Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

2026-06-01T07:24:12Z3fb7b525e1f81d38cb1430a93a293dd9bd9e45e161cdfa7187fcdcbc475af09c
CVE-2026-0257CVE-2026-27771CVE-2026-39987CVE-2026-45659ChatGPhishEKZ InfostealerFortiClient EMSGREYVIBEGiteaGlassWorm takedownGlobalProtectGogs RCEKimsukyLLM agentMarimoPAN-OSSharePointactive exploitationbotnetmalicious NuGetmalicious npmphishingprompt injectionsupply-chain malwaretakedown

What happened

A collection of high-impact cyber developments: Dutch authorities dismantled a massive botnet of ~17 million infected devices, while multiple actively exploited and high-severity vulnerabilities were reported and patched. Notable faults include PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) under active exploitation, Marimo compromise using CVE-2026-39987 enabling credential theft and LLM-driven post-exploitation, a critical Gogs RCE (CVSS 9.4) allowing code execution, and continued abuse of a critical FortiClient EMS flaw to deploy the EKZ Infostealer. Additional supply-chain and曝

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
3fb7b525e1f81d38cb1430a93a293dd9bd9e45e161cdfa7187fcdcbc475af09c
Enrichment time
2026-06-01T07:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.