Botnet of more than 17 million devices dismantled

2026-05-29T20:51:55Z2e6342a0a2769921fdd1232777ce9f3c3d8db6108f591f86103c590c49f7911f
BadHostai-agentsbitlockerbotnetbrowser-trackingchromium-exploitcisa-credentials-leakcopyfailcritical-vulnerabilitydaemon-toolselement-datagithub-credentials-leaklaw-enforcement-takedownlinux-vulnerabilityopen-source-malwareprompt-injectionproxy-networkresidential-proxysoftware-backdoorssd-side-channelstarlettesupply-chain-attackteamPCPvpn-compromisezero-day

What happened

A broad set of May 2026 security events: law enforcement and researchers dismantled a Russia-linked residential-proxy botnet of ~17M devices while multiple high-impact software supply-chain attacks and backdoors surfaced (Daemon Tools, element-data, TeamPCP-targeted repos, and attacks affecting security vendors). Critical vulnerabilities and exploit activity threaten large populations — a critical flaw in the Starlette package ("BadHost") impacting AI agents, a published Chromium exploit, and a zero-day that defeats default Windows 11 BitLocker protections — alongside multiple severe Linux/CI/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
2e6342a0a2769921fdd1232777ce9f3c3d8db6108f591f86103c590c49f7911f
Enrichment time
2026-05-29T20:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Botnet of more than 17 million devices dismantled · Baitaphish