✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Security/Investigations
Breach intelligence, attack campaigns, and threat reports targeting the Security/Investigations sector.
Explore Other Sectors
Security/Investigations Threat Reports
RondoDox Botnet 2025: Mass Exploitation Sheds Light on Multi-Vendor Security Gaps
In October 2025, security researchers uncovered a major campaign involving the RondoDox botnet, which rapidly weaponized over 50 vulnerabilities across more than 30 device vendors. The attack leveraged an "exploit shotgun" approach, targeting a vast range of internet-facing infrastructure including routers, DVRs, NVRs, CCTV systems, and web servers. Threat actors behind RondoDox employed automated scanning and exploitation, compromising vulnerable devices at scale for botnet expansion, distributed denial-of-service (DDoS) attacks, and potential further malicious activity. The operational impact included service degradation, widespread risk of breach propagation, and the exposure of inadequately secured assets across diverse environments. This incident highlights a surging trend in large-scale, opportunistic exploitation—where attackers rapidly integrate newly disclosed vulnerabilities into botnet tools. The scale and automation reflect the growing sophistication of threat actors, amplifying risks for businesses lagging in patch management and segmentation. Regulatory scrutiny is intensifying as such campaigns threaten critical infrastructure and data security.
6 months ago
Kill Chain
RondoDox Botnet Orchestrates Mass n-day IoT Attacks in 2025
In mid-2025, the RondoDox botnet emerged as a powerful threat targeting IoT and network devices by exploiting 56 known (n-day) vulnerabilities across over 30 device types, including routers, NVRs, DVRs, and CCTV systems. The operators, closely monitoring vulnerability disclosures—such as those revealed at Pwn2Own events—rapidly weaponized publicly disclosed exploits, including CVE-2023-1389 and CVE-2024-12856, using a high-volume "exploit shotgun" methodology to maximize infections. With operations observed since June 2025, the campaign affected both end-of-life and actively supported products, resulting in a widespread compromise of infrastructure, particularly among organizations and consumers with unpatched devices. This attack underscores a growing trend of mass exploitation of n-day vulnerabilities in IoT ecosystems, reflecting increasing automation and sophistication among botnet operators. The pace at which attackers operationalize new exploits demands faster patching, improved segmentation, and heightened baseline security practices across networked environments.
6 months ago
Kill Chain
Persistent Exploitation of Hikvision Camera Vulnerabilities (2017–2025): Lessons for IoT Security
Between 2017 and 2025, waves of exploit attempts have targeted Hikvision IP cameras using vulnerabilities such as CVE-2017-7921. Attackers abused easily guessable or default credentials passed via HTTP GET parameters, leveraging weak authentication mechanisms to access sensitive camera endpoints, user configurations, and device data. The entry vector relied on IoT device misconfigurations and insecure design, while brute-force attempts and credential stuffing remain prevalent. This activity has potential to expose live feeds, user data, and create a foothold into internal networks, with implications for privacy, compliance, and physical security. This breach is notable today as attempts to exploit Hikvision and similar IoT cameras continue at scale, highlighting persistent IoT security challenges due to poor credential hygiene, slow patch adoption, and device interface limitations. The incident demonstrates ongoing risk as attackers increasingly automate targeting of legacy and unpatched embedded devices across global networks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports