New Mirai Variant Targeting Network Security Devices
New Mirai botnet variant exploits nine vulnerabilities in SonicWall, D-Link, Netgear, and other devices, with attacks ongoing at publication.
Unit 42 observed attacks exploiting VisualDoor (SonicWall SSL-VPN), CVE-2020-25506 (D-Link DNS-320), CVE-2020-26919 (Netgear ProSAFE Plus), and other flaws, with infrastructure rotating across at least three IP addresses between February 16 and March 13, 2021. Payloads were updated hours after CVE-2021-27561 and CVE-2021-27562 (Yealink Device Management, unauthenticated root RCE) and later added CVE-2021-22502 (Micro Focus Operation Bridge Reporter) and CVE-2019-19356 (Netis WF2419). Successful exploitation invokes wget to fetch shell scripts that download Mirai binaries compiled for multiple architectures and brute-forcers, and attacks were still ongoing when reported.
CISA Warns of Zimbra OS Command Injection Vulnerability Active Exploitation (CVE-2026-73570)
CISA added actively exploited Zimbra OS command injection flaw CVE-2026-73570 to its KEV catalog, urging users to patch by August 24, 2026.
CISA warned that Zimbra vulnerability CVE-2026-73570 is being actively exploited in the wild and added it to its Known Exploited Vulnerabilities Catalog. The OS command injection flaw resides in the SNMP monitoring component and is exploitable when SNMP notifications are enabled. Users, including US federal agencies subject to BOD deadlines, were urged to apply fixes before the August 24, 2026 deadline. Qualys ThreatPROTECT published tracking coverage of the KEV addition.