[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAZURqTG3t6QHAWh1ZC-wrzCMrg5mVGVY-32DwL_VVss":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"7c70f61a-fd4b-4e74-aafc-4e78e756cdb8","end-of-life-network-devices-exploited-in-active-botnet-campaign","175987fa-25b4-4b9b-a0e6-cbeae2e51d2e","End-of-Life Network Devices Exploited in Active Botnet Campaign","Cybercriminals are actively exploiting a 13-month-old command injection vulnerability (CVE-2025-29635) in end-of-life D-Link routers to build Mirai botnets for DDoS attacks. The vulnerability was publicly disclosed over a year ago, but many organizations failed to patch or replace these devices, leaving them exposed to attack. This incident demonstrates how unpatched network infrastructure becomes a critical attack vector, especially when devices reach end-of-life status and no longer receive security updates. The widespread exploitation across multiple router brands shows that attackers systematically target known vulnerabilities in consumer and small business network equipment.","**Immediate actions:**\n- Replace all end-of-life network devices that no longer receive security updates\n- Apply emergency patches to supported devices with known vulnerabilities\n- Scan network perimeter for exposed devices using the affected firmware versions\n\n**Long-term improvements:**\n- Establish lifecycle management policies for all network infrastructure equipment\n- Implement automated vulnerability scanning for internet-facing network devices\n- Create hardware refresh schedules that replace devices before end-of-life dates\n\n**Detection measures:**\n- Monitor network traffic for unusual outbound connections indicative of botnet activity\n- Deploy network segmentation to isolate IoT and network devices from critical systems",[12,13,14,15,16],"CIS Control 7 - Continuous Vulnerability Management","CIS Control 1 - Inventory and Control of Enterprise Assets","NIST CSF ID.AM-2 - Software platforms and applications","NIST CSF PR.IP-12 - Vulnerability management plan","NIST SP 800-53 SI-2 - Flaw Remediation","published","2026-04-23T03:09:27.365135+00:00","2026-04-23T03:09:27.255+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-mirai-campaign-exploits-rce-flaw-in-eol-d-link-routers\u002F","new-mirai-campaign-exploits-rce-flaw-in-eol-d-link-routers-cf26ec","New Mirai campaign exploits RCE flaw in EoL D-Link routers",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[38],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"d7fb0130-2b99-48dc-8475-a124f8afe7ed","2026-04-23","morning","ThreatNoir Morning Brief — April 23","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-23\u002Fthreatnoir-morning-brief-2026-04-23.mp3"]