ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

A massive IoT botnet has been uncovered, compromising over 296,000 devices worldwide. What’s more alarming is that hundreds of water treatment systems have been targeted, raising concerns about the potential for catastrophic damage and even loss of life. Meanwhile, a critical vulnerability in Microsoft’s SharePoint platform has been discovered, allowing attackers to remotely execute code on vulnerable servers.

At its core, this IoT botnet is a prime example of how widespread, unsecured internet-connected devices can be exploited by malicious actors. These compromised devices are often used as “bots” to launch DDoS attacks, spread malware, and even participate in cryptocurrency mining operations. The sheer scale of the botnet’s reach – over 296,000 devices worldwide – underscores the gravity of this issue.

But what sets this story apart is the targeting of water treatment systems. It appears that hackers have been actively scanning for vulnerable systems, taking advantage of outdated software or weak passwords to gain access. This raises serious concerns about the potential consequences: imagine a scenario where a compromised system disrupts water supply, leaving communities without access to this vital resource.

So how does it work? Compromised IoT devices typically rely on default or weak credentials, allowing attackers to easily gain control. They then become part of the larger botnet, which can be remotely controlled by its operators. From there, attackers can exploit these devices for their own purposes, whether that’s generating revenue through cryptocurrency mining or conducting more malicious activities.

The targeting of water treatment systems highlights a critical issue: our increasing reliance on connected technologies has created new vulnerabilities that must be addressed urgently. As we continue to integrate technology into all aspects of life, including critical infrastructure, it’s essential to prioritize security and ensure that such systems are properly protected against potential threats.

In the context of this story, one key takeaway stands out: users – particularly those responsible for managing these connected devices or systems – must remain vigilant about patching vulnerabilities and maintaining robust security measures. This includes regularly updating software, changing default credentials, and monitoring network activity for suspicious behavior. By taking proactive steps to secure our digital foundations, we can mitigate the risks associated with this growing threat landscape.


Source: The Hacker News — 2026-08-27