Aeternum botnet hides commands in Polygon smart contracts
2026-03-04T21:44:14Z•31f91c032faf57513f9a9e0c77cb0cc9eb0bab3775dd26e863afc6cbb8a115aa
CVE-2026-20127CVE-2026-21902AeternumApex OneC2CISACiscoDohdoorJuniperKEVManoManoPTXPolygonRCESD-WANTrend MicroUAT-10027blockchainbotnetcredentials-leakdata-breachexposed .envmisconfiguration','incident-response','AI','NATO','iPhone','iPadsmart-contractszero-day
What happened
This collection highlights multiple high-impact threats and disclosures: Aeternum botnet is using Polygon smart contracts to host C2, complicating takedown efforts; Juniper released an emergency patch for a critical PTX router RCE (CVE-2026-21902, CVSS 9.3); a critical Cisco SD‑WAN authentication bypass (CVE-2026-20127, CVSS 10.0) has been actively exploited since 2023 and was added to CISA’s KEV catalog; Trend Micro patched two critical Apex One RCEs; Cisco SD‑WAN zero-day and other network device flaws pose widespread risk. Also reported: the UAT-10027 cluster deploying a new Dohdoor backdó
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 31f91c032faf57513f9a9e0c77cb0cc9eb0bab3775dd26e863afc6cbb8a115aa
- Enrichment time
- 2026-03-04T21:44:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.