IoT Botnet C0XMO Adds Competitor-Killing Capability

2026-06-08T08:51:51Z3a29696554d037019b6e39dde917a1d6b61de696b7a7b2401e1c52afbda28cd9
AnthropicC0XMOCVE-2021-27137CVE-2026-20245CVE-2026-28318CiscoClaude-OpusDDoSGafgytIoT-botnetKnown-Exploited-VulnerabilityMythosNSAPCPJackSD-WANShinyHuntersSilent-Ransom-GroupSolarWindsZcashcloud-email-relaycryptocurrency-vulnerabilitydata-breachextortionfast-fluxprivilege-escalation

What happened

This feed highlights multiple high-impact incidents and vulnerabilities from early June 2026: a new Gafgyt-derived IoT botnet variant dubbed C0XMO exploiting legacy router flaws (notably CVE-2021-27137) to spread, kill rival bots and conduct large-scale DDoS; a 234 GB data leak allegedly published by the ShinyHunters group after extorting DentaQuest (potentially affecting ~2.6M people); CISA adding SolarWinds Serv-U flaw (CVE-2026-28318, CVSS 7.5) to its Known Exploited Vulnerabilities catalog; a privilege-escalation file-upload/command-injection flaw in Cisco Catalyst SD-WAN Manager (CVE-2026

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
3a29696554d037019b6e39dde917a1d6b61de696b7a7b2401e1c52afbda28cd9
Enrichment time
2026-06-08T08:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.