Canadian Man Arrested for Operating Kimwolf Botnet
2026-05-22T13:24:07Z•a225cc28237aa988f28ecb83492f75fd490b4a60e45510154d64f6b2af9134b0
apex-onearrestbotnetciscocriticalcve-2026-34926cve-2026-9082drupalfirst-vpngrafanakimwolfmicrosoftpatchprivilege-escalation','remote-code-executionransomwareredsunsecure-workloadsupply-chaintanstacktoken-compromisetrendaiundefendvpnvulnerabilityzero-day
What happened
Multiple high-severity security events reported: Canadian arrest of a suspected Kimwolf botnet operator and disruption/arrest of an administrator of the 'First VPN' cybercrime service used by ransomware groups. Several critical software vulnerabilities were disclosed and patched — TrendAI Apex One directory traversal (CVE-2026-34926) exploited in the wild, a highly critical unauthenticated Drupal flaw exposing sites to info disclosure/privilege escalation/RCE (CVE-2026-9082), and a critical Cisco Secure Workload REST API auth/validation flaw granting Site Admin privileges; Microsoft also fixed
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- a225cc28237aa988f28ecb83492f75fd490b4a60e45510154d64f6b2af9134b0
- Enrichment time
- 2026-05-22T13:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.