TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

2026-07-15T19:24:11Z82d45c945c5532bec9799e036c7e7f4219a680a0f7f0463f2a197deb29113ed9
AsyncAPICVE-2026-15409CVE-2026-15718CVE-2026-15719CVE-2026-44747FirefoxIoT-botnetLLM-assistedLabubaRAT','CrashStealer','macOS','Cursor-flaw','code-execution'LedgerOkoBotRATSAPSonicWallTrezorTuxBotactive-exploitationhardware-walletmalwarenpmnpm-compromiseseed-phrase-phishingsupply-chainvulnerabilityzero-day

What happened

A large batch of security news: multiple actively exploited and high-severity vulnerabilities (including SonicWall SMA zero-day CVE-2026-15409 with CVSS 10.0 and SAP NetWeaver CVE-2026-44747 at 9.9) and disclosed Firefox WebAssembly/DOM bugs (CVE-2026-15718, CVE-2026-15719). Researchers also reported new malware and fraud toolsets — OkoBot (seed-phrase phishing against Ledger/Trezor apps), LabubaRAT (Rust-based RAT masquerading as NVIDIA software), CrashStealer macOS stealer, and a multi-stage botnet loader delivered via compromised @asyncapi npm packages. Supply-chain and tooling risks appear

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
82d45c945c5532bec9799e036c7e7f4219a680a0f7f0463f2a197deb29113ed9
Enrichment time
2026-07-15T19:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.