
There’s a new cybersecurity incident, where hackers have exploited a newly discovered vulnerability in SAP’s NetWeaver software to deploy a stealthy Linux backdoor called Auto-Color. According to the report from Darktrace, the attack targeted a US-based chemicals company in April 2025. Over the course of three days, threat actors breached the company’s network and attempted to download multiple suspicious files.
While Darktrace’s security systems detected and contained the intrusion before any serious damage could occur, a deeper investigation found some concerning trends.