Aeternum botnet hides commands in Polygon smart contracts

2026-03-04T21:44:14Z31f91c032faf57513f9a9e0c77cb0cc9eb0bab3775dd26e863afc6cbb8a115aa
CVE-2026-20127CVE-2026-21902AeternumApex OneC2CISACiscoDohdoorJuniperKEVManoManoPTXPolygonRCESD-WANTrend MicroUAT-10027blockchainbotnetcredentials-leakdata-breachexposed .envmisconfiguration','incident-response','AI','NATO','iPhone','iPadsmart-contractszero-day

What happened

This collection highlights multiple high-impact threats and disclosures: Aeternum botnet is using Polygon smart contracts to host C2, complicating takedown efforts; Juniper released an emergency patch for a critical PTX router RCE (CVE-2026-21902, CVSS 9.3); a critical Cisco SD‑WAN authentication bypass (CVE-2026-20127, CVSS 10.0) has been actively exploited since 2023 and was added to CISA’s KEV catalog; Trend Micro patched two critical Apex One RCEs; Cisco SD‑WAN zero-day and other network device flaws pose widespread risk. Also reported: the UAT-10027 cluster deploying a new Dohdoor backdó

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
31f91c032faf57513f9a9e0c77cb0cc9eb0bab3775dd26e863afc6cbb8a115aa
Enrichment time
2026-03-04T21:44:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.