How AI Assistants are Moving the Security Goalposts
2026-03-09T01:23:31Z•b457bd597fc91f80c4bf9748c2ef06c9c7ea05b03d295ada3df49cf5b23574b2
AI assistantsBadbox 2.0DDoSI2PIoT botnetKimwolfMFA bypassMicrosoft updatesPatch TuesdayScattered Lapsus ShinyHuntersStarkilleragent securitybotnet attributioncredential theftdoxingextortioninsider-threatphishing-as-a-serviceswattingzero-day vulnerabilities
What happened
Multiple KrebsOnSecurity posts document a surge in high-impact cyber threats in early 2026: Kimwolf, a massive IoT botnet (reported >2M infected devices), is being used for large-scale DDoS, relay abuse, doxing and swatting, and its operators (handle “Dort”) have actively targeted researchers and journalists. Kimwolf has also been leveraged to disrupt/evade takedowns via anonymity networks (I2P) and to compromise other botnets (Badbox 2.0). A new phishing-as-a-service called “Starkiller” proxies real login pages and relays credentials and MFA codes in real time, enabling credential theft and a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- b457bd597fc91f80c4bf9748c2ef06c9c7ea05b03d295ada3df49cf5b23574b2
- Enrichment time
- 2026-03-09T01:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.