International Operation Disrupts Sality P2P Botnet
US-led international operation with Europol, CrowdStrike, and Shadowserver sinkholed the 20-year-old Sality P2P botnet, once exceeding one million infected machines.
On August 31, 2026, authorities from the US, Bulgaria, Hungary, and Romania, supported by Europol, CrowdStrike, and the Shadowserver Foundation, disrupted the Sality P2P botnet by sinkholing communications and seizing domains. Sality has operated for over 20 years, at its peak controlling more than one million infected machines used for credential theft, spam, proxy services, crypto-theft, and DDoS attacks, with over 11 million unique IP addresses linked to its infrastructure since 2017. The disruption exploited the botnet's super-peer reputation mechanism by removing legitimate peers via protocol-level manipulation and inserting sinkhole entries into emptied peer lists.
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
Attackers are exploiting unpatched Zimbra servers via CVE-2026-73570; 274 instances compromised, and CISA added the flaw to its KEV catalog.
The Shadowserver Foundation counted at least 274 compromised internet-facing Zimbra Collaboration Suite instances exploited through CVE-2026-73570, up from 155 on August 20. The unauthenticated code injection flaw affects servers with the optional zimbra-snmp package and SNMP notifications enabled, allowing arbitrary OS command execution via crafted SMTP requests. Synacor patched the issue in ZCS v10.1.20 on July 20, 2026, and at least 8,200 instances remain unpatched. CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave US federal civilian agencies three days to remediate and check for compromise.
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
Law enforcement and CrowdStrike disrupted the 23-year-old Sality P2P botnet, isolating 15,000+ infected machines and seizing linked domains.
International law enforcement, working with CrowdStrike and the Shadowserver Foundation, executed a peer-to-peer sinkhole operation against Sality, a botnet active since 2003 that delivered malware to more than 15,000 machines worldwide. Sality's primary payload for eight years was EggJagger, a clipboard hijacker that swaps copied bitcoin and ethereum wallet addresses with attacker-controlled ones, yielding at least $150,000 in stolen cryptocurrency. The US Justice Department, FBI, and DoD Office of Inspector General's Defense Criminal Investigative Service seized Sality-linked domains, with parallel action in Bulgaria, Hungary, and Romania. The Shadowserver Foundation is coordinating with ISPs and CSIRTs to identify infections and notify victims.