threat-intel Naxclow IoT Platform This CISA advisory details a critical vulnerability in the Naxclow IoT Platform, specifically affecting versions of the Smart Doorbell X3, X Smart Home, V720, and ix cam devices. The flaw allows an attacker to impersonat… CISA Advisories · Jun 11, 2026 Critical CVE-2026-42947CVE-2026-50108CVE-2026-50101USiotcredential theftauthentication
threat-intel China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-sca… The Hacker News · Jun 10, 2026 High CVE-2026-35616USBRDEiotreconnaissancebotnet
threat-intel China-linked JDY botnet expands targeting of U.S. military networks A Chinese-linked botnet, JDY, has significantly expanded its targeting of U.S. military networks and associated infrastructure. The botnet, previously associated with Volt Typhoon, utilizes reconnaissance techniques like… BleepingComputer · Jun 10, 2026 High CVE-2026-35616USbotnetreconnaissanceapt
malware C0XMO botnet spreads via DD-WRT router flaw, kills rival malware A new botnet, C0XMO, leveraging a DD-WRT router vulnerability (CVE-2021-27137) is spreading across various device architectures, including routers, DVRs, and Android devices. This botnet, developed by the Gafgyt group, i… BleepingComputer · Jun 7, 2026 High CVE-2021-27137DEJPddosbotnetexploit
threat-intel ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More This Hacker News bulletin details several recent cyber threats, including a massive C2 infrastructure footprint discovered in the Middle East dominated by IoT botnets, a privilege escalation vulnerability in Azure Backup… The Hacker News · May 28, 2026 High CVE-2026-8398SAROUSc2supply-chainprivilege-escalation
vulnerability Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter This advisory details a critical vulnerability in the Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter, specifically version 7.03T.07. The device contains hardcoded administrative cr… CISA Advisories · May 28, 2026 Critical CVE-2026-7786CNfirmwarecredentialsiot
threat-intel Smashing Security podcast #469: What your Oura ring won’t tell you This podcast episode, "Smashing Security" #469, discusses cybersecurity concerns, primarily focusing on the potential vulnerabilities of wearable devices like the Oura ring and broader issues within the cybersecurity ind… Graham Cluley · May 27, 2026 Medium CARUwearablesiotmalware
ddos Canadian man arrested, charged for running KimWolf DDos botnet A Canadian man, Jacob Butler, has been arrested and charged with operating the KimWolf DDoS botnet, a significant online threat that disrupted numerous websites. Law enforcement agencies, in a coordinated international e… The Record · May 22, 2026 High CAUSGEddosbotnetcybercrime
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain
threat-intel US and Canada arrest and charge suspected Kimwolf botnet admin US and Canadian authorities have arrested Jacob Butler, an administrator of the KimWolf DDoS botnet, following a multi-national operation targeting several botnets. The botnet, which infected nearly two million devices g… BleepingComputer · May 22, 2026 High USCADEddosbotnetiot
threat-intel Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada A 23-year-old man, identified as Jacob Butler (a.k.a. ‘Dort’), has been arrested in Canada and faces criminal charges for operating the Kimwolf DDoS botnet. The botnet, responsible for massive DDoS attacks and targeting… Krebs on Security · May 21, 2026 High CAUSddosbotnetiot
other Flipper One project needs community help to build open Linux platform This article reports on Flipper Devices’ ambitious project, Flipper One, an open Linux platform designed for networking and hardware experimentation, utilizing an ARM-based Rockchip RK3576 SoC. The project aims to provid… BleepingComputer · May 21, 2026 Low linuxarmopen source
vulnerability Siemens Industrial Devices This article details a vulnerability (CVE-2025-40833) affecting multiple Siemens industrial devices, including IE/PB LINK HA, SCALANCE M series routers, and RuggedCom RM1224 LTE devices. The vulnerability allows an attac… CISA Advisories · May 14, 2026 High CVE-2025-40833industrial controldenial of servicefirmware update
threat-intel ISC Stormcast For Thursday, May 14th, 2026 https://isc.sans.edu/podcastdetail/9932, (Thu, May 14th) The SANS Internet Storm Center's Stormcast for May 14th, 2026 highlighted a concerning increase in various online threats, including phishing campaigns and malicious activity targeting critical infrastructure. The report… SANS Internet Storm Center · May 14, 2026 Medium phishingddosiot
threat-intel A Deep Dive Into Attempted Exploitation of CVE-2023-33538 This report details an ongoing attempt to exploit CVE-2023-33538, a vulnerability in older TP-Link Wi-Fi router models (TL-WR940N v2/v4, TL-WR740N v1/v2, TL-WR841N v8/v10). Automated scans, utilizing Mirai-like malware p… Palo Alto Unit 42 · Apr 16, 2026 High CVE-2023-33538USiotvulnerabilitymirai