Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
2026-05-15T19:24:11Z•cdde70be0fd0dc13b9cc4260d4c60fa60ecdea11035eb133540bb5f94621dbcb
CISA-KEVCisco-SD-WANClaw-ChainEximFragnesiaGemStufferGhostwriterKazuarLinux-LPEMicrosoft-ExchangeNGINXOpenClawPraisonAIRubyGemsTanStackTurlaactive-exploitationcredential-theftnode-ipcpeer-to-peer-botnetpersistencephishingstate-sponsoredsupply-chainzero-day
What happened
A broad set of high-impact threats and disclosures surfaced across multiple vectors: Turla upgraded its Kazuar backdoor into a modular P2P botnet for stealthy persistent access; multiple supply‑chain incidents (TanStack, malicious node-ipc versions, GemStuffer RubyGems) and targeted campaigns (Ghostwriter) were reported; and numerous high‑severity vulnerabilities were disclosed or seen in the wild. Notable CVEs include a maximum‑severity Cisco Catalyst SD‑WAN authentication bypass (CVE-2026-20182) added to CISA KEV and actively exploited, Exchange Server spoofing/XSS exploitation (CVE-2026-428
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- cdde70be0fd0dc13b9cc4260d4c60fa60ecdea11035eb133540bb5f94621dbcb
- Enrichment time
- 2026-05-15T19:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.