IoT Botnets Still Exploit Default Credentials, 2026 Notices Reveal Asset Management Gaps
China's National Network and Information Security Notification Centre published a notice in late August 2026 identifying five active cross-border botnet families — Mirai, CondiBot, Gafgyt, TBot, and SoftBot — with command-and-control nodes spread across at least five countries. Analysts note that the attack methods remain unchanged from years past, relying on Telnet and SSH brute-force attacks against factory-default credentials and long-disclosed vulnerabilities. A newer botnet variant called KATARU, analysed by Nozomi Networks in August 2026, follows the same entry path, while the separately flagged Dysphoria botnet adds blockchain-based naming services to resist takedowns. Security experts point to three persistent structural failures: unclear device ownership after installation, short or absent firmware update windows, and management interfaces left open with default credentials. Recommended mitigations are largely administrative — maintaining a full device inventory, changing credentials at deployment, and requiring firmware security maintenance clauses in procurement contracts.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in