Authorities arrest 23-year-old accused of running the Kimwolf botnet
2026-05-23T02:51:48Z•bae54e93a4fb59789cf2f179ef0325cfa909aa566d4234d755ef1dcf5a08d14a
Apple fraud preventionArch LinuxC2 infrastructureCISACVE-2008-4250CVE-2025-34291CVE-2026-20223CiscoDDoSDiscordFirst VPNHunt.ioKEVKimwolfLinux LPEMFA bypassPinTheftSecure WorkloadSonicWallarrestbotnetend-to-end encryptionexploitlaw enforcement takedowntelecom abuse
What happened
Feed covers multiple high-impact developments: Canadian authorities arrested 23-year-old Jacob Butler (aka “Dort”) accused of operating the Kimwolf DDoS botnet, with the U.S. seeking extradition. CISA added several actively exploited flaws to its KEV catalog (including CVE-2025-34291 and historically notable CVE-2008-4250). Cisco released a patch for a maximum-severity Secure Workload REST API vulnerability (CVE-2026-20223, CVSS 10.0). Other notable items: SonicWall Gen6 VPNs remain vulnerable to MFA bypass when post-patch manual steps are missed; Hunt.io mapped 1,350+ C2 servers concentrated/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- bae54e93a4fb59789cf2f179ef0325cfa909aa566d4234d755ef1dcf5a08d14a
- Enrichment time
- 2026-05-23T02:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.