Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

2026-06-01T01:24:10Z88b3cc696b99392c68d4cd0bc96531b75bcd7b23c58a960bf1fd44d02593b8a0
APTCVE-2026-0257CVE-2026-27771CVE-2026-39987CVE-2026-45659EKZ-InfostealerGREYVIBEGiteaGlassWormGogs-RCELLM-agentMarimoMicrosoft-SharePointactive-exploitationauthentication-bypassbotnetbotnet-takedowncredential-theftmalicious-packagenugetpan-ospost-exploitationsoftware-supply-chainsupply-chainvpn-bypass

What happened

A broad set of high-impact cyber incidents and vulnerabilities were reported: Dutch authorities dismantled a massive botnet of ~17 million infected devices; multiple high/critical vulnerabilities are being actively exploited (PAN-OS GlobalProtect authentication bypass CVE-2026-0257, Marimo notebook compromise via CVE-2026-39987, Microsoft SharePoint RCE CVE-2026-45659, Gitea private-image exposure CVE-2026-27771, and a critical Gogs RCE rated CVSS 9.4). Threat actors continue supply-chain and credential-theft campaigns (malicious NuGet packages targeting Sicoob, GlassWorm developer supply‑side

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
88b3cc696b99392c68d4cd0bc96531b75bcd7b23c58a960bf1fd44d02593b8a0
Enrichment time
2026-06-01T01:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.