Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
2026-06-01T01:24:10Z•88b3cc696b99392c68d4cd0bc96531b75bcd7b23c58a960bf1fd44d02593b8a0
APTCVE-2026-0257CVE-2026-27771CVE-2026-39987CVE-2026-45659EKZ-InfostealerGREYVIBEGiteaGlassWormGogs-RCELLM-agentMarimoMicrosoft-SharePointactive-exploitationauthentication-bypassbotnetbotnet-takedowncredential-theftmalicious-packagenugetpan-ospost-exploitationsoftware-supply-chainsupply-chainvpn-bypass
What happened
A broad set of high-impact cyber incidents and vulnerabilities were reported: Dutch authorities dismantled a massive botnet of ~17 million infected devices; multiple high/critical vulnerabilities are being actively exploited (PAN-OS GlobalProtect authentication bypass CVE-2026-0257, Marimo notebook compromise via CVE-2026-39987, Microsoft SharePoint RCE CVE-2026-45659, Gitea private-image exposure CVE-2026-27771, and a critical Gogs RCE rated CVSS 9.4). Threat actors continue supply-chain and credential-theft campaigns (malicious NuGet packages targeting Sicoob, GlassWorm developer supply‑side
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 88b3cc696b99392c68d4cd0bc96531b75bcd7b23c58a960bf1fd44d02593b8a0
- Enrichment time
- 2026-06-01T01:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.