Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed deni

Canadian authorities have arrested a 23-year-old Ottawa man, Jacob Butler, also known online as "Dort," on charges related to the creation and operation of the Kimwolf botnet. The botnet, which allegedly enslaved millions of Internet of Things devices, was used in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. Butler faces criminal hacking charges in both Canada and the United States.
A criminal complaint unsealed in an Alaska district court charges Butler with operating the Kimwolf DDoS botnet. The U.S. Department of Justice stated that Butler's arrest in Canada by the Ontario Provincial Police was executed under a U.S. extradition warrant. Butler is currently in Canadian custody awaiting an initial court hearing.
The Kimwolf botnet is accused of targeting devices that are typically firewalled from the internet, such as digital photo frames and web cameras. These compromised systems were allegedly rented out to other cybercriminals or compelled to participate in record-breaking DDoS attacks. The botnet was also linked to assaults that impacted Internet address ranges belonging to the Department of Defense. The Defense Criminal Investigative Service, with assistance from the FBI's Anchorage field office, is investigating the case.
The Justice Department indicated that Kimwolf was associated with DDoS attacks reaching nearly 30 Terabits per second, a volume described as a record for recorded DDoS attack activity. These attacks reportedly resulted in financial losses exceeding one million dollars for some victims. The Kimwolf botnet is alleged to have issued over 25,000 attack commands.
On March 19, U.S. authorities, in conjunction with international law enforcement, seized the technical infrastructure for Kimwolf and three other large DDoS botnets: Aisuru, JackSkid, and Mossad. These botnets were reportedly competing for the same pool of vulnerable devices.
Butler was identified as the Kimwolf botmaster in late February by KrebsOnSecurity, following an investigation into his various email addresses, cybercrime forum registrations, and public posts on Telegram and Discord. Despite efforts to track his identity, Butler allegedly continued to threaten and harass researchers who contributed to slowing the botnet's spread. He also claimed responsibility for at least two swatting incidents targeting the founder of Synthient, a security startup that helped address a critical vulnerability exploited by Kimwolf for rapid propagation.
Synthient's founder, Ben Brundage, expressed relief at Butler's apprehension, stating that he hopes the harassment will now cease. Investigators reportedly connected Butler to the Kimwolf botnet's administration through IP addresses, online account information, transaction records, and messaging application data obtained via legal processes. The criminal complaint suggests Butler did not significantly separate his real-world and cybercriminal identities.
In April, the Department of Justice, alongside European authorities, seized domain names associated with nearly four dozen DDoS-for-hire services. At least one of these services is said to have collaborated with Butler's Kimwolf botnet.
Following a search warrant executed at Butler's Ottawa residence on March 19, multiple devices were seized by the Ontario Provincial Police. Butler faces charges in Canada including unauthorized use of a computer, possession of a device for unauthorized computer system use or mischief, and mischief in relation to computer data. He is scheduled to remain in custody until his hearing on May 26.
If extradited to the United States, Butler faces one count of aiding and abetting computer intrusion. A conviction in a U.S. court could result in a maximum sentence of 10 years imprisonment, though this may be influenced by sentencing guidelines that consider factors such as youth, lack of prior criminal history, and cooperation with investigators.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.