JDY botnet expanded reconnaissance and flaw-focused scanning activity
Malware Activity
Summary
Hide ▲
Show ▼
The JDY botnet has expanded its reconnaissance and flaw-focused scanning, increasing the risk that exposed infrastructure will be rapidly identified and targeted. Researchers say it remains heavily focused on the United States, especially U.S. military and associated networks, while operating through compromised SOHO and IoT devices. The botnet's scanning workflow helps operators locate systems vulnerable to newly disclosed flaws and quickly operationalize the results. Its growth from January 2024 to today also shows the network is becoming a more capable discovery platform.
Related Happenings
CISA warning on FortiBleed for FortiGate customers
Public Sector Action
H score89
First: 19.06.2026 17:00
Last: 19.06.2026 17:00
Sources 1
About this happening:
CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
CISA warning on FortiBleed for FortiGate customers
Public Sector ActionAbout this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
FortiBleed Fortinet/FortiGate VPN credential leak
Data Leak
H score80
First: 17.06.2026 18:12
Last: 17.06.2026 18:12
Sources 1
About this happening:
FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
FortiBleed Fortinet/FortiGate VPN credential leak
Data LeakAbout this happening: FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
Latest development: 19.06.2026 09:47
CISA urged Fortinet customers to secure FortiGate appliances after nearly 74,000 firewall and VPN credentials were exposed in the FortiBleed leak. The agency advised affected owners to terminate SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant multifactor authentication, review logs for unauthorized access or lateral movement, store admin credentials with PBKDF2, restrict firewall management interfaces from public internet access, and remove unauthorized accounts.
Calypso telecommunications espionage campaign using Showboat and JFMBackdoor
Campaign
H score36
First: 21.05.2026 17:00
Last: 21.05.2026 17:00
Sources 1
About this happening:
A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...
Calypso telecommunications espionage campaign using Showboat and JFMBackdoor
CampaignAbout this happening: A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...
OpenAI launches Daybreak cybersecurity initiative for AI-powered vulnerability detection and patch validation
Security Tool/Service
H score25
First: 12.05.2026 09:55
Last: 12.05.2026 09:55
Sources 1
About this happening:
OpenAI's Daybreak launch adds an AI-powered cybersecurity service for vulnerability detection and patch validation, helping organizations fix flaws before attacker...
OpenAI launches Daybreak cybersecurity initiative for AI-powered vulnerability detection and patch validation
Security Tool/ServiceAbout this happening: OpenAI's Daybreak launch adds an AI-powered cybersecurity service for vulnerability detection and patch validation, helping organizations fix flaws before attacker...
AVRecon malware for Linux powering SocksEscort proxy network
Malware Activity
H score19
First: 12.03.2026 18:19
Last: 12.03.2026 18:19
Sources 1
About this happening:
The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
AVRecon malware for Linux powering SocksEscort proxy network
Malware ActivityAbout this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
Timeline
-
10.06.2026 18:00 2 articles · 1mo ago
JDY botnet expands reconnaissance against U.S. military networks
Campaign Scope UpdateBlack Lotus Labs by Lumen says JDY has expanded its reconnaissance and flaw-focused scanning, maintains a strong focus on the United States, and heavily targets military and associated networks. The botnet has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices, and its operators are using the network to identify vulnerable infrastructure shortly after public vulnerability disclosures, including scans against CVE-2026-35616.
Show sources
- China-linked JDY botnet expands targeting of U.S. military networks — www.bleepingcomputer.com — 10.06.2026 18:00
- China-linked JDY botnet expands targeting of U.S. military networks — www.bleepingcomputer.com — 10.06.2026 18:00