August 20, 2026
- The Aeternum botnet stores C2 instructions in Polygon smart contracts, retrieving immutable commands via public RPC endpoints to resist takedown (Unit 42).
· Threat Intelligence
in Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs
August 16, 2026
- Evooo1Bot — a new Linux botnet family that bolts the Mirai DDoS engine onto a more modular, capable framework and turns compromised routers into traffic-relay nodes. BleepingComputer
· Threat Activity
in Bring Your Own EDR: Turning a Commercial Endpoint Agent Into a Trojan Horse
July 30, 2026
- The new Tengu botnet abuses a hardware watchdog for advanced persistence, alongside multi-architecture payloads and extensive DDoS/proxy capability. SC World
· Threat Activity
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 19, 2026 weekly
SonicWall SMA1000 and WordPress core suffered pre-auth RCEs that moved from proof-of-concept to mass exploitation within hours, with the first attributed to Inc ransomware and UTA0533. Call-stack spoofing techniques defeating Intel CET shipped in commercial C2 frameworks like Nighthawk 1.0 and UnwindRaven, closing a defensive gap. Kimi K3, an open-weight frontier model, was jailbroken within hours of release to generate malware and CBRN detail despite guardrails. Finland's Supo confirmed a multi-year FSB Center 16 campaign targeting critical infrastructure via exposed SNMP and Cisco Smart Install devices.
July 16, 2026
- Four to five
@asyncapi npm packages were compromised to deliver a multi-stage botnet loader with info-stealing/RAT capabilities. Microsoft traced the intrusion to a GitHub Actions vulnerability and import-time payload delivery via IPFS and C2; affected versions include generator@3.3.1, generator-helpers@1.1.1, and specs@6.11.2. Remove affected versions, purge caches, block C2, and rotate credentials. Microsoft, The Hacker News, BleepingComputer
· Supply Chain - Unit 42 analyzed TuxBot v3 "Evolution," a modular IoT botnet framework showing signs of LLM-assisted development — functional DDoS core, but several exploit and fallback features broken by development bugs. Unit 42, The Hacker News
· AI & Model Security
in Relay Chains, Bind-Link Blindspots, and a Wave of Live Zero-Days
July 8, 2026
- A new LLM-assisted cloud-native botnet, "CAI," targets developer tooling to steal secrets, deploy XMRig-style miners, and forcibly evict rival malware from compromised cloud infrastructure — a marker of increasingly automated, competitive cloud crimeware. The Register
· AI & Model Security
in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM
July 3, 2026
- Google's Threat Intelligence Group, with the FBI, Lumen, and others, disrupted the NetNut / Popa residential proxy network — ~2 million enrolled home devices operated by Israeli firm Alarum Technologies — after observing 316 distinct threat clusters (cybercrime and espionage) using it to mask activity and run password-spray attacks. Note some coverage flagged the FBI seizing the wrong NetNut domain initially. Google/Mandiant, KrebsOnSecurity.
· Threat Activity
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire