JDY Botnet Evolves After KV Takedown, Targets Military Networks

2026-06-11T08:51:53Z34b7b364e2290671e0390201658d72f241cb7626fa78fc854631e6b4e758e39a
AI-wormsCISA KEVCVE-2025-8088CVE-2026-11645CVE-2026-44963ChromeGitHub compromiseJDYMiasmaMicrosoft DefenderPoCRoguePlanetTchap breachVeeamVolt TyphoonWinRARautonomous malwarebotnetincident responsemalwarepatchingreconnaissancestate-sponsoredsupply-chainzero-day

What happened

A wave of high-impact activity affecting enterprise and national networks was reported: the JDY botnet (linked to Chinese state actors including Volt Typhoon) resurfaced after the KV takedown and is scanning SOHO/IoT devices with targeting observed against US military networks. Russian-linked APTs continue to exploit the patched WinRAR path-traversal (CVE-2025-8088) via phishing archives. Multiple high-risk vulnerabilities were disclosed or actively exploited: a critical Veeam RCE (CVE-2026-44963) allowing low-privilege takeover of backup servers, an actively exploited Chrome V8 zero-day (CVE-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
34b7b364e2290671e0390201658d72f241cb7626fa78fc854631e6b4e758e39a
Enrichment time
2026-06-11T08:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · JDY Botnet Evolves After KV Takedown, Targets Military Networks · Baitaphish