Security researchers have detailed a new Linux botnet that breaks into routers, cameras, video recorders and virtual private ...
Black Lotus Labs attributed the PoeLLM malware to an Italian-speaking criminal, and named the financially motivated campaign Canto Incognito because it hides the malicious commands in a poem posted to ...
Canto Incognito has infected over 3,400 servers, using exposed AI and LLM infrastructure for crypto mining and botnet growth.
A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads.
Nozomi reports that Cling botnet uses STUN traffic to conceal command-and-control activity and attacks against vulnerable IoT ...
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle ...
Cling malware exploits vulnerable Realtek devices to build a botnet while disguising command traffic as Google STUN responses ...
Maritime security firm Cydome compared the images against 2023 photos of a different ship’s engine room and assessed them as ...
Windows botnet that can steal browser data, abuse paid AI credits, control devices and launch website attacks.
The PaperCut NG/MF exploitation campaign compromised 11 organizations in 26 seconds. Once the full operation launched, a single United States high school moved from initial access to full domain ...
CARBONATO is a Docker-based botnet that utilizes an autonomous AI agent as its command-and-control (C2) engine rather than a static server. Discovered by ThreatDown researchers in August 2026, this is ...
The x47.c Windows botnet includes DDoS, credential theft, and SOCKS5 proxy capabilities and uses AI to maintain persistence.