CVE Tools
Back to feed
Exploited in the wild JDY botnet Volt Typhoon ddos-botnet malware

JDY Botnet Resurges: China-Nexus IoT Army Hunts New Vulnerabilities Within Hours

Daily CyberSecurity (securityonline.info)·By Do Son··4 min read
CVE Tools coverage

Black Lotus Labs reports that the China-nexus JDY botnet has grown and is again scanning the internet for newly disclosed vulnerabilities within hours, using masked infrastructure and scanning techniques designed to blend into normal traffic. Compromised devices include Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, and the activity is notably tied to Fortinet systems following publication of CVE-2026-35616. The fast weaponization window matters because edge and embedded deployments are often harder to monitor and patch, increasing the chance of pre-patch probing and exploitation.