23-year-old botnet down

International law enforcement agencies, in collaboration with cybersecurity firm CrowdStrike and the Shadowserver Foundation, have successfully disrupted the Sality peer-to-peer botnet, which has been active for 23 years. The operation, which took place on Monday, September 1, 2026, involved a peer-to-peer sinkhole strategy designed to isolate infected machines and sever the botnet operator's control.
Sality, first identified in 2003, has been used to distribute various forms of malicious code to over 15,000 machines globally. Its capabilities have included credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, the botnet's primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, redirecting funds during transactions.
CrowdStrike estimates that the Sality operator stole at least $150,000 in cryptocurrency through the use of EggJagger alone. The disruption aimed to break the botnet's functionality by preventing infected devices from receiving new payload download instructions or direct payload transfers.
The counterattack exploited a core mechanism of the Sality botnet: its peer list. Each Sality bot maintains a list of "super peers," which are publicly reachable infected machines forming the backbone of the P2P network. Bots check the status of their peers every 40 minutes, purging unresponsive ones. The disruption strategy involved systematically removing legitimate super peers from each bot's list and inserting purpose-built sinkhole entries. This process progressively isolated more infected machines and provided law enforcement and cyber operatives with visibility into the operation's progress, aiding in victim notification.
In addition to the sinkhole operation, the U.S. Justice Department, the FBI, and the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains within the United States. Concurrently, law enforcement agencies in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe.
The Shadowserver Foundation is now working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infected machines and assist with victim notification and remediation efforts.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a