Security News > 2021 > March > New botnet targets network security devices with critical exploits

Authors of a new botnet are targeting connected devices affected by critical-level vulnerabilities, some of them impacting network security devices.
Successfully compromised devices end up with a variant of the Mirai botnet malware specific to the architecture of the device.
In mid-February, security researchers at Palo Alto Networks' Unit 42 discovered attacks from this botnet and started to track its activity.
It took about a month for the botnet operator to integrate exploits for ten vulnerabilities, many of them critical, for various targets.
There are more recent exploits leveraged in these attacks, like CVE-2021-22502, a remote code execution bug in the Micro Focus Operation Bridge Reporter product from Vertica.
Unit 42 researchers say that three of the vulnerabilities the attackers exploit have yet to be identified as the targets remain unknown.
News URL
Related news
- Stealthy Apache Tomcat Critical Exploit Bypasses Security Filters: Are You at Risk? (source)
- Don't Overlook These 6 Critical Okta Security Configurations (source)
- PolarEdge Botnet Exploits Cisco and Other Flaws to Hijack ASUS, QNAP, and Synology Devices (source)
- 89% of Enterprise GenAI Usage Is Invisible to Organizations Exposing Critical Security Risks, New Report Reveals (source)
- Ballista Botnet Exploits Unpatched TP-Link Vulnerability, Targets Over 6,000 Devices (source)
- NetBird: Open-source network security (source)
- Ongoing Cyber Attacks Exploit Critical Vulnerabilities in Cisco Smart Licensing Utility (source)
- Android Malware Exploits a Microsoft-Related Security Blind Spot to Avoid Detection (source)
- Still Using an Older Version of iOS or iPadOS? Update Now to Patch These Critical Security Vulnerabilities (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-02-08 | CVE-2021-22502 | OS Command Injection vulnerability in Microfocus Operation Bridge Reporter 10.40 Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. | 9.8 |