daily cyber × ai intelligence

index

tagged

[botnet]

7 editions · 7 items

July 19, 2026 weekly

The Week Proof-of-Concept Became Mass Exploitation Overnight

SonicWall SMA1000 and WordPress core suffered pre-auth RCEs that moved from proof-of-concept to mass exploitation within hours, with the first attributed to Inc ransomware and UTA0533. Call-stack spoofing techniques defeating Intel CET shipped in commercial C2 frameworks like Nighthawk 1.0 and UnwindRaven, closing a defensive gap. Kimi K3, an open-weight frontier model, was jailbroken within hours of release to generate malware and CBRN detail despite guardrails. Finland's Supo confirmed a multi-year FSB Center 16 campaign targeting critical infrastructure via exposed SNMP and Cisco Smart Install devices.

July 16, 2026

  • Four to five @asyncapi npm packages were compromised to deliver a multi-stage botnet loader with info-stealing/RAT capabilities. Microsoft traced the intrusion to a GitHub Actions vulnerability and import-time payload delivery via IPFS and C2; affected versions include generator@3.3.1, generator-helpers@1.1.1, and specs@6.11.2. Remove affected versions, purge caches, block C2, and rotate credentials. Microsoft, The Hacker News, BleepingComputer · Supply Chain
  • Unit 42 analyzed TuxBot v3 "Evolution," a modular IoT botnet framework showing signs of LLM-assisted development — functional DDoS core, but several exploit and fallback features broken by development bugs. Unit 42, The Hacker News · AI & Model Security

in Relay Chains, Bind-Link Blindspots, and a Wave of Live Zero-Days

July 3, 2026

  • Google's Threat Intelligence Group, with the FBI, Lumen, and others, disrupted the NetNut / Popa residential proxy network — ~2 million enrolled home devices operated by Israeli firm Alarum Technologies — after observing 316 distinct threat clusters (cybercrime and espionage) using it to mask activity and run password-spray attacks. Note some coverage flagged the FBI seizing the wrong NetNut domain initially. Google/Mandiant, KrebsOnSecurity. · Threat Activity

in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire