Thursday, October 8, 2026

IoT

ClingSTUN Malware Turns Vulnerable IoT Devices Into Persistent Remote Proxy Nodes

ClingSTUN, a Linux backdoor that exploits unpatched internet-facing devices and converts them into persistent, remotely controlled proxy nodes. The malware combines startup persistence, process concealment, competitor termination, and remote...

Researchers Find Security Risks in 73.6% of 61,500 Abandoned IoT Apps

Researchers have identified significant security and privacy risks across 61,500 abandoned Android Internet-of-Things (IoT) companion applications. Their study found that 73.6% of these apps...

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available...

Dysphoria Hijacks Routers, Gateways and IP Cameras to Build Massive IoT Botnet

The Dysphoria botnet has expanded into a major Internet of Things threat, with a new Shadowserver Special Report identifying approximately 296,000 compromised devices. The...

Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks

A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture...

LLM-Assisted TuxBot Botnet Targets IoT Devices Across 17 Processor Architectures

TuxBot v3 Evolution, a modular IoT botnet framework capable of infecting devices running architectures ranging from ARM and MIPS to x86_64, PowerPC and RISC-V....

New VEXAIoT AI Agents Autonomously Exploit IoT Vulnerabilities With 95% Success Rate

VEXAIoT, an autonomous multi-agent framework designed to discover and exploit vulnerabilities in the Internet of Things (IoT) within controlled test environments. In 200 attack...

New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits

A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and...

China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits

A significant resurgence of the JDY botnet, a covert reconnaissance network tied to China-nexus threat activity. Once a component of the larger KV-botnet ecosystem,...

ORB Networks Leverages Compromised IoT Devices and SOHO Routers to Mask Cyberattacks

Operational Relay Box (ORB) networks are covert, mesh-based infrastructures used by advanced threat actors to hide the true origin of their cyberattacks. Built from...

Hackers Exploit IoT Vulnerabilities to Deploy New ShadowV2 Malware

Cybersecurity researchers have uncovered a concerted campaign where hackers are actively exploiting vulnerabilities in Internet of Things (IoT) devices to deploy a potent new...