Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
3 / 3 results
highbug_reportVulnerabilityEvooo1Bot botnet exploits 18 CVEs to turn edge devices into SOCKS5 proxies
Internet-facing Linux-based edge devices including routers (NETGEAR, Tenda, D-Link, TP-Link, Zyxel), IP cameras (Hikvision), enterprise appliances (Alcatel OmniPCX, Mitsubishi ME-RTU, Telesquare SDT-CW3B1/TLR-2005KSH), and servers running vulnerable…
highbug_reportVulnerabilityEvooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxies
Internet-facing Linux gateway devices (routers, firewalls, edge appliances). Specific vendors and models not disclosed. Mirai-based malware with modular architecture targeting devices with weak credentials or known vulnerabilities.
highbug_reportVulnerabilityTengu botnet abuses Linux watchdog to force reboots after process kill
Linux-based IoT devices and embedded systems across multiple architectures (i386, amd64, MIPS, ARM, PowerPC, m68k). No specific vendor or device model identified. Devices with exposed Telnet services and weak credentials are primary targets.