CVE Tools

JDY Botnet Resurges: China-Nexus IoT Army Hunts New Vulnerabilities Within Hours

Daily CyberSecurity (securityonline.info)By Do Son

Reported exploitedJDY botnetVolt Typhoon

Our summary

Black Lotus Labs reports that the China-nexus JDY botnet has grown and is again scanning the internet for newly disclosed vulnerabilities within hours, using masked infrastructure and scanning techniques designed to blend into normal traffic. Compromised devices include Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, and the activity is notably tied to Fortinet systems following publication of CVE-2026-35616. The fast weaponization window matters because edge and embedded deployments are often harder to monitor and patch, increasing the chance of pre-patch probing and exploitation.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store