← BACK TO FEED
TAG

ddos2 articles

Weekly Roundup: Zombie Cards, Salt Typhoon Scissors, and GitHub's AI Blame Deflection

This week's cybersecurity roundup covers a range of notable incidents and developments, including CISA mandating fixes for an actively exploited Ray vulnerability, T-Mobile physically cutting a router cable to halt a Chinese state-sponsored intrusion, and researchers demonstrating a "Zombie Card" attack that enables contactless payments using expired Visa cards. Other highlights include a critical GitHub Actions vulnerability discovered by an AI agent (though the flawed code itself was human-written), Medusa ransomware affiliates exploiting GoAnywhere and BeyondTrust vulnerabilities across 500+ critical infrastructure organizations, and data breaches affecting Alation and Japan's Sakura Internet. Rounding out the week, Canadian firm Crypto4A achieved a landmark FIPS 140-3 Level 3 certification for post-quantum cryptography hardware.

22 Aug 2026

C0XMO Botnet Exploits DD-WRT Routers, Evicts Rival Malware to Claim Territory

C0XMO is a new, advanced variant of the Gafgyt botnet that exploits CVE-2021-27137, a buffer overflow vulnerability in DD-WRT router firmware, to spread across multiple device types and CPU architectures. It supports 19 DDoS attack methods, uses a Python-based scanner to brute-force credentials and move laterally across networks, and actively eliminates rival malware and security tools to maintain dominance on infected devices. Researchers at Fortinet describe it as significantly more sophisticated than typical IoT botnets, recommending that users keep devices patched, use strong credentials, and disable unnecessary remote access.

9 Jun 2026