ThreatsDay Analysis: 296K IoT Botnet, Water System Attacks, and SharePoint RCE Exploits
The article details a 296K IoT botnet named Dysphoria targeting devices for DDoS attacks and residential proxy functions, alongside a SharePoint RCE chain and multiple emerging threats like AI-integrated botnets and phishing frameworks. It highlights vulnerabilities in critical infrastructure, such as 100+ water systems targeted, and advanced malware tactics including operator-driven phishing and Android fraud bots.
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.
The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different
*** END OF TRANSMISSION ***