<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories]]></title><description><![CDATA[<p dir="auto">A fake login page, a fake security scan, and a fake productivity app: pretending to be useful remains one of the easiest ways into a machine. This week’s threat landscape is defined by increasingly deceptive initial access campaigns and a continued shift toward abusing legitimate infrastructure.</p>
<p dir="auto">The headline story involves a massive <strong>296,000-strong IoT botnet</strong> that has been observed borrowing AI-related branding to spread. The botnet’s command-and-control traffic is hiding in plain sight by leveraging public cloud infrastructure. Meanwhile, a separate campaign has targeted <strong>over 100 water and wastewater systems</strong>, indicating a sustained focus on critical infrastructure, though the specific attack vectors remain varied.</p>
<p dir="auto">In the vulnerability space, a <strong>SharePoint RCE chain</strong> has been disclosed, representing a critical risk for enterprise environments that rely heavily on the platform. The attack chain requires multiple steps but ultimately leads to remote code execution. Additionally, researchers have highlighted a new trend where malicious tools deliberately delay their malicious behavior, likely to evade sandbox analysis and automated detonation in security research environments.</p>
<p dir="auto">Beyond these major stories, the weekly roundup includes <strong>27 additional new stories</strong> and significant shifts in exploit development. The consistent theme is that exposed systems are being scanned faster than ever, and the window for patching critical vulnerabilities is shrinking.</p>
<p dir="auto">Key takeaways from the report include:</p>
<ul>
<li>The <strong>296K IoT botnet</strong> is likely composed of vulnerable routers and cameras, with new variants using AI-baiting filenames to trick users into execution.</li>
<li>The <strong>100+ water systems</strong> under attack were targeted via exposed internet-facing interfaces, emphasizing the need for strict network segmentation.</li>
<li>The <strong>SharePoint RCE chain</strong> affects on-premises installations; administrators are urged to check their current patch levels immediately.</li>
<li>Malware authors are increasingly implementing "logic bombs" or time-based triggers to delay malicious payloads, making static analysis more difficult.</li>
</ul>
<p dir="auto">The report also notes a rise in command-and-control traffic blending into legitimate services like public cloud storage and file-sharing platforms, which makes network monitoring significantly harder.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Given the shrinking patch window and the targeting of critical infrastructure, is your organization prioritizing external-facing device inventories and rapid patching, or are you still relying on traditional perimeter defenses?</p>
]]></description><link>https://xploitlk.com/topic/129/threatsday-296k-iot-botnet-100-water-systems-targeted-sharepoint-rce-chain-27-new-stories</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 14:23:13 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/129.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 28 Aug 2026 08:30:28 GMT</pubDate><ttl>60</ttl></channel></rss>