174 Vulnerabilities Targeted by RondoDox Botnet
2026-03-17T13:24:08Z•d7ad5319ef61c24cc93df3f64a7569e26aa4b296dc194803938dd234c3085ab3
AI-powered attacksAPI abuseCVE-2025-47813China-linkedCloudflareDDoSDKIMForceMemoGlassWormLayer 7Oracle EBSRondoDoxSEO poisoningStorm-2561Wing FTPbotnetcredential theftespionagephishingsupply-chain/GitHub compromisevulnerability exploitation
What happened
Multiple SecurityWeek reports describe an active and widening threat landscape: the RondoDox botnet is conducting up to ~15,000 exploitation attempts/day and now targets 174 distinct vulnerabilities; CISA says CVE-2025-47813 (Wing FTP) is being exploited in the wild; Akamai warns of coordinated Layer‑7 DDoS, API abuse and AI‑powered attacks; and nation‑state actors conducted long, patient espionage against Asian militaries. Other incidents include Storm‑2561 distributing fake VPN clients via SEO poisoning to steal credentials, a sophisticated DKIM‑signed phishing campaign targeting a security‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- d7ad5319ef61c24cc93df3f64a7569e26aa4b296dc194803938dd234c3085ab3
- Enrichment time
- 2026-03-17T13:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.