Wednesday, September 16, 2026

IoT

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available Linux kernel exploits before enrolling...

Dysphoria Hijacks Routers, Gateways and IP Cameras to Build Massive IoT Botnet

The Dysphoria botnet has expanded into a major Internet of Things threat, with a new Shadowserver Special Report identifying approximately 296,000 compromised devices. The...

Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks

A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture...

LLM-Assisted TuxBot Botnet Targets IoT Devices Across 17 Processor Architectures

TuxBot v3 Evolution, a modular IoT botnet framework capable of infecting devices running architectures ranging from ARM and MIPS to x86_64, PowerPC and RISC-V....

New VEXAIoT AI Agents Autonomously Exploit IoT Vulnerabilities With 95% Success Rate

VEXAIoT, an autonomous multi-agent framework designed to discover and exploit vulnerabilities in the Internet of Things (IoT) within controlled test environments. In 200 attack...

New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits

A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and...

China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits

A significant resurgence of the JDY botnet, a covert reconnaissance network tied to China-nexus threat activity. Once a component of the larger KV-botnet ecosystem,...

ORB Networks Leverages Compromised IoT Devices and SOHO Routers to Mask Cyberattacks

Operational Relay Box (ORB) networks are covert, mesh-based infrastructures used by advanced threat actors to hide the true origin of their cyberattacks. Built from...

Hackers Exploit IoT Vulnerabilities to Deploy New ShadowV2 Malware

Cybersecurity researchers have uncovered a concerted campaign where hackers are actively exploiting vulnerabilities in Internet of Things (IoT) devices to deploy a potent new...

PolarEdge Botnet Hits 25K IoT Devices in Major Cyber Campaign

Cybersecurity researchers at XLab have uncovered a sophisticated infrastructure-as-a-service botnet operation called PolarEdge, which has compromised over 25,000 Internet of Things devices and established...

New Botnet ‘Loader-as-a-Service’ Turns Home Routers and IoT into Mirai Farms

CloudSEK has uncovered a sophisticated Loader-as-a-Service botnet campaign spanning the last six months, leveraging exposed command-and-control logs to orchestrate attacks against SOHO routers, embedded...