FortiGuard Labs says the ClingSTUN Linux backdoor exploits two dozen flaws in a dozen vendors' gear and carries seven more to spread itself. Exploitation is indiscriminate, so any reachable vulnerable device on those lists, Ivanti's included, can join its proxy pool.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence66
Fortinet says the Mirai-derived botnet bolts a SOCKS5 relay onto compromised routers, cameras and Confluence hosts. Sellable proxy capacity changes what you hunt for.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 63%
- Investor
- Investor 12%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence65
A code injection flaw in Ray is now on CISA's mandatory fix list after BitSight saw a Mirai-derived botnet exploiting it. Compute clusters are being swept with the same traffic as routers.
Reality
- Evidence48
- Adoption55
- Hype gap+22
- Incentives52
- Confidence52
Fortinet says the price was immaterial to its business. For teams budgeting a standalone AI red-teaming and guardrails tool, that is the number that matters.
Reality
- Evidence34
- Adoption18
- Hype gap+32
- Incentives82
- Confidence58
FortiGuard Labs says Evooo1Bot packs SOCKS5 relaying, credential sniffing, SSH spreading and 16 flood modes into one binary across 12 CPU architectures. The tunnel matters more than the flood.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+18
- Incentives58
- Confidence42