174 Vulnerabilities Targeted by RondoDox Botnet

2026-03-17T13:24:08Zd7ad5319ef61c24cc93df3f64a7569e26aa4b296dc194803938dd234c3085ab3
AI-powered attacksAPI abuseCVE-2025-47813China-linkedCloudflareDDoSDKIMForceMemoGlassWormLayer 7Oracle EBSRondoDoxSEO poisoningStorm-2561Wing FTPbotnetcredential theftespionagephishingsupply-chain/GitHub compromisevulnerability exploitation

What happened

Multiple SecurityWeek reports describe an active and widening threat landscape: the RondoDox botnet is conducting up to ~15,000 exploitation attempts/day and now targets 174 distinct vulnerabilities; CISA says CVE-2025-47813 (Wing FTP) is being exploited in the wild; Akamai warns of coordinated Layer‑7 DDoS, API abuse and AI‑powered attacks; and nation‑state actors conducted long, patient espionage against Asian militaries. Other incidents include Storm‑2561 distributing fake VPN clients via SEO poisoning to steal credentials, a sophisticated DKIM‑signed phishing campaign targeting a security‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
d7ad5319ef61c24cc93df3f64a7569e26aa4b296dc194803938dd234c3085ab3
Enrichment time
2026-03-17T13:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.