FR
live
tag

#botnet

The MikroTrick chain opens the RouterOS admin console with no password or SSH key

CERT Polska has documented the MikroTrick chain: two RouterOS SSH flaws, CVE-2026-67279 and CVE-2026-86060, combine to hand attackers full administrative control of an exposed router with no password and no SSH key. CISA added CVE-2026-67279 to its KEV catalog on September 25, 2026: patch to 6.49.21, 7.23.4 or 7.24.2 and hunt for signs of compromise.

One operator breached 14,530 Dahua cameras in 35 days — 89% without a password

Between June 17 and July 22, 2026, a single operator compromised more than 14,530 Dahua cameras by chaining brute force, a 2021 flaw and the vendor’s P2P relay — 89% of them with no authentication at all. Hunt.io’s investigation reveals a hard truth: connected video surveillance is an open door by design.

The FBI takes down QScan and QTRouter, the obfuscation network hiding China’s intrusions

On August 26, 2026, the U.S. Department of Justice and the FBI seized the domains of QScan and QTRouter, two platforms run by a Chinese group that concealed the origin of intrusions against U.S. critical infrastructure. The lesson outlives the news cycle: network obfuscation is now an industrialized service, and it breaks where the attacker has the least redundancy.

Evooo1Bot turns exposed routers into monetized SOCKS5 traffic relays

The Mirai-derived modular botnet Evooo1Bot has been recruiting internet-exposed gateways — Alcatel, NETGEAR, Tenda, D-Link — into resellable SOCKS5 relay nodes since July. Fortinet documents a full arsenal whose economic novelty, the residential relay, should push every operator to inventory their internet-facing routers.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss