Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries
2026-03-13T07:24:09Z•4ec15ec8045c4435d89ca4881e2c50e620fa573ed6c7704e5ef2479baf7d0e55
AI‑generated malwareCISACVE-2025-68613CVE-2026-21666CVE-2026-21667CVE-2026-27493CVE-2026-27577FortiGateHive0163KadNap','router malware'RCERust malwareSlopolySocksEscortUNC6426VENONVeeambotnetcrates.iomalicious cratesn8nnx npmproxyremote code executionsupply chain
What happened
A collection of high‑impact security events and disclosures: international law enforcement dismantled the SocksEscort residential‑router proxy botnet (~369,000 IPs); Veeam released patches for multiple critical Backup & Replication RCEs (notably CVE-2026-21666/21667); n8n was added to CISA's KEV for an RCE (CVE-2025-68613) and researchers disclosed additional critical n8n RCEs (CVE-2026-27577, CVE-2026-27493). Other highlights include a new Rust‑based VENON banking malware targeting Brazilian banks, AI‑assisted Slopoly malware used by Hive0163, active exploitation and mass‑scanning activity (e
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 4ec15ec8045c4435d89ca4881e2c50e620fa573ed6c7704e5ef2479baf7d0e55
- Enrichment time
- 2026-03-13T07:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.