Is your smart home open to hackers? - Farah
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
England’s 4-2 win over Croatia on Tuesday night offered an early reminder that goals are rarely in short supply at a World Cup. Yet as fans celebrate the action on the pitch, security teams across the US, Canada, and Mexico are focused on a different challenge: protecting the vast network of connected infrastructure that keeps the tournament running. From smart turnstiles and digital ticketing systems to CCTV networks, building management platforms, stadium-wide communications infrastructure and even a smart ball, the 2026 FIFA World Cup is as much a technological undertaking as a sporting spectacle. Organisers must not only deliver matches across three countries and 16 host cities, but also safeguard the interconnected systems that enable millions of supporters to move through venues, access services, and stay connected. Modern stadiums increasingly resemble connected industrial environments, combining lighting controls, environmental management systems, digital signage, access-control technologies, surveillance infrastructure, and communications networks into a single operational ecosystem. “World Cup host cities are currently welcoming millions of people, including players, officials, game sponsors, and media personnel,” says Cynthia Overby, Director of Strategic Security Solutions at Rocket Software. “With many relying heavily on connected devices and public networks, the tournament is creating an unmissable opportunity for cybercriminals to exploit.” Overby says organisations must adopt a layered security strategy that extends beyond traditional network defences. This includes isolating operational technology such as stadium lighting, HVAC systems, and digital signage from corporate IT environments and public-facing networks. The scale of the challenge is amplified by the size of the tournament. Expanded to 48 teams for the first time, the 2026 competition spans multiple jurisdictions, dozens of venues, and millions of visitors. Each host city relies on a complex web of technology providers, telecommunications networks, transport operators, broadcasters, payment platforms, and third-party contractors. That growing interconnectedness is creating
Symphion Inc. has launched The Symphion Managed Endpoint Cybersecurity Operations Program for Printers & Connected IoT, a managed service designed to help organizations continuously secure printers and other connected devices across enterprise networks. The Dallas-based cybersecurity company said the program combines its technology platform and managed operations services into a single offering that addresses what it sees as a growing gap in endpoint security ownership. According to Symphion, responsibility for printer and connected IoT security is often spread across IT, information security, governance, procurement, managed print providers, and device manufacturers, leaving no single group responsible for ongoing cybersecurity operations. The program is designed to integrate printers and connected IoT devices into a continuous cybersecurity management framework. Services include inventory monitoring, configuration and password management, firmware lifecycle oversight, certificate management, remediation support, security baseline enforcement, and reporting. Symphion said the approach is intended to address operational disruptions that can occur when device replacements, firmware updates, technician interventions, or lifecycle changes affect endpoint security settings and identity management. Printers have become a particular focus as organizations expand Zero Trust security initiatives and face increasing audit and compliance requirements. While printers are typically managed for uptime and operational efficiency, Symphion said cybersecurity oversight is often fragmented despite the devices’ growing role within enterprise networks. “Organizations don’t need more tools or staffing burdens,” said Jim LaRoe, CEO of Symphion. “They need an affordable operational model that restores trusted state, reduces risk and enables Zero Trust without disrupting business.” The vendor-agnostic program operates independently of printer manufacturers and managed print service providers, allowing organizations to manage security across mixed device fleets through a single operational framework. Symphion, headquartered in Dallas, specializes in print fleet cybersecurity and connected endpoint security services.
Request unsuccessful. Incapsula incident ID: 239000750000350800-260532731843267
Goldilock offers a device operating at Layer 1 of the OSI stack (i.e., the physical layer) that enables IT, OT or IoT systems to be disconnected from a network whenever a cybersecurity threat has been identified. Email Article All set! This article has been sent to my@email.address. All fields are required. For multiple recipients, separate email addresses with a semicolon. Please Note: Only individuals with an active subscription will be able to access the full article. All other readers will be directed to the abstract and would need to subscribe. The Analyst Team Rik Turner Follow AnalystChief Analyst, Cybersecurity Rik Turner is a chief analyst in Omdia’s cybersecurity team, covering emerging cybersecurity technology trends across all the areas the team researches. Rik has also worked in Omdia’s financial services technology team, with a specialization in capital markets technology. Prior to joining Informa, he worked as an IT journalist, specializing in networking and security. He was also a foreign correspondent in Brazil, where he worked, among others, for the Financial Times and The Economist. More Content By Rik Turner Hollie Hennessy Follow AnalystOT/IoT Cybersecurity Lead Hollie provides insight into the fascinating and fast-moving domain of OT and IoT cybersecurity, covering both cybersecurity and product security across automotive, medical, embedded, and industrial. Hollie has a range of experience in research. She began her career in the legal sector, writing and researching for expert witness reports on the labor market. She then moved into product testing, with a consumer protection focus. In this role, she was responsible for managing comparative tests of various technology and IoT products, as well as regular testing and investigative work into the security of these devices. She has published articles in Which?, produced by the UK’s largest consumer organization and one of the country’s largest subscription magazines, Computing,
The Department of Homeland Security (DHS) Science and Technology Directorate (S&T) has revealed details of the latest space cybersecurity research to help protect critical infrastructure. Through the Aerospace SPARTA framework, S&T has published key resources, including Indicators of Behavior, published in April 2025, and Prioritized Countermeasures, published in March 2026. These resources are meant to enable onboard threat detection and provide actionable information for implementing space cybersecurity. These efforts are seen as major milestones helping secure the space-based capabilities that the U.S’s national critical infrastructure and DHS missions increasingly rely on. DHS revealed details of this research, June 10. SPARTA is a publicly available space-cyber knowledge base of real and lab-tested cyber threats. It’s sourced by the IEEE P3536 Committee, the working group developing standards for space systems cybersecurity design. “Onboard threat detection is critical for space cyber resilience. These industry resources are an important first step in lowering barriers and enabling space systems to be resilient against current and emerging cyber threats,” Ernest Wong, S&T technical lead, said in a statement. The DHS S&T directorate works to develop resources for industry to facilitate future cyber resilient space systems. An open-source reference implementation of threat detectors will be released later this year.
Organizations increasingly use Internet of Things (IoT) products for the mission benefits they can offer, but care must be taken in the acquisition and implementation of this equipment. NIST Internal Report (IR) 8618 summarizes the presentations and feedback received by the NIST Cybersecurity for the Internet of Things (IoT) Program at the hybrid workshop on "Cybersecurity for IoT Workshop: Future Directions” held March 31 – April 1, 2026. The purpose of this workshop was to consider emerging and future trends for IoT technologies and their impact to IoT cybersecurity. Additionally, the workshop was intended to inform updates to NIST Special Publication (SP) 800-213, IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, and the development of future IoT cybersecurity guidelines. NIST plans to release the initial public draft of NIST SP 800-213 Revision 1 on June 24th.
At its annual Unify event, the Connectivity Standards Alliance, of which Apple is a member, marked the latest releases of Matter and Product Security. Building on the momentum of previous Matter releases, Matter 1.6 continues to expand the foundation for more intelligent, interoperable, and context-aware connected environments. This focused feature release enhances how devices interact across ecosystems, improves their ability to adapt to user preferences, and provides a deeper understanding of device status, offering greater visibility into the information consumers need to confidently manage their smart home experience, says Alliance President and CEO Tobin Richardson. Additionally, in response to the growing complexity of global IoT cybersecurity requirements, the release of Product Security 1.1 is the latest evolution of its Product Security Certification Program. Designed to help manufacturers navigate increasingly fragmented regulatory landscapes, version 1.1 expands the program beyond individual devices to support complete IoT systems, including apps, gateways, and remote processes, while introducing new levels of security assurance through independent testing pathways, Richardson says. I hope you’ll help support Apple World Today by becoming a patron. Almost all our income is from Patreon support and sponsored posts. Patreon pricing ranges from $2 to $10 a month. Thanks in advance for your support.
The internet has transformed the way people live, work, and communicate. From smartphones and laptops to smart home devices, connected cars, and industrial systems, billions of devices now rely on internet connectivity to deliver convenience and efficiency. However, this growing digital ecosystem comes with a significant reality: anything connected to the internet can potentially be hacked. Cybersecurity experts have long warned that no internet-connected device is completely immune to cyber threats. While manufacturers and software developers invest heavily in security measures, hackers continuously search for vulnerabilities that can be exploited for financial gain, espionage, disruption, or data theft. As technology evolves, so do the methods used by cybercriminals. One of the primary reasons internet-connected devices are vulnerable is the complexity of modern software. Even the most advanced systems contain millions of lines of code, making it difficult to identify and eliminate every security flaw. A single vulnerability can provide attackers with an entry point into a device, network, or online service. Once access is gained, hackers may steal sensitive information, install malware, or use the compromised system as part of a larger cyberattack. The rise of the Internet of Things (IoT) has further expanded the attack surface available to cybercriminals. Smart televisions, security cameras, doorbells, thermostats, fitness trackers, and even household appliances are now connected to the internet. While these devices offer convenience and automation, many are released with limited security protections or outdated software. As a result, they often become attractive targets for attackers seeking easy access to home or business networks. Businesses are also facing growing cybersecurity challenges. Organizations rely on cloud platforms, remote work technologies, and connected infrastructure to support daily operations. A successful breach can expose customer data, intellectual property, financial records, and confidential communications. High-profile cyberattacks have demonstrated that even large corporations with dedicated security
Contract expected to reach up to 6,000 active offenders, a roughly 6x increase in scale over the previous contract NEW YORK, June 16, 2026 /PRNewswire/ -- SuperCom (NASDAQ: SPCB), a global provider of secured solutions for the e-Government, IoT, and Cybersecurity sectors, today announced that it has signed the contract for and launched the national electronic monitoring (EM) project with Sweden's Prison and Probation Services, the customer, following completion of the customary standstill waiting period and contract negotiations. This project was formally awarded earlier this year through a five-company competitive bid process. The contract establishes SuperCom as Sweden's national EM provider on a far larger scale than its first national project in Sweden, launched in 2019, when it displaced a roughly 25-year incumbent. The total project value is estimated to range from $17 million, reflecting the base case scenario previously announced, to $75 million, the budget published by the customer. The published budget reflects potential expansion through a higher number of active offenders monitored, additional features and capabilities such as alcohol monitoring, the PureOne GPS solution and the Pure Officer mobile device for supervising officers. Revenues recognized by SuperCom will depend on actual usage levels. Sweden has been a pioneer in electronic monitoring for public safety in Europe, with initial probation programs dating back to 1994. The Swedish Prison and Probation Service is undergoing a period of historic expansion, and with it, broader use of electronic monitoring. The nationwide contract is designed to cover all of Sweden's prison and probation electronic monitoring programs, reflecting roughly 6x the scale of the program SuperCom first launched with the same customer in 2019. Under the contract, SuperCom will deploy its PureSecurity Electronic Monitoring (EM) Suite across a broad range of public safety programs, including GPS tracking of offenders, home detention monitoring, and indoor
By Trevor Dearing The European Parliament disabled AI features on staff devices over cybersecurity concerns. Trevor Dearing argues organisations should similarly manage and isolate AI risks. The business world is going all-in on AI. Global AI spending is on course to exceed $500bn this year, yet nearly 90% of analysed AI tools have been exposed to data breaches. The instinct for managing this risk is often binary: leave it on or switch it off. But a third, much more nuanced approach is possible. That choice was on full display earlier this year when the European Parliament disabled built-in AI features on devices issued to lawmakers and staff, concluding it could not guarantee the safety of tools like summarisers and virtual assistants. It was a measured restriction that stopped short of a full operational shutdown and didn’t impact core workplace tools such as email and calendars. At the same time, it exposes the complicated nature of AI, particularly with the growing use of agentic tools that can act autonomously. So how can organisations gain the benefits of advancing AI while keeping control? Why yes/no is a false choice Faced with AI uncertainty, most organisations default to one of two positions. They either impose blanket bans to remove risk entirely or allow AI tools to spread with minimal oversight. Neither is sustainable. While Illumio research found that over half (55%) of security leaders see AI-powered attacks as a major risk, only 19% see unapproved or unmanaged use of large language models as a top concern. Many risk sleepwalking into a major security incident by overlooking the rapid spread of unsanctioned AI within their environments. Part of this risk comes from trying to secure AI using security models that were never designed for it. Traditional security frameworks are built around trusted actors, user
Report issue SEALCOIN QAIT 4 Watchlists DePIN Status What is SEALCOIN? Trending Coins and Tokens - 240RSK Infrastructure Framework RIF $ 0.09238 11.7% - Messari - Ai Pay With Crypto - 263SIREN SIREN $ 0.1147 17.7% - 235ChainOpera AI COAI $ 0.4934 40.4% - SEALCOIN - QAIT - 19Gram (prev. Toncoin) GRAM $ 1.71 2.16%
As reported by Security Affairs, a significant number of internet-connected cameras are found to be streaming live video without any form of authentication, posing a serious privacy and security risk. The investigation by Mysterium VPN highlights that cheap, budget devices are the primary culprits, often lacking basic security measures.A recent analysis by Mysterium VPN revealed that over 21,000 live cameras are accessible online without any login credentials or security barriers. While major brands like Hikvision and Dahua have largely addressed this vulnerability by enforcing mandatory password setup, the issue persists predominantly with low-cost devices. These budget cameras, often utilizing protocols like RTSP, act as open conduits, broadcasting feeds to anyone who discovers their IP address. The report indicates that Japan and the United States have the highest number of such exposed feeds, largely due to residential broadband connections. This lack of security is not a result of hacking but rather a failure to implement basic security practices, such as setting unique passwords.The findings echo the vulnerabilities exploited by the Mirai botnet in 2016, which leveraged default credentials. Despite regulatory efforts to ban default passwords, millions of older devices remain vulnerable, potentially revealing sensitive information about individuals and their routines to strangers.Source: Security Affairs Get daily email updates SC Media's daily must-read of the most current and pressing daily news You can skip this ad in 5 seconds
India is facing a shortage of cybersecurity specialists in emerging areas such as cloud, AI, operational technology and IoT security, even as companies deploy AI systems and prepare for a new generation of machine-speed cyber threats. The country has around 300,000 cybersecurity professionals, but nearly 19% change employers every year, resulting in the same pool of specialists moving between companies instead of expanding the talent base. Around 39,000 cybersecurity positions remain open despite an annual addition of 40,000-60,000 professionals, according to Careernet's India Cybersecurity Talent Outlook 2026. The report also said that demand is highest in domains with the smallest talent pools. IoT and connected devices security recorded a demand ratio of 237% despite having only 4,612 professionals, while blockchain and Web3 security reported a demand ratio of 230% with a workforce of 1,736 specialists. Cloud-native and container security recorded the highest workforce churn at 26.67%, followed by AI and machine learning security at 25.97%, reflecting competition for a limited pool of specialists. "Cybersecurity hiring has become one of the few areas where companies are increasingly unwilling to compromise on quality, even under hiring pressure," said Neelabh Shukla, chief business officer at Careernet. "In cybersecurity, especially across cloud, OT, infrastructure, and AI-led environments, the cost of a capability gap is far more immediate," he said. The shortage comes as organisations adopt agentic AI systems. Research by Veeam Software showed that 93% of Indian organisations are already using or piloting AI agents and 44% have deployed them in production. However, 42% of executives identified risks arising from autonomous agent behaviour and decision chaining as a key factor slowing AI adoption. The pressure on cyber teams has increased following the emergence of Anthropic's Claude Mythos Preview, a restricted AI model that was evaluated by the AI Security Institute and found to represent
Most companies still approach cyber security as if attackers are trying to “break in”. That thinking is outdated. Modern cyber criminals are not smashing through firewalls wearing hoodies in dark rooms. They are logging in through the front door using stolen credentials, hijacked Microsoft 365 accounts and employees who unknowingly hand over access every single day. The uncomfortable reality is this: many businesses are already hosting attackers inside their environments long before anyone notices. By the time ransomware appears on screens or operations grind to a halt, the damage has already been done. Data has been stolen, systems mapped, backups identified and trust compromised. Cyber security is no longer an IT discussion, it’s now a business survival discussion. Every organisation today is a digital business whether it wants to admit it or not. Manufacturing plants rely on connected systems. Retailers depend on online payments and logistics platforms. Professional services firms operate through cloud applications and email. Healthcare environments rely on digital patient information and connected infrastructure. If those systems stop functioning, the business stops functioning. This is why cyber resilience has become one of the defining operational challenges facing modern organisations. The issue is no longer whether a business will be targeted. The issue is whether the business can continue operating when prevention eventually fails. Prevention does fail. Cybercrime has fundamentally changed over the last few years, attacks are now automated, scalable and increasingly powered by artificial intelligence. Criminal groups no longer need deep technical expertise to launch sophisticated attacks. Entire cybercrime ecosystems now operate as commercial businesses complete with subscription models, technical support and ready-made attack kits. Today, attackers can purchase ransomware as a service, phishing kits, stolen credentials and automated attack tools with very little effort. AI generated phishing emails are becoming increasingly difficult to distinguish from legitimate
The oil and gas industry is spending billions on cybersecurity — and much of it is pointed in the wrong direction. Network monitoring tools, vulnerability scanners, and vendor questionnaires are the pillars of most operators’ OT security programs. They’re necessary. They’re also insufficient. Because none of them answer the one question that matters most—what is actually running inside the firmware of the controllers, RTUs, and SCADA systems keeping your pipelines flowing and your refineries processing? That question, paired with the industry’s collective failure to answer it, is the most dangerous blind spot in critical infrastructure security today. The Numbers Are Moving the Wrong Way The threat landscape isn’t abstract. In 2024, Halliburton suffered a ransomware attack that cost $35 million. CISA reported a 145% surge in OT-targeted cyberattacks that same year. Dragos documented an 87% increase in ransomware groups targeting industrial organizations. The average cost of a single OT security incident in oil and gas has reached $4.4 million. These aren’t outliers. They’re a pattern. And the pattern that stems from decades where operational technology lived in isolation, running proprietary protocols on air-gapped networks. IT/OT convergence changed that. Remote monitoring, predictive maintenance, and real-time optimization connected those systems to networks that threat actors have been probing for years. Over this time, however, the underlying equipment stayed the same. I’m referring to fifteen-year-old controllers, firmware that was never designed to face the internet and protocols that predate modern encryption. The attack surface expanded. The software inside the devices didn’t change. And almost nobody has looked inside it. What’s Actually in the Firmware Here’s a real-world example that illustrates the gap. A deep binary analysis was recently performed on firmware from a major RTU vendor widely deployed across upstream oil and gas operations. This is a reputable vendor whose product has passed
Every company selling a networked device, connected component, or software product into the European Union faces a binding new deadline: beginning September 11, 2026, manufacturers must file an early warning with EU cybersecurity authorities within 24 hours of detecting an actively exploited vulnerability in any product on the EU market. Today, June 11, marks the first formal milestone in the CRA's phased rollout — the date on which national authorities were required to designate conformity assessment bodies under the law's Chapter IV — and the window to complete the internal pipeline work that makes 24-hour compliance possible is now measured in weeks, not months. The regulation driving this change is the EU Cyber Resilience Act (Regulation EU 2024/2847), which entered into force on December 10, 2024, and covers virtually any hardware or software product that connects directly or indirectly to a device or network. Consumer smart speakers, home routers, industrial control systems, enterprise software suites, and connected vehicle telematics units are all in scope. Non-compliance can result in product withdrawal from the EU's 450-million-person single market and financial penalties of up to €15 million or 2.5% of global annual turnover, whichever is higher. The most immediate challenge for vendors is not what the regulation requires — the requirements are now clearly documented — but whether the internal engineering, legal, and security operations infrastructure exists to meet a 24-hour notification clock that starts the moment an organization becomes aware of an exploitation, not when it has confirmed or analyzed it. CRA Vulnerability Reporting: What the 24-Hour Pipeline Requires Under Article 14 of the CRA, manufacturers must submit notifications through the ENISA Single Reporting Platform (SRP), a centralized EU web portal that routes each submission simultaneously to the national Computer Security Incident Response Team (CSIRT) of the manufacturer's main EU establishment and
Threat actors have been disguising malware as AI study guides and developer resources to trick professionals into running a multi-stage attack that ends in the AsyncRAT trojan. New analysis from Fortinet's FortiGuard Labs described booby-trapped files with names like "AI-Ready PostgreSQL 18" and a fake guide to agentic coding with Claude Code, all aimed at people hunting for AI learning material. The campaign hits Windows users at any organization, the researchers said, and runs entirely through trusted system tools to stay hidden. Read more on fileless AsyncRAT attacks: Fileless Malware Deploys Advanced RAT via Legitimate Tools Fake Guides Open a Staged Chain The lure plays on the demand for AI know-how. "Attackers are now packaging malware as trusted learning content," said Diana Kelley, CISO at Noma Security, who urged teams to treat downloaded documents and training assets as part of the software supply chain. Inside the archive sits a shortcut (LNK) file and two hidden documents. Opening it triggers a chain of scripts that each pull the next stage from hidden offsets inside one PDF-named data file, decrypting and executing as they go. It plants scheduled tasks disguised as Realtek audio services and opens a clean decoy document, so the victim sees a harmless file while the PowerShell stages run silently. The two files posing as Realtek components are really copies of AutoHotkey, a legitimate automation tool repurposed as an execution engine, so the malicious logic sits in scripts that are harder to fingerprint than compiled binaries. One branch rebuilds a hidden program from numbers in a fake manifest and uses process hollowing to run it inside a real .NET process. The manifest yields two .NET payloads: a modular remote access trojan (RAT) Fortinet tracks as clay_Client, and AsyncRAT, which beacons to its own command-and-control (C2) server. John Gallagher, VP
June 10, 2026 — ABB and Samsung Electronics announced a new integration between ABB Ability Building Pro and Samsung SmartThings Pro, building on their existing partnership. The integration enables building owners and operators to access building data, insights and controls through a more connected environment. Building owners and operators are managing increasingly complex property portfolios while facing growing pressure to improve efficiency and meet sustainability goals. ABB and Samsung are directly addressing that challenge by connecting their respective building intelligence and enterprise IoT platforms, providing greater visibility into building performance through a familiar digital environment. ABB Ability BuildingPro connects devices and data across building systems, enabling analytics and operational insights through ABB Ability BuildingPro Suites. Samsung SmartThings Pro brings these capabilities into the Samsung ecosystem via a secure cloud-to-cloud integration, allowing data to be shared between both platforms. "Building owners require a data foundation they can trust and tools that make it easier to manage increasingly complex building portfolios," said Mike Mustapha, division president, ABB Electrification’s Smart Buildings Division. "By integrating ABB Ability BuildingPro with Samsung SmartThings Pro, we are helping owners and operators access the insights they need to make more informed decisions across their buildings.” “Samsung SmartThings Pro gives enterprise customers a familiar platform to manage and maximize their buildings and assets,” said Chan-Woo Park, executive vice president, Samsung Electronics Device eXperience Division. “Combined with ABB Ability BuildingPro, customers can access building information and controls through a connected experience that helps simplify day-to-day building management.” Together, ABB Ability BuildingPro and Samsung SmartThings Pro provide building operators with a unified view of lighting, climate, shading and access-control systems, alongside energy monitoring and presence detection data. With ABB Ability BuildingPro Suites, operators can access analytics and operational insights to better manage building performance across offices, retail locations and larger commercial
Cybersecurity researchers have warned of a "resurgence and expansion" of JDY, a covert network associated with China-nexus state-sponsored threat actors. "The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale," Lumen's Black Lotus Labs said in a report shared with The Hacker News. JDY was first flagged as a cluster within another botnet codenamed KV-botnet in mid-December 2023. Primarily used for broader scanning against internet targets, the stealthy network comprising compromised SOHO routers, firewalls, and IoT devices has been put to use by Chinese hacking groups like Volt Typhoon. Following KV-botnet's takedown by the U.S. government in early 2024, the botnet operators began making behavioral changes to the network, with the second KV cluster largely going offline. It's suspected that the botnet is offered by the operators to various hacking outfits, while carrying out reconnaissance and targeting on their own. The latest findings from Black Lotus Labs show that the malware has expanded in scope to infect a broader range of devices and act as a conduit to feed "structured reconnaissance data" into a larger scanning ecosystem for follow-on target identification and exploitation. Specifically, the JDY cluster is being used to conduct targeted scanning and service fingerprinting with an aim to flag vulnerable infrastructure following public disclosures. This points to an industrialized reconnaissance effort, the results of which are leveraged by Chinese nation-state groups. This has been complemented by a growth in the botnet's size, which has surged from 650 bots at the start of January 2024 to more than 1,500 compromised devices. Most of the hacked nodes are located in the U.S. and Brazil, followed by Europe and Asia. Black Lotus Labs told The Hacker