Russian national convicted for running botnet used in attacks on U.S. firms

2026-03-26T02:51:45Z9cd073717d63ae97dc4c6ced430a0105e8c395e7021b8cd7df467ef9d3d89654
Archer NXAstraZenecaCVE-2025-15517CVE-2026-3055Citrix NetScalerDutch Ministry of FinanceFCC router banHackerOneKubernetes lateral movementLapsus$LiteLLMNaviaQualDermTP-LinkTeamPCPbackdoorbotnetconvictioncredential theftcritical-vulnerabilitydata breachfirmware takeoverransomwarerouter securitysupply chain

What happened

Collection of SecurityAffairs reports (Mar 24–25, 2026): notable criminal sentences for Russian operators tied to botnets and ransomware; multiple large data breaches (QualDerm Partners — 3.1M records, Dutch Ministry of Finance incident, Navia breach affecting ~300 HackerOne employees, claimed Lapsus$ theft from AstraZeneca); a supply‑chain compromise of LiteLLM (malicious v1.82.7–1.82.8 linked to TeamPCP, stealing credentials and enabling Kubernetes lateral movement); router/IoT security actions and vulnerabilities (FCC move to ban certain foreign routers; TP‑Link Archer NX authentication‑byp

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
9cd073717d63ae97dc4c6ced430a0105e8c395e7021b8cd7df467ef9d3d89654
Enrichment time
2026-03-26T02:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Russian national convicted for running botnet used in attacks on U.S. firms · Baitaphish