Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

2026-05-15T19:24:11Zcdde70be0fd0dc13b9cc4260d4c60fa60ecdea11035eb133540bb5f94621dbcb
CISA-KEVCisco-SD-WANClaw-ChainEximFragnesiaGemStufferGhostwriterKazuarLinux-LPEMicrosoft-ExchangeNGINXOpenClawPraisonAIRubyGemsTanStackTurlaactive-exploitationcredential-theftnode-ipcpeer-to-peer-botnetpersistencephishingstate-sponsoredsupply-chainzero-day

What happened

A broad set of high-impact threats and disclosures surfaced across multiple vectors: Turla upgraded its Kazuar backdoor into a modular P2P botnet for stealthy persistent access; multiple supply‑chain incidents (TanStack, malicious node-ipc versions, GemStuffer RubyGems) and targeted campaigns (Ghostwriter) were reported; and numerous high‑severity vulnerabilities were disclosed or seen in the wild. Notable CVEs include a maximum‑severity Cisco Catalyst SD‑WAN authentication bypass (CVE-2026-20182) added to CISA KEV and actively exploited, Exchange Server spoofing/XSS exploitation (CVE-2026-428

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
cdde70be0fd0dc13b9cc4260d4c60fa60ecdea11035eb133540bb5f94621dbcb
Enrichment time
2026-05-15T19:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.