Russian hackers turn Kazuar backdoor into modular P2P botnet

2026-05-16T19:23:49Z0f7bdc2aef83ca7ced946d57fb0ebc9209d4741b92735caea3bd37e0b532a90f
avada-builderburst-statisticsciscocredential-theftcredit-card-theftcve-2026-20182exchange-zero-dayfunnel-builderkazuarmicrosoft-edgenginxnode-ipcnpmopenai-breachoutlook-on-the-webp2p-botnetpwn2ownrce-dosremus-infostealersd-wansecret-blizzardsupply-chain-attacktanstackwindows-11wordpress

What happened

Multiple high-impact active threats and vulnerabilities reported: Russian group Secret Blizzard evolved the long‑running Kazuar backdoor into a modular P2P botnet for long‑term persistence and data collection; several WordPress plugins (Funnel Builder, Avada Builder, Burst Statistics) contain critical flaws being exploited to steal credentials, payment cards, and gain admin access; a supply‑chain compromise affected the popular node‑ipc npm package and broader TanStack-related packages (OpenAI confirmed device breaches), leading to credential theft and code‑signing rotations; Cisco warned of a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0f7bdc2aef83ca7ced946d57fb0ebc9209d4741b92735caea3bd37e0b532a90f
Enrichment time
2026-05-16T19:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.