Akamai's SOTI Security report details how agentic AI is reshaping the threat landscape for commerce, with a 19% YoY increase in AI bot traffic and over 200 billion application/API attacks between 2024 and 2025. Attackers are exploiting consumer-facing chatbots through logic manipulation, back-end AI agents via prompt injection, and public AI endpoints for token freeloading. The retail vertical bore the brunt of Layer 7 DDoS activity (84%), with hacktivist groups like 313 Team leveraging Mirai-derived IoT botnets and browser impersonation for multi-vector attacks.
IoT
9 posts
Smash and Grab at Scale: Agentic AI Is Reshaping the Threat to Commerce UAT-7810 continues building ORB networks using new malware UAT-7810, a China-nexus APT actor, continues to build Operational Relay Box (ORB) networks by exploiting n-day vulnerabilities in Ruckus and ASUS AiCloud routers. Talos identified four new malware families — LONGLEASH (an upgraded multi-protocol proxy backdoor), DOGLEASH (a passive C-based Linux backdoor), JARLEASH (a Java-based administrative backdoor), and LEASHTEST (a MIPS test binary) — deployed across MIPS, ARM, and x64 platforms. The actor uses at least four new servers to host payloads and deploy DOGLEASH via shell scripts that modify iptables rules on compromised devices.
Brickcom Cameras (CVE-2026-50245, CVE-2026-50005) Brickcom IP cameras (version 3.2.3.5.6) contain two high-severity vulnerabilities (CVE-2026-50245 and CVE-2026-50005) involving missing authentication on the /ONVIF endpoint and the use of default credentials. Successful exploitation allows attackers with local network access to view live video feeds and potentially gain administrative control. The vendor has not responded to coordination requests, leaving the devices currently unpatched.
Naxclow IoT Platform (CVE-2026-42947, CVE-2026-50108, CVE-2026-50101 +4 more) Seven vulnerabilities, including critical flaws, have been identified in the Naxclow IoT Platform affecting various smart home devices. These vulnerabilities stem from hard-coded cryptographic keys, missing authorization, predictable identifiers, and exposed UART consoles, enabling attackers to perform device takeovers, intercept communications, and extract sensitive network credentials.
April 2026 CVE Landscape In April 2026, 37 high-impact vulnerabilities were actively exploited, heavily impacting enterprise systems and edge infrastructure. Notable exploitation includes the delivery of the Nexcorium botnet via CVE-2024-3721 in TBK DVR devices and complete service takeovers of Nginx UI instances via CVE-2026-33032, a missing authentication flaw.
LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience This article summarizes a LABScon 25 presentation by Joe FitzPatrick on the systemic risks introduced by foreign-manufactured networked devices in critical infrastructure and consumer markets. It highlights issues such as undocumented cellular radios, mandatory product activation, and the ineffectiveness of import bans, advocating instead for hardware bills of materials and right-to-repair legislation.
Intelligence Center Generative AI enables defenders to rapidly deploy highly adaptive honeypots that simulate complex environments like Linux shells or IoT devices. By leveraging LLMs to generate plausible responses to attacker inputs, organizations can deceive automated AI-driven attacks, shifting the defensive strategy from passive detection to active manipulation and intelligence gathering.
CVE-2025-29635: Mirai Campaign Targets D-Link Devices Threat actors are actively exploiting CVE-2025-29635, a command injection vulnerability in end-of-life D-Link DIR-823X routers, to deploy a Mirai botnet variant. The campaign utilizes malicious HTTP POST requests to download and execute shell scripts that fetch the final Mirai payload, while also targeting vulnerabilities in TP-Link and ZTE devices.
A Deep Dive Into Attempted Exploitation of CVE-2023-33538 Unit 42 observed active, automated exploitation attempts targeting CVE-2023-33538, a command injection vulnerability in end-of-life TP-Link routers, to deploy Mirai-like botnet malware. While the observed in-the-wild attacks were flawed and failed, technical analysis confirmed the vulnerability is exploitable if attackers authenticate using default credentials, allowing them to inject shell commands via the ssid1 parameter.