Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Rondodox botnet targets 56 N-day flaws in worldwide attacks
    Security

    Rondodox botnet targets 56 N-day flaws in worldwide attacks

    PineapplesUpdateBy PineapplesUpdateOctober 12, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Rondodox botnet targets 56 N-day flaws in worldwide attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Rondodox botnet targets 56 N-day flaws in worldwide attacks

    A new large-scale botnet called Rondodox is targeting 56 vulnerabilities in more than 30 different devices, including flaws first revealed during Pwn2Own hacking competitions.

    The attacker focused on a wide range of exposed devices including DVRs, NVRs, CCTV systems and web servers and has been active since June.

    The Rondodox botnet takes advantage of what Trend Micro researchers call an “exploit shotgun” strategy, where multiple exploits are used together to maximize infection, even if the activity is very noisy.

    since FortiGuard Labs Discovers RondodoxThe botnet appears to have expanded the list of exploited vulnerabilities, including CVE-2024-3721 and CVE-2024-12856.

    Large scale N-day exploitation

    one in report Today, Trend Micro says Rondodox exploits CVE-2023-1389, a flaw in the TP-Link Archer AX21 Wi-Fi router that was originally revealed at Pwn2Own Toronto 2022.

    Pwn2Own is a hacking competition held twice a year by Trend Micro’s Zero Day Initiative (ZDI), where white-hat teams demonstrate exploits for zero-day vulnerabilities in widely used products.

    Rondodox TP-Link flaw exploit timeline
    Rondodox TP-Link flaw exploit timeline
    Source: Trend Micro

    Security researchers note that botnet developers pay close attention to exploits exposed during Pwn2Own incidents, and move quickly to weaponize them, as Mirai did in 2023 with CVE-2023-1389.

    Below is a list of post-2023 N-Day faults that Rondodox has added to its arsenal:

    • Digivar – CVE-2023-52163
    • QNAP – CVE-2023-47565
    • LB-Link – CVE-2023-26801
    • TrendNet – CVE-2023-51833
    • D-Link – CVE-2024-10914
    • TBK – CVE-2024-3721
    • char-faith – CVE-2024-12856
    • Netgear – CVE-2024-12847
    • Avitek – CVE-2024-7029
    • Totolink – CVE-2024-1781
    • Tenda – CVE-2025-7414
    • Totolink – CVE-2025-1829
    • MeteorBridge – CVE-2025-4008
    • Edimax – CVE-2025-22905
    • Linksys – CVE-2025-34037
    • Totolink – CVE-2025-5504
    • TP-Link – CVE-2023-1389

    Old faults, especially in devices that have reached end of life, are a significant risk as they are more likely to be unfixable. Having the latest in supported hardware is equally dangerous as many users ignore firmware updates after setting up the device.

    Trend Micro also found that Rondodox contains exploits for 18 command injection flaws that have not been assigned a vulnerability ID (CVE). They affect D-Link NAS units, TVT and Lilin DVRs, FiberHome, ASMAX and Linksys routers, BRICCOM cameras, and other unknown endpoints.

    To protect against RondoDox and other botnet attacks, apply the latest available firmware updates for your device and change the EOL device. It is also recommended to partition your network and replace default credentials with secure passwords to isolate critical data from Internet-facing IoTs, or guest connections.


    PICS BAS Summit

    attend Breach and Attack Simulation Summit and experience future of security verificationHear from top experts and see how AI-powered BAS Changing breach and attack simulations.

    Don’t miss the event that will shape the future of your security strategy

    attacks botnet flaws NDay Rondodox Targets Worldwide
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMicrosoft Defender accidentally marked SQL Server as end of life
    Next Article I thought Bose QuietComfort headphones had already reached their peak — then I tried the latest model
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    OpenAI is secretly fast-tracking ‘garlic’ to fix ChatGPT’s biggest flaws: what we know

    December 3, 2025
    Security

    Your Uber driver has a new endeavor: training an AI for cash

    October 18, 2025
    Security

    American Airlines subsidiary Envoy confirms Oracle data breach attack

    October 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.