MalwareBleeping Computer
9.8 — CRITICAL
China-linked JDY botnet expands targeting of U.S. military networks
The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
The JDY botnet, linked to Chinese threat actors, has expanded its targeting scope and reconnaissance efforts in the US military networks, compromising over 1,500 devices with a focus on service discovery, protocol fingerprinting, and flaw-focused reconnaissance.
⚙️Technical Details
CVEs
CVE-2026-35616
Affected Systems
Fortinet ForticlientemsCiscoAraknisMimosa NetworksUbiquitiDrayTekHikvisionLinksys
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
🛡️Recommended Actions
1Ensure routers, firewalls, and IoT devices are running the latest security updates and patches to prevent recruitment into reconnaissance networks.
2Disable unnecessary internet-exposed administrative interfaces and restrict remote management access to reduce external attack surfaces.
3Monitor for unusual outbound scanning activity originating from edge devices and replace default credentials.
📦Affected Products
Fortinet ForticlientemsCiscoAraknisMimosa NetworksUbiquitiDrayTekHikvisionLinksys
🔐NVD Verified DataVERIFIED
CVE-2026-35616 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-284
Affected Products (CPE)
Fortinet Forticlientems
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
