Russian hackers turn Kazuar backdoor into modular P2P botnet
2026-05-16T19:23:49Z•0f7bdc2aef83ca7ced946d57fb0ebc9209d4741b92735caea3bd37e0b532a90f
avada-builderburst-statisticsciscocredential-theftcredit-card-theftcve-2026-20182exchange-zero-dayfunnel-builderkazuarmicrosoft-edgenginxnode-ipcnpmopenai-breachoutlook-on-the-webp2p-botnetpwn2ownrce-dosremus-infostealersd-wansecret-blizzardsupply-chain-attacktanstackwindows-11wordpress
What happened
Multiple high-impact active threats and vulnerabilities reported: Russian group Secret Blizzard evolved the long‑running Kazuar backdoor into a modular P2P botnet for long‑term persistence and data collection; several WordPress plugins (Funnel Builder, Avada Builder, Burst Statistics) contain critical flaws being exploited to steal credentials, payment cards, and gain admin access; a supply‑chain compromise affected the popular node‑ipc npm package and broader TanStack-related packages (OpenAI confirmed device breaches), leading to credential theft and code‑signing rotations; Cisco warned of a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0f7bdc2aef83ca7ced946d57fb0ebc9209d4741b92735caea3bd37e0b532a90f
- Enrichment time
- 2026-05-16T19:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.