Authorities arrest 23-year-old accused of running the Kimwolf botnet
2026-05-22T20:51:44Z•2ff0ece4ab6608f3e85e49202947a83073a0080b6f8af0a41861d95d8594c9b4
Apple App Store fraudArch LinuxC2 infrastructureCISA KEVCisco Secure WorkloadDDoS botnetDiscord E2EEFirst VPNHunt.ioKimwolfLangflowLinux LPEPinTheftSonicWall MFA bypassTrend Micro Apex Onearresthosting abuselaw enforcement takedown
What happened
Multiple high-impact cyber incidents and vulnerability disclosures: Canadian authorities arrested a 23-year-old accused of operating the Kimwolf DDoS botnet; global law enforcement seized and took First VPN offline for facilitating cybercrime; Hunt.io mapped thousands of C2 servers concentrated at a small set of Middle East hosting providers; CISA added multiple actively exploited flaws to its KEV catalog (including CVE-2025-34291); SonicWall Gen6 VPNs remain vulnerable where remediation steps were missed, enabling MFA bypasses; Cisco patched a maximum-severity API/authentication flaw in Cisco
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 2ff0ece4ab6608f3e85e49202947a83073a0080b6f8af0a41861d95d8594c9b4
- Enrichment time
- 2026-05-22T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.