Find notable cyber news and cases, enriched with sources, timelines, and signals.

RondoDox persistent IoT and web app botnet campaign

Campaign
First reported
Last updated
Happening score
H score 51
1 unique sources, 1 articles Impact confidence: high

Summary

Hide ▲

RondoDox ran a nine-month campaign against IoT devices and web applications to expand botnet enrollment. The operation began in March-April 2025 with initial reconnaissance and manual vulnerability scanning against exposed systems. By December 2025, the actors were using React2Shell (CVE-2025-55182) against vulnerable Next.js servers, and the payloads included cryptocurrency miners, a botnet loader and health checker, and a Mirai variant. CloudSEK urged defenders to update Next.js and harden IoT exposure.

Cases

Related Happenings

TA416 European government espionage campaign

Campaign
H score32 First: 01.04.2026 15:05 Last: 01.04.2026 15:05 Sources 1

About this happening: TA416 has resumed cyber espionage activity, targeting European governments and EU/NATO diplomatic missions with a renewed malware-delivery operation that raises cross-...

Latest development: 03.04.2026 20:34

TA416 expanded its espionage campaign to Middle Eastern government and diplomatic entities after the outbreak of the U.S.-Israel-Iran conflict in late February 2026, while linking to archives hosted on Google Drive or a compromised SharePoint instance to refine its PlugX delivery chain and collect regional intelligence.

MuddyWater U.S. network intrusion campaign targeting banks, airports, and a software company arm

Campaign
H score42 First: 06.03.2026 12:23 Last: 06.03.2026 12:23 Sources 1

About this happening: MuddyWater (Seedworm) is running a state-linked intrusion campaign that has embedded itself in U.S. banks, airports, a non-profit, and an Israeli software company arm,...

Ariomex leaked database exposing 11,826 verified user records

Data Leak
H score69 First: 03.03.2026 16:30 Last: 03.03.2026 16:30 Sources 1

About this happening: A newly obtained Ariomex database exposed 11,826 verified user records, creating a concrete view of activity tied to sanctions evasion and large-scale capital transf...

React2Shell (CVE-2025-55182) mass scanning and exploitation wave

Exploitation Wave
H score89 First: 20.02.2026 23:07 Last: 20.02.2026 23:07 Sources 1

About this happening: CVE-2025-55182 (React2Shell) was publicly disclosed on December 3, 2025 as a CVSS 10 remote code execution flaw in React Server Components. Since then, the vulnera...

BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms

Campaign
H score33 First: 11.02.2026 00:17 Last: 11.02.2026 00:17 Sources 1

About this happening: Separate analyses described North Korea-linked operators associated with UNC1069 and BlueNoroff using social engineering against cryptocurrency targets and a fin...

Timeline

  1. 01.01.2026 11:19 2 articles · 6mo ago

    RondoDox persistent IoT and web app botnet campaign

    Initial Disclosure

    In March-April 2025, the operation began with initial reconnaissance and manual vulnerability scanning against exposed IoT devices and web applications.

    Show sources