group.
Written from all 3 reports below, not from any single one.
How it was reported
- TechCrunch·Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in ‘widespread’ attack
- Ars Technica·Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack
- TechMeme·Kaspersky says Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates (Dan Goodin/Ars Technica)
Related stories
- The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one3 outlets
- Protect your enterprise now from the Shai-Hulud worm and npm vulnerability in 6 actionable steps3 outlets
- Researchers: OpenAI agents attacked Ruby package manager RubyGems in May; OpenAI says its agents used RubyGems to access the internet to do "benign tasks" (Robert McMillan/Wall Street Journal)4 outlets
- Meta claims its own AI also hacked into a third-party service during testing3 outlets