Botnet of more than 17 million devices dismantled
2026-05-29T20:51:55Z•2e6342a0a2769921fdd1232777ce9f3c3d8db6108f591f86103c590c49f7911f
BadHostai-agentsbitlockerbotnetbrowser-trackingchromium-exploitcisa-credentials-leakcopyfailcritical-vulnerabilitydaemon-toolselement-datagithub-credentials-leaklaw-enforcement-takedownlinux-vulnerabilityopen-source-malwareprompt-injectionproxy-networkresidential-proxysoftware-backdoorssd-side-channelstarlettesupply-chain-attackteamPCPvpn-compromisezero-day
What happened
A broad set of May 2026 security events: law enforcement and researchers dismantled a Russia-linked residential-proxy botnet of ~17M devices while multiple high-impact software supply-chain attacks and backdoors surfaced (Daemon Tools, element-data, TeamPCP-targeted repos, and attacks affecting security vendors). Critical vulnerabilities and exploit activity threaten large populations — a critical flaw in the Starlette package ("BadHost") impacting AI agents, a published Chromium exploit, and a zero-day that defeats default Windows 11 BitLocker protections — alongside multiple severe Linux/CI/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 2e6342a0a2769921fdd1232777ce9f3c3d8db6108f591f86103c590c49f7911f
- Enrichment time
- 2026-05-29T20:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.