TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
2026-07-15T19:24:11Z•82d45c945c5532bec9799e036c7e7f4219a680a0f7f0463f2a197deb29113ed9
AsyncAPICVE-2026-15409CVE-2026-15718CVE-2026-15719CVE-2026-44747FirefoxIoT-botnetLLM-assistedLabubaRAT','CrashStealer','macOS','Cursor-flaw','code-execution'LedgerOkoBotRATSAPSonicWallTrezorTuxBotactive-exploitationhardware-walletmalwarenpmnpm-compromiseseed-phrase-phishingsupply-chainvulnerabilityzero-day
What happened
A large batch of security news: multiple actively exploited and high-severity vulnerabilities (including SonicWall SMA zero-day CVE-2026-15409 with CVSS 10.0 and SAP NetWeaver CVE-2026-44747 at 9.9) and disclosed Firefox WebAssembly/DOM bugs (CVE-2026-15718, CVE-2026-15719). Researchers also reported new malware and fraud toolsets — OkoBot (seed-phrase phishing against Ledger/Trezor apps), LabubaRAT (Rust-based RAT masquerading as NVIDIA software), CrashStealer macOS stealer, and a multi-stage botnet loader delivered via compromised @asyncapi npm packages. Supply-chain and tooling risks appear
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 82d45c945c5532bec9799e036c7e7f4219a680a0f7f0463f2a197deb29113ed9
- Enrichment time
- 2026-07-15T19:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.