Botnet of more than 17 million devices dismantled
2026-05-31T20:51:47Z•a37a23e55f4270d68866be73d70f5402ebccae8255c78b717d1b01a417f0829b
badhostbitlockerbitwardenbotnetcheckmarxchromium-exploit-publicationcisa-credentials-leakage','prompt-injection','ai-prompt-inject',copyfailcredential-theftdaemon-toolselement-dataexploit-codegithub-credential-leaklaw-enforcement-hackinglinux-vulnerabilityopen-source-compromiseproxy-networkresidential-proxysoftware-backdoorstarlettesupply-chain-attackteamPCPvpn-compromisewindows-11zero-day
What happened
A wide-ranging set of security incidents and research surfaced across May 2026: law-enforcement and criminal infrastructure actions (a 17M-device botnet linked to a Russia-based residential proxy network; police hacking a VPN), multiple high-impact supply-chain compromises (Daemon Tools backdoor, TeamPCP campaign, attacks targeting Checkmarx and Bitwarden, element-data stealing credentials), and multiple severe vulnerabilities and zero-days (a critical "BadHost" issue in Starlette, a zero-day defeating default Windows 11 BitLocker, CopyFail — a major Linux threat). Other notable items include:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- a37a23e55f4270d68866be73d70f5402ebccae8255c78b717d1b01a417f0829b
- Enrichment time
- 2026-05-31T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.