Hijacked IoT devices become hidden proxies inside enterprise networks
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, October 6th, 2026.
Compromised routers, surveillance equipment, and industrial devices are being turned into hidden proxy nodes inside enterprise networks. The ClingSTUN Linux malware targets at least 24 known weaknesses to gain initial access. It also carries exploits for seven more weaknesses that can help it spread to other vulnerable devices.
ClingSTUN uses legitimate public STUN servers to learn how an infected device appears on the internet and which ports can be reached from outside. Researchers have not yet verified exactly how the operators use that information to deliver control traffic. Because STUN also supports legitimate applications, simply blocking it could interrupt normal services.
A hijacked device can make malicious traffic appear to originate from the enterprise’s public address. That creates risks including I P blocklisting, reputational damage, bandwidth consumption, and operational disruption. Weak segmentation may also expose internal destinations the device can reach.
For defenders, inventory device models and firmware, remove unnecessary internet exposure, and look for STUN behavior that does not fit each device’s role. Update affected firmware, isolate I O T systems, and investigate unexpected recurring STUN traffic or unusual outbound connections.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.