From Android TVs to routers: the xlabs_v1 Mirai-based botnet built for DDoS attacks

2026-05-07T14:51:51Za8c00152157bd374faffbdca91d257c74c8a9fa9e9cb506459be91b3d920e0bf
adb‑exposed devicesapache http servercisa kevcritical infrastructure hackcve-2026-0300cve-2026-23918ddosiot botnetmiraimuddywaterpalo alto pan‑ospypi malicious packagepytorch lightningransomware‑style espionageremote code executionshinyhunterssupply‑chain compromisethird‑party vendor compromisevimeo breachxlabs_v1

What happened

Multiple high‑impact cyber incidents and vulnerabilities were reported: a new Mirai‑derived botnet (xlabs_v1) is infecting ADB‑exposed Android and IoT devices for large DDoS campaigns; Palo Alto PAN‑OS vulnerability CVE‑2026‑0300 (CVSS 9.3) was added to CISA’s KEV and is being actively exploited for unauthenticated RCE; Apache HTTP Server fixed CVE‑2026‑23918, a HTTP/2 double‑free enabling RCE; Iran‑linked MuddyWater used ransomware‑style extortion to mask espionage; a malicious PyTorch Lightning release on PyPI briefly stole credentials raising AI supply‑chain concerns; Vimeo suffered a 119K‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
a8c00152157bd374faffbdca91d257c74c8a9fa9e9cb506459be91b3d920e0bf
Enrichment time
2026-05-07T14:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.