New Evooo1Bot Linux botnet turns routers into traffic relay nodes
2026-08-15T19:23:20Z•3b01399380be143bb001f031ab7c0c767b37ddff332995352a58fa31b86f4d87
AkiraEDR-evasionLinuxMiraiSAP-Commerce-CloudSOCKS5-proxyactive-exploitationbotnetcredential-theftcybersecurity-newsdata-breachespionagefraudmacOSmercenary-spywareransomwareremote-code-executionrouterszero-day
What happened
BleepingComputer security feed covering active exploitation of software vulnerabilities, Linux router botnet activity, ransomware and data theft, espionage, fraud, spyware, and major breaches. Notable items include Evooo1Bot compromising internet-facing gateway devices as SOCKS5 relay nodes, an actively exploited macOS Screen Sharing authentication bypass, a maximum-severity SAP Commerce Cloud remote-code-execution flaw, Akira affiliates disabling EDR via Safe Mode, and a newly patched Windows zero-day.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 3b01399380be143bb001f031ab7c0c767b37ddff332995352a58fa31b86f4d87
- Enrichment time
- 2026-08-15T19:23:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.