Authorities arrest 23-year-old accused of running the Kimwolf botnet
2026-05-22T14:52:08Z•5666f23f568deb4716549a03ef61ee1db50bf0a0b1e09fca234a9123506a918d
Apple App Store fraudC2-infrastructureCISACisco Secure WorkloadDiscord E2EEFirst VPNHunt.ioKimwolfKnown Exploited VulnerabilitiesLangflowLinux LPEMFA-bypassPinTheftRDS subsystemSonicWallTrend MicroVPN-takedownbotnetcritical-vulnerabilityhosting-abuselaw-enforcement
What happened
Multiple high-impact cyber events reported: Canadian authorities arrested the alleged operator of the Kimwolf DDoS botnet; an international takedown seized First VPN and exposed cybercrime users; Hunt.io mapped 1,350+ active C2 servers concentrated at a small set of Middle East providers. CISA added several flaws to its Known Exploited Vulnerabilities catalog (including CVE-2025-34291 and historic/other Microsoft/Adobe/ScreenConnect entries), and Cisco released a patch for a critical Secure Workload API flaw (CVE-2026-20223, CVSS 10.0). Other notable items: SonicWall MFA bypasses due to missed
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5666f23f568deb4716549a03ef61ee1db50bf0a0b1e09fca234a9123506a918d
- Enrichment time
- 2026-05-22T14:52:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.