Authorities arrest 23-year-old accused of running the Kimwolf botnet

2026-05-23T08:51:50Ze83106482c95e3c361f7cb1285116e8d2e4e4104f5b7d8e24b14c49d137b7b6b
Arch LinuxC2 infrastructureCISACVE-2008-4250CVE-2025-34291CVE-2026-20223Cisco Secure WorkloadDiscordFirst VPNHunt.ioLangflowLinux local privilege escalationMFA bypassPinTheftSonicWallTrend Micro Apex Onearrestbotnetddosend-to-end encryption (E2EE)extraditionkimwolfknown exploited vulnerabilitiesransomwaretelecom hosting abuse

What happened

Feed of security news: Canadian authorities arrested a 23‑year‑old alleged operator of the Kimwolf DDoS botnet and the US seeks extradition. CISA added multiple flaws to its Known Exploited Vulnerabilities catalog (notably CVE-2025-34291) while other advisories include Cisco patching a critical Secure Workload API vulnerability (CVE-2026-20223, CVSS 10.0) and Microsoft/Adobe related entries (including CVE-2008-4250). Additional coverage: a global law‑enforcement takedown of First VPN (used by ransomware/data‑theft actors), Hunt.io mapping a concentration of C2 infrastructure at a single Middle

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
e83106482c95e3c361f7cb1285116e8d2e4e4104f5b7d8e24b14c49d137b7b6b
Enrichment time
2026-05-23T08:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Authorities arrest 23-year-old accused of running the Kimwolf botnet · Baitaphish