Canadian Man Arrested for Operating Kimwolf Botnet

2026-05-22T13:24:07Za225cc28237aa988f28ecb83492f75fd490b4a60e45510154d64f6b2af9134b0
apex-onearrestbotnetciscocriticalcve-2026-34926cve-2026-9082drupalfirst-vpngrafanakimwolfmicrosoftpatchprivilege-escalation','remote-code-executionransomwareredsunsecure-workloadsupply-chaintanstacktoken-compromisetrendaiundefendvpnvulnerabilityzero-day

What happened

Multiple high-severity security events reported: Canadian arrest of a suspected Kimwolf botnet operator and disruption/arrest of an administrator of the 'First VPN' cybercrime service used by ransomware groups. Several critical software vulnerabilities were disclosed and patched — TrendAI Apex One directory traversal (CVE-2026-34926) exploited in the wild, a highly critical unauthenticated Drupal flaw exposing sites to info disclosure/privilege escalation/RCE (CVE-2026-9082), and a critical Cisco Secure Workload REST API auth/validation flaw granting Site Admin privileges; Microsoft also fixed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
a225cc28237aa988f28ecb83492f75fd490b4a60e45510154d64f6b2af9134b0
Enrichment time
2026-05-22T13:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Canadian Man Arrested for Operating Kimwolf Botnet · Baitaphish