JDY Botnet Resurges: China-Nexus IoT Army Hunts New Vulnerabilities Within Hours
Reported exploitedJDY botnetVolt TyphoonOur summary
Black Lotus Labs reports that the China-nexus JDY botnet has grown and is again scanning the internet for newly disclosed vulnerabilities within hours, using masked infrastructure and scanning techniques designed to blend into normal traffic. Compromised devices include Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, and the activity is notably tied to Fortinet systems following publication of CVE-2026-35616. The fast weaponization window matters because edge and embedded deployments are often harder to monitor and patch, increasing the chance of pre-patch probing and exploitation.
Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.