Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
2026-05-16T01:24:11Z•6c3bf728a4dba93d2e460ca8e2a590fc0bc336f6dd68861407174850dca041fc
CISA/KEVCisco Catalyst SD‑WANCobalt StrikeEximGemStufferGhostwriterKazuarLinux kernelMicrosoft ExchangeNGINXP2P botnetRubyGemsTanStackTurlaactive exploitationmalicious packagesnode‑ipcprivilege escalationremote code executionstate‑sponsoredsupply‑chain
What happened
The Hacker News feed highlights a surge of high‑impact security incidents: state‑sponsored activity (Turla converting the Kazuar backdoor into a modular P2P botnet; Ghostwriter targeting Ukrainian government), multiple high‑severity and actively exploited vulnerabilities (notably Cisco Catalyst SD‑WAN CVE‑2026‑20182 added to CISA KEV and Exchange Server CVE‑2026‑42897), several critical RCE/LPE flaws disclosed in widely used server components (NGINX CVE‑2026‑42945, Exim CVE‑2026‑45185, Linux kernel CVE‑2026‑46300), and numerous supply‑chain/malicious package incidents (TanStack supply‑chain,恶意
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 6c3bf728a4dba93d2e460ca8e2a590fc0bc336f6dd68861407174850dca041fc
- Enrichment time
- 2026-05-16T01:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.