The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.

A new Linux botnet, dubbed Evooo1Bot, has reportedly expanded its capabilities significantly beyond the typical distributed denial-of-service (DDoS) attacks commonly associated with Mirai-derived malware. This evolution marks a shift towards more sophisticated and persistent forms of compromise, according to recent reports.
Evooo1Bot is said to incorporate several advanced modules that extend its functionality well beyond simple traffic generation. These new features reportedly include exploitation modules, which allow the botnet to actively seek out and compromise vulnerable devices. This move from passive recruitment to active exploitation represents a substantial increase in the threat actor's ability to expand their network of compromised machines.
Furthermore, the botnet is reported to include credential theft capabilities. This functionality suggests that Evooo1Bot aims to harvest login information from compromised systems, potentially enabling lateral movement within networks or access to additional services. The theft of credentials can provide attackers with long-term access and a broader attack surface, making remediation more challenging.
Another significant addition is the implementation of reverse SOCKS relays. This feature allows compromised devices to act as proxies for attacker traffic, effectively masking the true origin of malicious activities. By routing traffic through multiple compromised nodes, attackers can evade detection, maintain anonymity, and launch further attacks from within seemingly legitimate networks.
The combination of exploitation, credential theft, and reverse SOCKS relays transforms compromised devices into persistent attacker infrastructure rather than mere cannon fodder for DDoS attacks. This allows the threat actors to establish a foothold, exfiltrate data, and launch subsequent attacks with greater stealth and resilience. Devices commonly targeted by Linux botnets include IoT devices, routers, network-attached storage (NAS) devices, and other embedded systems with internet exposure.
Mitigation for this class of threat typically involves rigorous patch management to address known vulnerabilities that exploitation modules might target. Strong, unique passwords and multi-factor authentication are crucial to prevent credential theft. Network segmentation can limit lateral movement, and intrusion detection/prevention systems can help identify unusual outbound connections indicative of SOCKS relays or command-and-control communication. Regular security audits and monitoring of network traffic for anomalous activity are also essential.
The emergence of Evooo1Bot highlights a continuing trend in the evolution of botnets, moving from simple, high-volume attacks to more nuanced, multi-functional threats. This shift underscores the need for organizations and individuals to adopt comprehensive security practices that address not only immediate threats but also the potential for long-term, stealthy compromises of their internet-connected devices.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed