Find notable cyber news and cases, enriched with sources, timelines, and signals.

Evooo1Bot multi-CVE exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 1
2 unique sources, 2 articles

Summary

Hide ▲

Evooo1Bot has been actively exploiting internet-facing devices since July 2026, with a wave of attempts spanning multiple vulnerabilities across diverse regions. The activity broadens the risk to exposed edge devices by tying one loader infrastructure to many CVE hits.

Related Happenings

Evooo1Bot modular Linux botnet activity

Malware Activity
H score33 First: 14.08.2026 16:00 Last: 14.08.2026 16:00 Sources 1

How related: A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.

About this happening: Evooo1Bot is a new modular Linux botnet that Fortinet says has been active since July 2026 and uses Mirai-derived code to compromise internet-facing edge devices...

Latest development: 15.08.2026 17:14

Fortinet says Evooo1Bot targets internet-facing gateway devices and newer builds add an exploitation module for Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. The malware reuses the Mirai DDoS engine, uses encrypted C2 over port 443, includes an SSH brute-force scanner, a SOCKS relay module, and a credential sniffer that monitors /proc/net/tcp.

UAT-7810 Operational Relay Box network-building campaign

Campaign
H score39 First: 08.07.2026 12:04 Last: 08.07.2026 12:04 Sources 1

About this happening: An ongoing UAT-7810 campaign is expanding Operational Relay Box (ORB) networks by breaking into internet-facing networking devices, increasing relay capacity for downs...

IP KVM devices unauthenticated root access and command execution flaws (multiple vulnerabilities)

Vulnerability
H score39 First: 18.03.2026 13:42 Last: 18.03.2026 13:42 Sources 1

About this happening: Nine IP KVM vulnerabilities across GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, and JetKVM can expose attached hosts to root access and comm...

AMD StackWarp SEV-SNP bypass (CVE-2025-29943)

Vulnerability
H score24 First: 19.01.2026 13:31 Last: 19.01.2026 13:31 Sources 1

About this happening: StackWarp is a CVE-2025-29943 hardware vulnerability in AMD Zen 1 through Zen 5 CPUs that can bypass SEV-SNP protections and expose confidential VM workloads. The...

Timeline

  1. 14.08.2026 16:00 3 articles · 13d ago

    Evooo1Bot exploitation attempts hit edge devices through multiple CVEs

    Initial Disclosure

    FortiGuard Labs researcher Yi Ping (Cara) Lin shared analysis of Evooo1Bot on August 13, identifying a Mirai-derived Linux botnet built from publicly leaked Mirai source code after observing exploitation attempts against edge devices. The activity mapped to multiple CVEs and all payload callbacks pointed to 91.92.40[.]118/wget.sh, while Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026.

    Show sources