China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
2026-06-10T19:24:12Z•0ab83e02b853646f92eb568aae10c0466116bfc3b0cc022f020b731dea01efd0
CISA KEVChrome V8FortinetHadesIoTJDYLangflowLinux kernelLiteLLMMiasmaPyPIRCERoguePlanetVeeamWinRARactive exploitationbotnetcommand injectionpath traversalprivilege escalationscanningstate‑sponsoredsupply chainvulnerabilityzero-day
What happened
A broad wave of high-impact security activity: a China-linked JDY botnet now exceeds 1,500 SOHO/IoT devices and is being used for large-scale scanning and reconnaissance; multiple critical remote code execution and command-injection flaws were disclosed and patched (Fortinet, Veeam, LiteLLM) while several high‑severity bugs and zero-days are being actively exploited (Chrome V8, Langflow, Check Point IKEv1 bypass). Public PoCs and exploits have been published (Microsoft Defender RoguePlanet PoC, Linux kernel local root), supply‑chain attacks continue (PyPI Hades / Miasma), and legacy flaws are仍
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0ab83e02b853646f92eb568aae10c0466116bfc3b0cc022f020b731dea01efd0
- Enrichment time
- 2026-06-10T19:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.