Breaking
SecurityConfirmed

Weekly Roundup: Botnet Exploits, T-Mobile’s Cable Snip

SecurityWeek’s weekly roundup covers a Ray bug, Threema DDoS, T-Mobile’s cable cut, Evooo1Bot, and more.

··1 hour ago·4 min read
red padlock on black computer keyboard
Photo by FlyD on Unsplash

In the past week, security teams faced a spectrum of threats ranging from a botnet wielding 174 exploits to a physical cable cut by T-Mobile staff to halt state-sponsored hackers. SecurityWeek’s weekly roundup highlights these developments, offering a snapshot of the evolving threat landscape that might otherwise slip under the radar.

Ray Vulnerability on CISA’s Radar

CISA has ordered federal civilian agencies to prioritize fixing a critical code injection vulnerability (CVE-2025-62593) in Ray-Project Ray. The flaw was added to the Known Exploited Vulnerabilities catalog after threat actors were observed actively abusing it in the wild.

BitSight observed the vulnerability being exploited by RondoDox, a Mirai-inspired botnet that uses a staggering 174 distinct exploits to compromise vulnerable edge devices. The botnet’s wide arsenal suggests a highly automated attack pipeline that can quickly adapt to new vulnerabilities.

GitHub Disputes AI Role in Bug

An autonomous AI tool developed by Wiz successfully identified and exploited a critical GitHub Actions workflow vulnerability in a public Snowflake repository, gaining unauthorized access to the company’s internal Jira tickets. The discovery initially suggested that GitHub Copilot may have introduced the flaw, but GitHub has since clarified that the vulnerable code snippet was entirely human-authored.

This distinction matters: the incident highlights a growing trend of AI-driven security testing, but also underscores the need for careful attribution when assessing the root cause of vulnerabilities.

Threema Battles DDoS Onslaught

Encrypted messaging provider Threema recently endured significant service disruptions following a series of sophisticated, sustained DDoS attacks targeting its infrastructure and colocation partner. To stabilize operations, the company quickly implemented specialized upstream traffic filtering to block the malicious requests before they could reach and overload its servers.

The attacks underscore the resilience challenges that even security-focused platforms face when targeted by well-resourced adversaries.

Evooo1Bot: Linux Botnet Expands

FortiGuard Labs is tracking Evooo1Bot, a highly modular Linux botnet that targets internet-facing devices by exploiting over a dozen known CVEs. Going beyond standard DDoS capabilities, this Mirai variant is equipped with an SSH brute-forcer, credential sniffer, and a SOCKS5 relay module designed to convert infected hosts into persistent proxy nodes for attackers.

The botnet’s multi-functional design represents a growing trend among botnets to offer a variety of malicious services, from DDoS to proxy services, to a broad customer base.

T-Mobile’s Physical Response to Salt Typhoon

To stop an active network intrusion by the Chinese state-sponsored hacking group Salt Typhoon in 2024, T-Mobile’s cybersecurity staff physically cut a compromised router’s network cable with scissors at a Bellevue data center. The incident, reported by Bloomberg, illustrates the extreme measures sometimes necessary to sever an attacker’s foothold.

T-Mobile was targeted in an extensive espionage campaign that impacted several other major US carriers, marking one of the most significant state-sponsored intrusions into US telecommunications infrastructure.

Data Breaches at Alation and Sakura Internet

Data catalog provider Alation confirmed an unauthorized intrusion into its internal network following a recent cyberattack. The hacking group TeamPCP has publicly claimed responsibility for the breach, alleging they successfully exfiltrated 73 gigabytes of sensitive data from the enterprise software company.

In a separate incident, Japanese hosting provider Sakura Internet discovered a severe data breach in its sales management system, potentially compromising contract and membership information for up to 1.36 million users. The massive exposure was identified while security teams were investigating a completely separate malware infection that impacted a small subset of the company’s rental server accounts.

  • 174 distinct exploits used by the RondoDox botnet
  • 73 gigabytes of data allegedly exfiltrated from Alation
  • 1.36 million users potentially affected in Sakura Internet breach

Medusa Ransomware Hits Critical Infrastructure

A joint advisory from CISA, the FBI, and HHS cautions that Medusa ransomware affiliates are rapidly exploiting newly disclosed vulnerabilities in Fortra GoAnywhere and BeyondTrust to compromise critical infrastructure. The updated alert highlights the group’s evolving evasion toolkit, which now includes utilizing Minidump for credential theft and Interactsh dynamic URLs to verify successful network exploitation.

The advisory says over 500 critical infrastructure organizations have been hit to date, underscoring the persistent and widespread threat posed by the group.

Zombie Card Attack: Expired Cards Work?

Academic researchers have demonstrated a new Zombie Card attack that bypasses cryptographic checks to complete contactless payments using physically expired Visa credit cards. By leveraging a smartphone relay setup to alter the expiration date fed to the POS terminal, attackers can exploit a communication gap between the local hardware and the issuing bank.

The attack does not appear to work against Mastercard, American Express and Discover cards, and it does not work against all banks. Visa has not responded to SecurityWeek’s request for comment.

Post-Quantum HSM Milestone

Crypto4A has become the first company globally to achieve FIPS 140-3 Level 3 validation for an HSM supporting all NIST-approved post-quantum cryptographic algorithms. The newly certified QASM module delivers a tamper-resistant foundation to protect sensitive cryptographic keys from the future threat of advanced quantum computing attacks.

This certification is a significant step toward preparing organizations for the post-quantum era, though adoption remains a long-term endeavor.

Why This Week Matters

The breadth of incidents this week—from botnets exploiting dozens of flaws to a physical cable snip—shows that security is not just a technical challenge but also an operational one. The Ray vulnerability’s inclusion on CISA’s list is a reminder that patching remains the first line of defense. The Zombie Card attack, while limited, highlights the need for continuous scrutiny of payment systems. For organizations, these stories reinforce the importance of staying updated on vulnerabilities, preparing for DDoS resilience, and ensuring that even physical access points are considered in incident response plans.

#roundup#vulnerabilities#botnet#ddos#ransomware#post-quantum

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories