The 19-Month Sleeper: A LoadMaster Exploit Kit Just Landed at Your Edge
The mechanic matters more than the payload. A GitHub identity sat quiet for nineteen months, long enough to age past reputation heuristics and dependency-trust checks, then published a one-click mass-exploitation kit for a Progress/Kemp LoadMaster RCE. Read that as deliberate trust-banking. The account looks legitimate to maintainers, scanners, and hurried reviewers. Once the tooling is public, the disclosure-to-scanning window collapses to hours.
The target is the point. LoadMaster is a load balancer, and Ubiquiti's freshly-patched seven critical UniFi flaws (RCE, privilege escalation, unauthorized device changes) sit in the same tier. Edge gear lives below endpoint telemetry. Own a balancer or gateway and you get traffic manipulation and credential interception. Your EDR sees none of it. That is the blind spot behind slow, quiet intrusions.
The third-party-edge trap
Owned inventory is the easy part. The harder exposure is LoadMaster instances in vendor and partner edge stacks fronting services being consumed downstream. A mass-exploitation kit does not distinguish one ASN from a supplier's. A compromised upstream balancer routing that traffic is an incident regardless of who owns the box.
A dormant account is a loaded position. It waits until the exploit is worth firing.
Caveat: confirm exact CVE identifiers and fixed versions against Progress and Ubiquiti bulletins before closing tickets — curated intel is a pointer, not the primary advisory.
What to do
Enumerate every Progress/Kemp LoadMaster instance across owned and third-party edge this week, apply the vendor RCE fix, and load the published exploit-kit IOCs into detections before mass scanning arrives.
Confirm no UniFi management plane is WAN-reachable and patch all APs, controllers, and gateways to fixed firmware, confirming the exact CVE identifiers and fixed versions against Ubiquiti's official bulletin.