A Russian organization trusted its secure network software to keep attackers out. Instead, the update system delivered the malware itself. That’s the story behind the HelloNet campaign, and it’s a preview of the next twelve months in cybersecurity: attackers aren’t breaking down your front door anymore, they’re riding in through the pipe you built to patch it.

Kaspersky’s Securelist team caught the HelloNet campaign pushing malicious modules through the ViPNet update system, a platform large Russian organizations rely on to build secure, encrypted networks. The irony is hard to overstate. ViPNet exists to create trusted communication channels. The attackers didn’t need to defeat that trust model, they just needed to get inside it.

Digital illustration representing the HelloNet campaign targeting ViPNet update infrastructure
The HelloNet campaign used a trusted secure-network update system to deliver malicious modules.

A Compromised Updater Doesn’t Trip Your Firewall

Here’s the uncomfortable part. Your firewall, your threat detection stack, your carefully tuned brute-force protection, none of it is looking at the update channel the same way it looks at inbound traffic from the internet. Update systems get whitelisted. They get elevated trust by design, because if you don’t trust your own patch pipeline, nothing in your environment is patchable.

That’s exactly what makes it such a good target. When a signed, expected update from a piece of security software itself becomes the delivery mechanism, most threat detection tooling waves it through. You built defense in depth around the assumption that updates are safe by definition. HelloNet is a reminder that assumption has an expiration date.

We identified targeted infection attempts against large Russian organizations using the ViPNet update system, a software suite for creating secure networks.

This isn’t the first time a trusted update path has been weaponized, and it won’t be the last. What’s notable here is the target profile: large organizations that presumably had mature security hardening programs, using software specifically designed for secure communication. If the update channel for your secure networking tool can be turned against you, the update channel for literally anything else in your stack deserves the same scrutiny.

CISA’s Deadline Won’t Save You If You’re Still Trusting the Wrong Layer

Meanwhile, CISA added CVE-2026-58644, a critical SharePoint deserialization flaw scoring 9.8, to its Known Exploited Vulnerabilities catalog this week, with federal agencies given until July 19 to patch. That’s a two-day window from disclosure to deadline, which tells you how actively this thing is already being used against real targets.

CISA logo alongside Microsoft SharePoint branding representing the KEV catalog addition
CISA gave federal agencies until July 19 to patch the actively exploited SharePoint flaw.

The connective tissue between a rushed SharePoint patch deadline and a compromised secure-network updater is the same lesson wearing two different outfits. Both cases involve infrastructure organizations were already relying on for cyber security, not infrastructure sitting exposed on the open internet waiting to be scanned. SharePoint servers are internal collaboration tools. ViPNet is secure networking software. These aren’t the assets that show up on a shadow-IT report. They’re the assets everyone assumed were handled.

Operational fallout from that kind of misplaced trust is not theoretical. Japanese frozen food giant Nichirei disconnected its systems on July 13 after a cyberattack and only started restoring operations days later. Whatever got them in, the result is the same pattern: an organization that thought its core infrastructure was accounted for found out otherwise, and paid for it in downtime, not just data.

Harden the Channel, Not Just the Perimeter

Patching matters, and if you’re running SharePoint on-prem, get CVE-2026-58644 closed before the KEV deadline regardless of whether you’re a federal agency. But patch discipline alone won’t catch a compromised update pipeline. You need to treat your trusted software supply chain, updaters, agents, and management consoles, as an attack surface with its own detection requirements.

  • Inventory every piece of software in your environment with autonomous update or remote management capability, including security tools themselves. If it can push code without a human clicking approve, it’s on the list.
  • Segment update traffic where possible so a compromised updater can’t pivot laterally the moment it lands. Treat it like any other high-privilege connection, not a free pass through your defense in depth.
  • Baseline normal update behavior, file sizes, signing certificates, destination hosts, frequency, so threat detection tooling has something to compare against when an update looks off.
  • Build incident response runbooks that explicitly cover “our own security software was the entry point.” Most IR plans assume the tooling is clean by default; that assumption needs to be tested, not inherited.
  • Rotate credentials and audit logs for any system tied to a vendor update mechanism after a disclosed campaign like HelloNet, even if you’re not the confirmed target. Threat actors reuse infrastructure across victims.

None of this requires ripping out your existing stack. It requires admitting that “trusted” and “verified” are not the same word, and that your cybersecurity posture is only as strong as the least-scrutinized update path in your environment. Attackers have figured that out. The question is whether your security hardening checklist has caught up.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.