Authorities arrest 23-year-old accused of running the Kimwolf botnet

2026-05-22T14:52:08Z5666f23f568deb4716549a03ef61ee1db50bf0a0b1e09fca234a9123506a918d
Apple App Store fraudC2-infrastructureCISACisco Secure WorkloadDiscord E2EEFirst VPNHunt.ioKimwolfKnown Exploited VulnerabilitiesLangflowLinux LPEMFA-bypassPinTheftRDS subsystemSonicWallTrend MicroVPN-takedownbotnetcritical-vulnerabilityhosting-abuselaw-enforcement

What happened

Multiple high-impact cyber events reported: Canadian authorities arrested the alleged operator of the Kimwolf DDoS botnet; an international takedown seized First VPN and exposed cybercrime users; Hunt.io mapped 1,350+ active C2 servers concentrated at a small set of Middle East providers. CISA added several flaws to its Known Exploited Vulnerabilities catalog (including CVE-2025-34291 and historic/other Microsoft/Adobe/ScreenConnect entries), and Cisco released a patch for a critical Secure Workload API flaw (CVE-2026-20223, CVSS 10.0). Other notable items: SonicWall MFA bypasses due to missed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
5666f23f568deb4716549a03ef61ee1db50bf0a0b1e09fca234a9123506a918d
Enrichment time
2026-05-22T14:52:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Authorities arrest 23-year-old accused of running the Kimwolf botnet · Baitaphish