Aeternum botnet hides commands in Polygon smart contracts
2026-03-04T22:25:42Z•bd12fbf44a9a85dda22d46ac0cac2f9746f5096fb00876cbfcc8e4509221bbf9
CVE-2026-20127CVE-2026-21902.env-leakAeternumCISAManoManoUAT-10027apex-oneblockchain-c2botnetciscodata-breachdohdooreducation-sectorhealthcare-sectoriphone-ipadjuniperknown-exploited-vulnerabilitynatopolygonremote-code-executionsd-wansecrets-exposuresmart-contractstrend-micro
What happened
Multiple high-impact security events: researchers uncovered the Aeternum botnet using Polygon smart contracts for decentralized C2, complicating takedown efforts. Critical, actively exploited router and SD‑WAN vulnerabilities prompted emergency advisories and CISA KEV listings (notably CVE-2026-21902 affecting Juniper PTX routers and CVE-2026-20127 affecting Cisco SD‑WAN, the latter with a 10.0 score). Trend Micro patched two critical Apex One RCEs. Large-scale data exposures and intrusions were also reported — a 38M‑account ManoMano breach via a third‑party, 12M IPs exposing .env files with泄k
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- bd12fbf44a9a85dda22d46ac0cac2f9746f5096fb00876cbfcc8e4509221bbf9
- Enrichment time
- 2026-03-04T22:25:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.