14,000 routers are infected by malware that's highly resistant to takedowns

2026-03-12T20:51:53Z074610d62fe6a809ac3d5165eaf0407f894813842ab1ad4b6eeea8ab45db7e03
AirSnitchAsusCISAIoTLLM-deanonymizationLumma StealerNotepad++RAMP-fbi-seizureSecure BootWi-Fibotnetcertificate-expirycryptocurrency-theftdYdXenergy-gridiOSknown-exploited-vulnerabilitymalwareoffice-exploitpassword-managersrouterssecurity-camerasstate-sponsoredsupply-chainwiper

What happened

This Ars Technica security feed aggregates multiple active, high-impact threats and incidents: ~14,000 mostly Asus routers infected by resilient malware, state-linked campaigns targeting consumer security cameras, three iOS flaws added to CISA’s known-exploited list, a new AirSnitch Wi‑Fi encryption bypass, renewed Lumma Stealer distribution and supply-chain compromises (Notepad++, malicious dYdX packages), and destructive wiper activity against Poland’s energy grid. The reporting also highlights systemic risks from password-manager server compromises, expiring Secure Boot certificates, Office

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
074610d62fe6a809ac3d5165eaf0407f894813842ab1ad4b6eeea8ab45db7e03
Enrichment time
2026-03-12T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 14,000 routers are infected by malware that's highly resistant to takedowns · Baitaphish