The botnet that scouts before it strikes. [Research Saturday] episode artwork

EPISODE · Aug 15, 2026 · 27 MIN

The botnet that scouts before it strikes. [Research Saturday]

from CyberWire Daily · host N2K Networks

Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The research and executive brief can be found here: Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation

Episode metadata supplied by the publisher feed · Published Aug 15, 2026

Embed this episode

NOW PLAYING

The botnet that scouts before it strikes. [Research Saturday]

0:00 27:13

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of CyberWire Daily?

This episode is 27 minutes long.

When was this CyberWire Daily episode published?

This episode was published on August 15, 2026.

Can I download this CyberWire Daily episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!