JDY Botnet Evolves After KV Takedown, Targets Military Networks
2026-06-11T08:51:53Z•34b7b364e2290671e0390201658d72f241cb7626fa78fc854631e6b4e758e39a
AI-wormsCISA KEVCVE-2025-8088CVE-2026-11645CVE-2026-44963ChromeGitHub compromiseJDYMiasmaMicrosoft DefenderPoCRoguePlanetTchap breachVeeamVolt TyphoonWinRARautonomous malwarebotnetincident responsemalwarepatchingreconnaissancestate-sponsoredsupply-chainzero-day
What happened
A wave of high-impact activity affecting enterprise and national networks was reported: the JDY botnet (linked to Chinese state actors including Volt Typhoon) resurfaced after the KV takedown and is scanning SOHO/IoT devices with targeting observed against US military networks. Russian-linked APTs continue to exploit the patched WinRAR path-traversal (CVE-2025-8088) via phishing archives. Multiple high-risk vulnerabilities were disclosed or actively exploited: a critical Veeam RCE (CVE-2026-44963) allowing low-privilege takeover of backup servers, an actively exploited Chrome V8 zero-day (CVE-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 34b7b364e2290671e0390201658d72f241cb7626fa78fc854631e6b4e758e39a
- Enrichment time
- 2026-06-11T08:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.