China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

2026-06-10T19:24:12Z0ab83e02b853646f92eb568aae10c0466116bfc3b0cc022f020b731dea01efd0
CISA KEVChrome V8FortinetHadesIoTJDYLangflowLinux kernelLiteLLMMiasmaPyPIRCERoguePlanetVeeamWinRARactive exploitationbotnetcommand injectionpath traversalprivilege escalationscanningstate‑sponsoredsupply chainvulnerabilityzero-day

What happened

A broad wave of high-impact security activity: a China-linked JDY botnet now exceeds 1,500 SOHO/IoT devices and is being used for large-scale scanning and reconnaissance; multiple critical remote code execution and command-injection flaws were disclosed and patched (Fortinet, Veeam, LiteLLM) while several high‑severity bugs and zero-days are being actively exploited (Chrome V8, Langflow, Check Point IKEv1 bypass). Public PoCs and exploits have been published (Microsoft Defender RoguePlanet PoC, Linux kernel local root), supply‑chain attacks continue (PyPI Hades / Miasma), and legacy flaws are仍

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
0ab83e02b853646f92eb568aae10c0466116bfc3b0cc022f020b731dea01efd0
Enrichment time
2026-06-10T19:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance · Baitaphish