The RondoDox botnet is exploiting the React2Shell vulnerability (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. This ongoing campaign has been active for nine months, primarily targeting…
The PowMix botnet has been identified as targeting Czech organizations since at least December 2025. Attackers use malicious LNK files to initiate a PowerShell loader that extracts a ZIP archive, bypasses AMSI…
The RondoDox botnet is exploiting the unpatched XWiki remote code execution vulnerability CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, many servers remain vulnerable,…
The RondoDox botnet is exploiting a critical vulnerability in HPE OneView, identified as CVE-2025-37164, which allows for remote code execution. Check Point has reported large-scale automated attacks leveraging this…
The RondoDox botnet has rapidly expanded, now exploiting 174 vulnerabilities using compromised residential IP addresses. First detected in May 2025, it has generated significant traffic in security honeypots, indicating…
The RondoDox botnet is exploiting the unpatched XWiki remote code execution (RCE) flaw CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, the botnet continues to infect servers,…
Check Point Research has identified a coordinated exploitation campaign by the RondoDox botnet targeting a critical vulnerability in HPE OneView, designated as CVE-2025-37164. This campaign marks a significant…
RondoDox v2, an evolved IoT botnet, has shown a 650% increase in exploit vectors, now encompassing over 75 CVEs. The botnet has transitioned from targeting consumer devices like DVRs and routers to enterprise systems,…