AryStinger botnet infected thousands of D-Link routers worldwide
2026-06-22T07:23:31Z•5f03f5536a6a8b4a476588a79fb67f5085e4271c4c398a1cea4be24f0acd97fa
AryStingerBlueNoroffCISAD-LinkEDR evasion','USB worm','crypto-stealerFortiBleedFortinetGentlemen ransomwareGravity SMTPIcarusKlueMastra AIOAuthPrinz EugenSapphire SleetSplunk EnterpriseTexas Parks and WildlifeWordPressbotnetcredentials leakdata breachinformation disclosurenpmransomwaresupply-chain
What happened
Multiple high-impact security incidents and active threats were reported: a new AryStinger botnet compromised >4,000 outdated D-Link routers to operate as proxies; a Mastra AI supply-chain compromise affected >140 npm packages and was attributed to North Korean group Sapphire Sleet/BlueNoroff; Klue confirmed an OAuth token breach being claimed by the Icarus extortion group; an unauthenticated info-disclosure bug in the Gravity SMTP WordPress plugin is being exploited on ~100,000 sites; the Texas Parks and Wildlife vendor breach exposed personal data for >3 million driver’s licenses; CISA warns
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 5f03f5536a6a8b4a476588a79fb67f5085e4271c4c398a1cea4be24f0acd97fa
- Enrichment time
- 2026-06-22T07:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.