Find notable cyber news and cases, enriched with sources, timelines, and signals.

JDY botnet expanded reconnaissance and flaw-focused scanning activity

Malware Activity
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

The JDY botnet has expanded its reconnaissance and flaw-focused scanning, increasing the risk that exposed infrastructure will be rapidly identified and targeted. Researchers say it remains heavily focused on the United States, especially U.S. military and associated networks, while operating through compromised SOHO and IoT devices. The botnet's scanning workflow helps operators locate systems vulnerable to newly disclosed flaws and quickly operationalize the results. Its growth from January 2024 to today also shows the network is becoming a more capable discovery platform.

Related Happenings

CISA warning on FortiBleed for FortiGate customers

Public Sector Action
H score89 First: 19.06.2026 17:00 Last: 19.06.2026 17:00 Sources 1

About this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...

FortiBleed Fortinet/FortiGate VPN credential leak

Data Leak
H score80 First: 17.06.2026 18:12 Last: 17.06.2026 18:12 Sources 1

About this happening: FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...

Latest development: 19.06.2026 09:47

CISA urged Fortinet customers to secure FortiGate appliances after nearly 74,000 firewall and VPN credentials were exposed in the FortiBleed leak. The agency advised affected owners to terminate SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant multifactor authentication, review logs for unauthorized access or lateral movement, store admin credentials with PBKDF2, restrict firewall management interfaces from public internet access, and remove unauthorized accounts.

Calypso telecommunications espionage campaign using Showboat and JFMBackdoor

Campaign
H score36 First: 21.05.2026 17:00 Last: 21.05.2026 17:00 Sources 1

About this happening: A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...

OpenAI launches Daybreak cybersecurity initiative for AI-powered vulnerability detection and patch validation

Security Tool/Service
H score25 First: 12.05.2026 09:55 Last: 12.05.2026 09:55 Sources 1

About this happening: OpenAI's Daybreak launch adds an AI-powered cybersecurity service for vulnerability detection and patch validation, helping organizations fix flaws before attacker...

AVRecon malware for Linux powering SocksEscort proxy network

Malware Activity
H score19 First: 12.03.2026 18:19 Last: 12.03.2026 18:19 Sources 1

About this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...

Timeline

  1. 10.06.2026 18:00 2 articles · 1mo ago

    JDY botnet expands reconnaissance against U.S. military networks

    Campaign Scope Update

    Black Lotus Labs by Lumen says JDY has expanded its reconnaissance and flaw-focused scanning, maintains a strong focus on the United States, and heavily targets military and associated networks. The botnet has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices, and its operators are using the network to identify vulnerable infrastructure shortly after public vulnerability disclosures, including scans against CVE-2026-35616.

    Show sources