Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AITengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-based botnet named Tengu has been discovered with advanced persistence capabilities, including the ability to trigger device reboots via hardware watchdog timers when its main process is terminated. Nozomi Networks Labs detected the malware spreading through Telnet brute-force attacks on Linux devices. The botnet supports at least 25 different distributed denial-of-service attack metho
AIChina-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Cybersecurity researchers have identified a significant expansion of the JDY botnet, a China-linked covert network that has grown to over 1,500 compromised SOHO and IoT devices. The botnet operates as a centrally controlled scanning infrastructure designed to discover, fingerprint, and continuously map exposed services at scale for cyber reconnaissance purposes.
AIDutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
Dutch law enforcement, in collaboration with the National Cyber Security Center, successfully dismantled a massive botnet comprising at least 17 million compromised devices including computers, mobile devices, and IoT equipment. The operation targeted over 200 command-and-control servers located within the Netherlands that were orchestrating malicious attacks through the infected device network.
