LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
malware

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

23-year-old botnet down

zeroday.news ·

International law enforcement agencies, in collaboration with cybersecurity firm CrowdStrike and the Shadowserver Foundation, have successfully disrupted the Sality peer-to-peer botnet, which has been active for 23 years. The operation, which took place on Monday, September 1, 2026, involved a peer-to-peer sinkhole strategy designed to isolate infected machines and sever the botnet operator's control.

Sality, first identified in 2003, has been used to distribute various forms of malicious code to over 15,000 machines globally. Its capabilities have included credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, the botnet's primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, redirecting funds during transactions.

CrowdStrike estimates that the Sality operator stole at least $150,000 in cryptocurrency through the use of EggJagger alone. The disruption aimed to break the botnet's functionality by preventing infected devices from receiving new payload download instructions or direct payload transfers.

The counterattack exploited a core mechanism of the Sality botnet: its peer list. Each Sality bot maintains a list of "super peers," which are publicly reachable infected machines forming the backbone of the P2P network. Bots check the status of their peers every 40 minutes, purging unresponsive ones. The disruption strategy involved systematically removing legitimate super peers from each bot's list and inserting purpose-built sinkhole entries. This process progressively isolated more infected machines and provided law enforcement and cyber operatives with visibility into the operation's progress, aiding in victim notification.

In addition to the sinkhole operation, the U.S. Justice Department, the FBI, and the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains within the United States. Concurrently, law enforcement agencies in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe.

The Shadowserver Foundation is now working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infected machines and assist with victim notification and remediation efforts.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

security

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity a

phishing

FBI raises alarm over deceptive phishing campaign targeting prominent people

The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop.

breach

Another Artifactory CVE under attack by AI agents or humans

Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit