- Evooo1BotName of the new Mirai-based Linux botnet.
443Port used for encrypted C2 communications.
The threat landscape continues to accelerate as attackers move swiftly to exploit newly disclosed vulnerabilities and deploy sophisticated malware variants. Today's security briefing covers active exploitation campaigns, advanced persistent threat activity, and infrastructure-level compromises that demand immediate attention from security teams worldwide.
A newly identified Mirai-based modular Linux botnet named Evooo1Bot has emerged as a significant threat to internet-facing gateway devices. The malware targets routers and similar network infrastructure, converting them into SOCKS5 traffic relay nodes that can be leveraged for obfuscating malicious traffic and conducting distributed attacks. This modular approach allows attackers to customize the botnet's functionality across compromised devices, expanding its operational flexibility. Source: New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud is already under active exploitation just three days after its patch release, according to threat intelligence firm Defused. The rapid weaponization of this flaw demonstrates the compressed window between vulnerability disclosure and real-world attack deployment. Organizations running SAP Commerce Cloud environments face urgent pressure to apply available patches before attackers can establish persistent access to their systems. Source: Max severity SAP Commerce Cloud flaw now targeted in attacks
Advanced persistent threat group HoneyMyte has significantly enhanced its CoolClient backdoor by integrating a kernel-mode rootkit driver, substantially increasing its evasion capabilities. The new variant can hide malicious processes, files, and network connections from security tools and threat analysts, making detection and incident response substantially more difficult. This upgrade reflects the group's commitment to maintaining persistent access within compromised enterprise environments and underscores the escalating sophistication of nation-state cyber operations. Source: APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
An unpatched zero-day vulnerability in GeoServer has become the target of active exploitation campaigns. The security defect is characterized as an SQL injection flaw that enables attackers to achieve remote code execution on affected systems. The rapid exploitation of this vulnerability highlights the critical importance of timely patching and monitoring for zero-day indicators across open-source geospatial infrastructure deployments. Source: Hackers Exploiting Unpatched GeoServer Zero-Day
Security teams should prioritize patch deployment for SAP Commerce Cloud systems, implement network segmentation to limit router compromise impact, and increase monitoring for GeoServer exploitation attempts. The convergence of multiple active threats underscores the need for elevated vigilance across all infrastructure layers.
Source articles and extracted indicators (defanged where appropriate).
443