
- TP-Link patches two vulnerabilities in older SOHO routers
- Chinese threat actor Quad7 used the botnet for broad password-spraying attacks
- The flaws were severe enough to warrant firmware updates, despite the routers being end-of-life
TP-Link has patched two vulnerabilities affecting some of its small office/home office (SOHO) routers, which were apparently used by Chinese actors to create a malicious botnet used to target Microsoft 365 accounts.