/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hackers breached the internal network of Avast likely aiming for another supply chain attack on CCleaner; Avast says it didn't find malicious changes to the app

again Robert Lemos / Dark Reading : Avast Foils Another CCleaner Attack Alex Scroxton / ComputerWeekly.com : Attacker hit VPN firm Avast through its VPN Seth Rosenblatt / The Parallax : SafeBreach discloses vulnerabilities in Avast, AVG, Avira Tweets: @briankrebs : Breaches acknowledged this week by Avast (a la CCleaner) and NordVPN tied to phantom user accounts, no 2FA https://krebsonsecurity.com/ ... pic.twitter.com/eOWuT2cofF Vincent Yiu / @vysecurity : Mate I think you're dizzy. How is getting “Domain Admin”, attempting to be stealth? Tracked them for a few months? Sounds a bit crappy because who leaves the attacker with DA privileges for 2 months to track them 🧐 https://twitter.com/...

BleepingComputer Ionut Ilascu

Context & Ripple Effects

This is a repeat, not a debut: in 2017 attackers hid a backdoor in CCleaner that tainted roughly 2.27M downloads, and Avast's own postmortem of the CCleaner backdoor described it as a targeted campaign against tech firms. Two years later, someone is back inside Avast's internal network with what looks like the same objective.

The breach lands while Avast's defenses are already under scrutiny — SafeBreach has just disclosed vulnerabilities across Avast, AVG, and Avira, and Brian Krebs' reporting ties the intrusion to phantom user accounts without two-factor authentication. Avast says it found no malicious changes to CCleaner this time, but the 2017 incident proved the update pipeline is exactly what attackers want.

First-order effects

  • Avast must re-verify its CCleaner build-and-signing pipeline end to end and convince 2.27M-plus users — the same population burned by the 2017 backdoor — that no second tampering occurred.
  • The disclosed SafeBreach vulnerabilities and the reported missing two-factor authentication now compound into a concrete security-posture problem for Avast and its AVG customer base.

Second-order effects

  • Enterprise buyers of endpoint software face an uncomfortable pattern: BitDefender admitted a breach back in 2015, and now Avast — meaning the vendors selling trust are themselves recurring targets, pressuring rivals to publish their own build-integrity controls.
  • Security vendors' update channels become a priced-in risk in procurement, the same dynamic now playing out with remote-access firms after TeamViewer's corporate-environment breach.

Third-order effects

  • The recurring sequence — CCleaner in 2017, 3CX's desktop client in 2023, TeamViewer in 2024 — points toward corporate IT networks of security and remote-access vendors becoming the preferred supply-chain entry point, shifting the battleground from end-user machines to vendor build infrastructure.
  • If intrusions keep targeting the vendors themselves, expect regulators and enterprise customers to demand verifiable build provenance and hardened identity controls (2FA, account hygiene) as a condition of trust rather than a best practice.

The trend: Supply-chain attackers are increasingly skipping end targets and compromising the security and remote-access vendors themselves, making vendor build pipelines the industry's systemic weak point.

Discussion

  • The Parallax Seth Rosenblatt on x
    SafeBreach discloses vulnerabilities in Avast, AVG, Avira
  • @briankrebs @briankrebs on x
    Breaches acknowledged this week by Avast (a la CCleaner) and NordVPN tied to phantom user accounts, no 2FA https://krebsonsecurity.com/ ... pic.twitter.com/eOWuT2cofF
  • @vysecurity Vincent Yiu on x
    Mate I think you're dizzy. How is getting “Domain Admin”, attempting to be stealth? Tracked them for a few months? Sounds a bit crappy because who leaves the attacker with DA privileges for 2 months to track them 🧐 https://twitter.com/...