Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

6 / 6 results
Active filter:tag: #iot✕ clear
Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprintinghighperson_alertThreat Actor
person_alertThreat Actor

Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting

Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…

Palo Alto Networks11 Aug · 17:36 UTC
Malicious SIM cards can execute code on IoT cellular modules via RUN AThighbug_reportVulnerability
bug_reportVulnerability

Malicious SIM cards can execute code on IoT cellular modules via RUN AT

Cellular IoT modules (6 of 8 tested, primarily Quectel parts with Qualcomm processors) in EV chargers, industrial routers, car telematics units. Limited phone impact: OPPO Find X5, OPPO Reno 14 F 5G, ASUS Zenfone 9.

The Hacker News11 Aug · 10:05 UTC
OpenWrt DHCPv6 stack overflow allows unauthenticated remote root code executioncriticalbug_reportVulnerability
bug_reportVulnerability

OpenWrt DHCPv6 stack overflow allows unauthenticated remote root code execution

OpenWrt versions prior to 24.10.8 (24.10 branch) and 25.12.5 (25.12 branch). The vulnerability affects the odhcpd DHCPv6 service running as root on all devices with DHCPv6 enabled by default.

CVE-2026-5392128 Jul · 10:56 UTC
Seven unpatched flaws in FatFs library affect millions of embedded deviceshighbug_reportVulnerability
bug_reportVulnerability

Seven unpatched flaws in FatFs library affect millions of embedded devices

FatFs filesystem library used in embedded devices including security cameras, drones, industrial controllers, and hardware crypto wallets. Affects devices reading/writing FAT and exFAT formats on USB drives and SD cards.

FatFs3 Jul · 18:19 UTC
China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Deviceshighperson_alertThreat Actor
person_alertThreat Actor

China-Nexus Actors Expand JDY Botnet to 1,500+ IoT/SOHO Devices

China-nexus state-sponsored threat actors operating the JDY botnet infrastructure. The actors leverage compromised small office/home office (SOHO) routers and IoT devices to build a distributed scanning platform for cyber reconnaissance operations.

The Hacker News10 Jun · 14:08 UTC
Dutch authorities dismantle botnet controlling 17M infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities dismantle botnet controlling 17M infected devices

At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.

The Hacker News31 May · 10:22 UTC