Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

2026-05-22T01:23:28Z582dd45f72eff26c383a94dbb5f4c8454ca57efc240cc6d9db03b9a4d45730f3
AWS GovCloudAdobe ReaderCISACanisterWormDDoSGandCrabGitHubGoogle ChromeIoTMicrosoftMicrosoft Office tokensREvilScattered SpiderSharePointarrestbotnetcredential leakagedata extortioneducationnation-state activitypatch Tuesdayransomrouter exploitationwiperzero-day

What happened

KrebsOnSecurity collection (Mar–May 2026) documents a string of high-impact cyber incidents: arrest of an alleged Kimwolf IoT botnet operator tied to massive DDoS, a contractor-leaked stash of highly privileged AWS GovCloud and internal CISA credentials on public GitHub, and a widespread Canvas data‑extortion incident threatening ~275M student/faculty records. Multiple patch rounds from major vendors fixed large numbers of vulnerabilities including publicly disclosed and actively exploited zero‑days (Microsoft SharePoint, Windows Defender “BlueHammer”, Google Chrome, Adobe Reader). Additional,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
582dd45f72eff26c383a94dbb5f4c8454ca57efc240cc6d9db03b9a4d45730f3
Enrichment time
2026-05-22T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.