Aeternum botnet hides commands in Polygon smart contracts

2026-03-04T22:25:42Zbd12fbf44a9a85dda22d46ac0cac2f9746f5096fb00876cbfcc8e4509221bbf9
CVE-2026-20127CVE-2026-21902.env-leakAeternumCISAManoManoUAT-10027apex-oneblockchain-c2botnetciscodata-breachdohdooreducation-sectorhealthcare-sectoriphone-ipadjuniperknown-exploited-vulnerabilitynatopolygonremote-code-executionsd-wansecrets-exposuresmart-contractstrend-micro

What happened

Multiple high-impact security events: researchers uncovered the Aeternum botnet using Polygon smart contracts for decentralized C2, complicating takedown efforts. Critical, actively exploited router and SD‑WAN vulnerabilities prompted emergency advisories and CISA KEV listings (notably CVE-2026-21902 affecting Juniper PTX routers and CVE-2026-20127 affecting Cisco SD‑WAN, the latter with a 10.0 score). Trend Micro patched two critical Apex One RCEs. Large-scale data exposures and intrusions were also reported — a 38M‑account ManoMano breach via a third‑party, 12M IPs exposing .env files with泄k

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
bd12fbf44a9a85dda22d46ac0cac2f9746f5096fb00876cbfcc8e4509221bbf9
Enrichment time
2026-03-04T22:25:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Aeternum botnet hides commands in Polygon smart contracts · Baitaphish