IoT Botnet C0XMO Adds Competitor-Killing Capability
2026-06-08T08:51:51Z•3a29696554d037019b6e39dde917a1d6b61de696b7a7b2401e1c52afbda28cd9
AnthropicC0XMOCVE-2021-27137CVE-2026-20245CVE-2026-28318CiscoClaude-OpusDDoSGafgytIoT-botnetKnown-Exploited-VulnerabilityMythosNSAPCPJackSD-WANShinyHuntersSilent-Ransom-GroupSolarWindsZcashcloud-email-relaycryptocurrency-vulnerabilitydata-breachextortionfast-fluxprivilege-escalation
What happened
This feed highlights multiple high-impact incidents and vulnerabilities from early June 2026: a new Gafgyt-derived IoT botnet variant dubbed C0XMO exploiting legacy router flaws (notably CVE-2021-27137) to spread, kill rival bots and conduct large-scale DDoS; a 234 GB data leak allegedly published by the ShinyHunters group after extorting DentaQuest (potentially affecting ~2.6M people); CISA adding SolarWinds Serv-U flaw (CVE-2026-28318, CVSS 7.5) to its Known Exploited Vulnerabilities catalog; a privilege-escalation file-upload/command-injection flaw in Cisco Catalyst SD-WAN Manager (CVE-2026
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 3a29696554d037019b6e39dde917a1d6b61de696b7a7b2401e1c52afbda28cd9
- Enrichment time
- 2026-06-08T08:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.