Find a story

Search Spins

Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.

14 results for “botnet”

SPIN Processed News Frame: The Shield

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

The Russian cyber threat group Sandworm is deploying an upgraded version of the Cyclops Blink botnet malware, exploiting Cisco vulnerabilities to infect network devices.

Spin 40% Source-Supported AI Risk Moderate Needs Evidence
Dark Reading

Sep 15, 2026

SPIN Processed News Frame: The Shield

Sality botnet infrastructure dismantled in joint global takedown

A multinational law enforcement and private-sector operation seized infrastructure supporting the Sality peer-to-peer botnet, disrupting its command-and-control capabilities.

Spin 30% Verified
BleepingComputer

Sep 2, 2026

SPIN Processed News Frame: The Shield

Android Malware Hijacks Update System for Car Head Units

Cybercriminals repurposed a known click-fraud botnet to hijack Android-based car head unit update mechanisms, exploiting legitimate system functionality to deploy malware.

Spin 40% Claim Present in Source AI Risk Moderate
Dark Reading

Aug 27, 2026

SPIN Processed News Frame: The Shield

Hackers infect Android car head units with proxy botnet malware

Hackers exploited the Android car head unit supply chain by hijacking a legitimate device-update app to deploy proxy botnet and ad fraud malware, exposing automotive IoT systems to stealthy, large-scale abuse.

Spin 50% Source-Supported AI Risk Moderate Needs Evidence
BleepingComputer

Aug 22, 2026

SPIN Processed News Frame: The Shield

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

A new Android-based vehicle head unit malware family, discovered by Kaspersky in June 2026, exploits built-in firmware updaters in DoFun-developed automotive infotainment systems to deploy multi-stage payloads enabling ad fraud and proxy botnet operations.

Spin 45% Source-Supported AI Risk Moderate Needs Evidence
The Hacker News

Aug 21, 2026

SPIN Processed News Frame: The Stampede

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

Evooo1Bot, a Linux-based botnet, extends Mirai's original DDoS-focused design by integrating exploitation modules, credential theft, and reverse SOCKS relays—transforming infected devices into long-term, multi-purpose attacker infrastructure.

Spin 65% Source-Supported AI Risk Moderate Needs Evidence
Dark Reading

Aug 17, 2026

SPIN Processed News Frame: The Hype

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Kimwolf v7 is a newly identified Android/IoT botnet variant that uses HTTP/2 to mimic legitimate browser traffic during DDoS attacks, increasing evasion capability against network defenses.

Spin 45% Claim Present in Source AI Risk Moderate
The Hacker News

Aug 12, 2026

SPIN Processed News Frame: The Hype

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Tengu is a Mirai-derived botnet that exploits Linux hardware watchdog timers to force device reboots upon process termination, enabling persistent DDoS operations after defensive intervention.

Spin 30% Source-Supported AI Risk Moderate Needs Evidence
The Hacker News

Jul 28, 2026

SPIN Processed News Frame: The Hype

New Dysphoria DDoS botnet spreads to 200k devices worldwide

A malicious botnet named Dysphoria has infected approximately 200,000 internet-connected devices globally to conduct DDoS attacks and traffic relay operations, representing an active, scalable cyber threat.

Spin 45% Source-Supported AI Risk Moderate Needs Evidence
BleepingComputer

Jul 28, 2026

SPIN Processed News Frame: The Shield

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

A Russian-speaking hacker named 'bandcampro' used Google's open-source Gemini CLI tool to automate parts of a cyberattack against eight dental clinics, including password cracking and botnet command-and-control setup.

Spin 72% Source-Supported AI Risk High Needs Evidence
The Hacker News

Jul 20, 2026

SPIN Processed News Frame: The Shield

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

Cybersecurity researchers disclosed TuxBot v3 Evolution, an IoT botnet framework exhibiting evidence of LLM-assisted development — but with flawed, non-functional code due to the LLM inserting safety disclaimers the developer overlooked.

Spin 75% Source-Supported AI Risk Moderate Needs Evidence
The Hacker News

Jul 16, 2026

SPIN Processed News Frame: The Shield

Google Gemini CLI abused as a hacking agent, malware botnet operator

A threat actor repurposed Google's open-source Gemini CLI tool for malicious hacking and botnet operations, revealing a security vulnerability in how AI command-line tools can be weaponized.

Spin 65% Source-Supported AI Risk Moderate Needs Evidence
BleepingComputer

Jul 16, 2026

SPIN Processed News Frame: The Shield

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four npm packages under the @asyncapi namespace were compromised and used to deliver multi-stage botnet malware, as jointly identified by four security firms.

Spin 35% Claim Present in Source AI Risk Moderate
The Hacker News

Jul 15, 2026

SPIN Processed News Frame: The Shield

NetNut cracked as Google and FBI target 2 million-device botnet - The Register

A joint operation by Google and the FBI disrupted the NetNut botnet, allegedly comprising two million compromised devices, by seizing infrastructure and redirecting traffic to sinkholes.

Spin 65% Source-Supported AI Risk Moderate Needs Evidence
The Register AI / Software via Google News

Published Jul 3, 2026 · Analyzed Jul 7, 2026