Back to Blog
Weekly CISO Digest — Week of 2026-08-17: Linux Botnet Exploits Edge Devices
security-guides

Weekly CISO Digest — Week of 2026-08-17: Linux Botnet Exploits Edge Devices

breachwire TeamAug 17, 20264 min read

Headline Incident: Multi-Functional Linux Botnet Evooo1Bot Discovered Exploiting Multiple Vulnerabilities

FortiGuard Labs has uncovered Evooo1Bot, a Mirai-based Linux botnet targeting edge devices worldwide by chaining at least 10 CVEs, including CVE-2024-29269 and CVE-2025-10123. The botnet’s modular design enables DDoS attacks, SOCKS relay, SSH brute forcing, and credential theft, with robust persistence mechanisms. Evooo1Bot communicates via port 443 to C2 infrastructure and uses loader scripts like wget.sh, making detection challenging. Any organization with vulnerable Linux edge devices is at risk, especially those lagging on patching legacy CVEs. Immediate action is required to audit Linux device exposure, update firmware, and monitor for Evooo1Bot indicators. Failure to act leaves critical infrastructure open to remote compromise and lateral movement.

This Week's Incidents

Clop Ransomware Targets Zebra.com in Major Data Breach

What: Clop ransomware exfiltrated 8TB of sensitive data, including CAD files and databases, from Zebra.com, a $5.6B tech company.
Who's at risk: Large enterprises with valuable IP and insufficient ransomware defenses.
Action: Review ransomware playbooks and ensure offsite, immutable backups are current.

Mustang Panda Upgrades CoolClient Backdoor With Kernel Rootkit

What: Mustang Panda APT deployed a signed kernel-mode driver to hide CoolClient backdoor activity, targeting government entities in Pakistan, Mongolia, Myanmar, and Russia.
Who's at risk: Government agencies and organizations with Windows endpoints.
Action: Hunt for unauthorized drivers and monitor for rootkit behaviors on endpoints.

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

What: Attackers breached the French Tax Authority (DGFiP), exposing income, tax rates, and family data of 678,000 taxpayers.
Who's at risk: European government agencies and citizens with sensitive tax data.
Action: Audit access controls and monitor for misuse of exposed taxpayer information.

Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials

What: Attackers used stolen credentials to access Microsoft Azure environments, exfiltrating millions of records from McDonalds, Vodafone, and Kyndryl.
Who's at risk: All organizations with Azure cloud deployments and weak credential hygiene.
Action: Enforce MFA, rotate credentials, and review Azure audit logs for anomalous access.

Apple warns users of targeted mercenary spyware attacks

What: Apple notified users in 110+ countries of mercenary spyware attacks targeting iOS/macOS devices of journalists, activists, and diplomats.
Who's at risk: High-profile individuals and organizations using Apple devices.
Action: Advise at-risk users to enable Lockdown Mode and update devices immediately.

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

What: APT36 used PATCHCORD malware disguised as VPN installers, leveraging Google Sheets and GitHub Gists for C2, targeting Afghan Telecom and South Asian critical infrastructure.
Who's at risk: Telecoms and government-linked organizations in South Asia.
Action: Block suspicious domains and monitor for PATCHCORD/SHEETCORD indicators.

Over 1,000 Charities Hit by Beacon CRM Data Breach

What: Beacon CRM suffered a breach via a compromised AWS key, exposing encrypted database backups for 1,000+ UK charities.
Who's at risk: Nonprofits and SaaS providers with cloud-based CRMs.
Action: Rotate all cloud access keys and audit for exposed credentials in code artifacts.

RingCentral Social Engineering Campaign Breach

What: RingCentral faced a social engineering attack impacting a subset of customer data, but core services remained unaffected.
Who's at risk: SaaS providers and their customers susceptible to social engineering.
Action: Train staff on social engineering tactics and review customer support authentication flows.

GeoServer Zero-Day Vulnerability Being Actively Probed

What: Attackers are probing a zero-day in GeoServer allowing SQL injection and potential RCE via jsonArrayContains; no patch is available yet.
Who's at risk: Organizations running GeoServer, especially with public endpoints.
Action: Restrict GeoServer exposure, monitor for exploit attempts, and prepare for emergency patching.

Threat Actor Sable Squirrel Uses Expired Domains to Deliver Malware

What: Sable Squirrel controls 10,000+ expired domains (e.g., healthymagination.com, rezilion.com) to deliver RATs and scams, targeting brands like GE, Rezilion, and GitLab.
Who's at risk: Organizations with expired domains and those relying on domain reputation.
Action: Monitor for traffic to expired domains and reclaim or sinkhole high-risk assets.

TeamPCP Behind Supply Chain Attack Impacting Over 2,500 Organizations

What: Supply chain attack on Aqua Security’s Trivy scanner and LiteLLM packages led to credential harvesting across 2,500+ organizations, especially in Germany, Brazil, and France.
Who's at risk: DevOps teams using open-source security and AI packages.
Action: Audit dependencies for compromise and rotate secrets exposed in build pipelines.

Ukrainian Police Raid 94 Fraudulent Call Centers Conducting Financial Scams

What: Police dismantled 94 call centers running bank, investment, and crypto scams, seizing thousands of devices and financial instruments.
Who's at risk: Financial institutions and individuals targeted by phishing calls.
Action: Update fraud detection rules and educate users on vishing and investment scams.

City-Forum attacks target Salesforce and ServiceNow user data

What: City-Forum attackers exploited UI-API layers and Service Portal endpoints to access Salesforce and ServiceNow user data, using custom toolsets and advanced leak mapping.
Who's at risk: Enterprises using Salesforce and ServiceNow for sensitive data workflows.
Action: Review API endpoint exposure and monitor for anomalous access patterns.

This Week's Pattern

  • Attackers are chaining old and new vulnerabilities (e.g., Evooo1Bot’s use of 10 CVEs, GeoServer zero-day) to compromise edge devices and cloud environments at scale.
  • Supply chain and credential-based attacks (Trivy, Azure, Beacon CRM) are exposing millions of records, highlighting persistent weaknesses in cloud and open-source security hygiene.
  • Sophisticated social engineering and APT campaigns (RingCentral, Mustang Panda, APT36) are increasingly targeting high-value sectors, requiring enhanced detection, user training, and rapid incident response.

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: