Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
2026-05-16T07:24:09Z•c2c1dfcfb0c5797f38af0c54bcff463257ab31a92d9c96213943bb204284ccc5
Cisco SD-WANClaw-ChainEximKazuarMicrosoft ExchangeNGINXOpenClawP2P-botnetPraisonAITanStackTurlaactive-exploitationauthentication-bypassbackdoorknown-exploited-vulnerabilitylocal-privilege-escalationmail-transfer-agentmalicious-packagesnode-ipcprivilege-escalationremote-code-executionrubyGemsstate-sponsoredsupply-chainsupply-chain-compromise
What happened
A wave of high‑severity incidents and disclosures: Russian group Turla has refactored its Kazuar backdoor into a modular P2P botnet for stealthy persistent access, while multiple high‑impact vulnerabilities across enterprise infrastructure are being disclosed and actively exploited. Notable issues include a critical authentication‑bypass in Cisco Catalyst SD‑WAN (CVE‑2026‑20182) now on CISA's KEV list and under active exploitation, an Exchange Server XSS/spoofing exploit (CVE‑2026‑42897) used in the wild, Exim Dead.Letter BDAT code‑execution (CVE‑2026‑45185), an 18‑year NGINX rewrite module RⱯ
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c2c1dfcfb0c5797f38af0c54bcff463257ab31a92d9c96213943bb204284ccc5
- Enrichment time
- 2026-05-16T07:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.