CRITICALZero Day
Verified
Global

UNC3886 Deploys Firmware Rootkit on Juniper MX Routers via Zero-Day

·Source: Mandiant

Updated:

Executive Summary

UNC3886 exploits Juniper Junos zero-day to deploy firmware-level rootkits on MX-series routers. Implant survives software upgrades and factory resets.

Analysis

Mandiant identified UNC3886 exploiting CVE-2026-29001 in Juniper Junos OS to install firmware-level rootkits on MX-series routers used by ISPs and large enterprises. The implant, dubbed TinyShell.Router, intercepts and exfiltrates network traffic while maintaining persistence across software upgrades. Discovery came during an IR engagement at a European telecom.

Timeline

Discovered
Mar 20, 2026
Exploitation Detected
Mar 20, 2026
Published
Mar 31, 2026

Indicators of Compromise (1)

CVE (1)
CVE-2026-29001
Source Attribution

Originally published by Mandiant on Mar 31, 2026. Verified by: Mandiant, CISA, Juniper.

Related Threats

CRITICALZero Day

Zero-Day Remediation Meets Operational Resiliency

Executive Summary In the Frontier AI era, the number of CISA-known exploited vulnerabilities has increased by 6.5x over the past four years, and time-to-exploitation has collapsed to -7 days. Traditional monthly patch cycles cannot keep up. Organizations need a new operating model that detects at AI speed, hyper-prioritizes truly exploitable exposures, and remediates immediately. TruRisk […]

Qualys Blog
CRITICALZero Day

What the Hugging Face breach reveals about defense in the age of agentic AI

We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased […] The post What the Hugging Face breach reveals about defense i

CyberScoop
CRITICALZero Day

A coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?

A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities linked by a common operational technology weakness. While the affected communities reported that drinking water remained

CSO Online