logo

Critical Wazuh bug exploited in growing Mirai botnet infection

ID: 40a9190d-0d9c-5b98-bc4d-16316aba3507

STIX ID: report--40a9190d-0d9c-5b98-bc4d-16316aba3507

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-06-10

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Researchers observed active exploitation of a critical Wazuh RCE (CVE-2025-24016, 9.9) being used to deploy Mirai variants and the Resbot botnet; attackers leveraged publicly shared PoC code and targeted IoT devices and legacy router vulnerabilities. The campaigns have been observed in the wild by Akamai and Kaspersky, and Wazuh released a patch in October 2024 (4.9.1) — upgrading to patched versions will mitigate the attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.