#ZeroBot
Pilot the mighty ZeroBot to save the world from rampaging AI-driven machines in this top-down shooter.

This is Oh! Robot: Legendary Mechanic. Would you play this?
July 9, 2026 at 9:00 PM
Ivan Kapelyukh, Xiaohan Zhang, Stephen James, Laura Herlant, Edward Johns: ZeroBot: Learning from Scratch in Minutes with Generative Real2Sim https://arxiv.org/abs/2609.34010 https://arxiv.org/pdf/2609.34010 https://arxiv.org/html/2609.34010
September 29, 2026 at 6:46 AM
Try the Oh! Robot: Legendary Mechanic demo, a top-down twin-stick shooter where a young pilot and ZeroBot battle rogue AI machines in fast arenas.

Play the demo: playtester.io/oh-robot-legendary-mechanic

#IndieGaming #GameDev #Gaming #IndieDev #IndieGame
May 7, 2026 at 5:31 PM
-More scammers arrested in Cambodia
-OnlyFake admin indicted
-Kimwolf botnet linked to Canadian man
-Meta sues malicious advertisers
-Malicious Go module deploys backdoor
-New bot attack targets GitHub repos
-New SonicWall scanning
-Reports on AeternumC2, Zerobot, MawaStealer, Moonrise RAT, 1Phish
March 2, 2026 at 9:15 AM
~Akamai~
Zerobot malware is actively exploiting critical RCEs in Tenda routers and the n8n automation platform to spread.
-
IOCs: 144. 172. 100. 228, 140. 233. 190. 96, 0bot. qzz. io
-
#Malware #ThreatIntel #Zerobot
Zerobot Malware Exploits n8n Platform
www.akamai.com
February 28, 2026 at 4:01 AM
Already blocked zerobot accts are so transparent. I don't know why ppl don't screen more bios. TT is rampant with zero bots and everyone argues with them anyway. So glad ppl are abandoning.
January 22, 2025 at 10:32 PM
ZeroBot

ZeroBot is an advanced voice-enabled chatbot that enables users to engage in verbal conversations through a web browser. This innovative product represents a major leap i

aitoolsmarketer.com/ai-tool...

#AITools #AITool #AI
June 12, 2025 at 8:46 PM
BlueKit's browser-in-the-middle streams your live login session to attackers - MFA doesn't save you. https://intel.threadlinqs.com/threat/TL-2026-2315 #ThreatIntel #BlueKit #ZeroBot #ScreenConnect
September 3, 2026 at 7:34 PM
Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware
Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware
A Mirai-based botnet campaign known as Zerobot has resurfaced with renewed force, this time targeting critical flaws in Tenda AC1206 routers and the n8n workflow automation platform. The campaign, now operating on its ninth known iteration — dubbed zerobotv9 — has been actively exploiting recently disclosed command injection vulnerabilities to spread malware across exposed networks and connected devices.​ Zerobot first emerged in 2022, when security researchers documented its operations as a Go-based malware focused on IoT devices. The newer version, zerobotv9, is a notably different threat. Unlike its predecessor, the latest variant is not written in Go — it is smaller in file size, UPX packed, and carries encrypted strings along with a hard-coded command and control (C2) domain of 0bot.qzz[.]io. This evolution signals that Zerobot’s operators have been actively refining their tools over time.​ Akamai researchers identified active exploitation attempts of these vulnerabilities in mid-January 2026, through the team’s global network of honeypots. The campaign traces back to at least early December 2025, making this one of the first confirmed cases of active exploitation of these specific CVEs since their public disclosure in 2025. The research was conducted by Kyle Lefton, a security researcher on Akamai’s SIRT with deep experience in threat research and cyber defense.​ The two key vulnerabilities being exploited are CVE-2025-7544 and CVE-2025-68613. CVE-2025-7544, published in mid-July 2025, is a critical stack-based buffer overflow in the  /goform/setMacFilterCfg  endpoint of Tenda AC1206 devices running firmware version 15.03.06.23. An attacker can trigger this flaw remotely by passing an oversized value through the  deviceList  parameter, enabling both denial-of-service (DoS) and remote code execution (RCE). CVE-2025-68613, published in mid-December 2025, is a critical RCE vulnerability in n8n’s workflow expression evaluation system, affecting versions 0.211.0 through 1.22.0. The absence of proper sandboxing allows attackers to run arbitrary code, steal API keys, access server files, and establish persistence.​ What makes this campaign particularly alarming is its targeting of n8n alongside traditional IoT hardware. Botnets have historically gone after routers, cameras, and DVRs — not enterprise automation platforms. Since many organizations rely on n8n to connect databases, automate data processing, and manage sensitive systems, a successful compromise could open serious pathways for lateral movement within an organization’s critical infrastructure.​ Infection Mechanism and Payload Delivery Once a vulnerable Tenda router or n8n instance is identified, Zerobot triggers the relevant exploit and forces the target device to download and execute a malicious shell script called  tol.sh  from a U.S.-based IP address (144.172.100.228). This script copies busybox to the  /tmp  directory, assigns execution permissions, then fetches and runs the main Mirai malware payload — zerobotv9. The payload supports multiple CPU architectures, a common trait of Mirai-based downloaders built for broad device compatibility.​ The exploit triggers the buffer overflow by passing 500 repeated characters through the  deviceList  parameter. The n8n attack sending commands via the workflow API to execute  tol.sh  and load the same payload. The zerobotv9 binary embeds hard-coded user-agent strings that mimic legitimate browser traffic to blend in and avoid network detection . The malware includes attack methods such as TCPXmas, Mixamp, SSH, and Discord — capabilities that exceed those of the original 2022 Zerobot variant. The botnet was further observed targeting CVE-2017-9841, CVE-2021-3129, and CVE-2022-22947, using fallback connection techniques including netcat, socat, and Perl socket methods.​ Organizations running Tenda AC1206 on firmware 15.03.06.23 should patch immediately or replace aging hardware. n8n users must upgrade beyond version 1.22.0, restrict access to the workflow execution interface, and enforce strict user privilege controls. Network defenders should block or monitor the known malicious IPs — 103.59.160.237, 140.233.190.96, 144.172.100.228, 172.86.123.179, and 216.126.227.101 — and the C2 domain  0bot.qzz[.]io . Applying the YARA and Snort detection rules published by the Akamai SIRT will further help teams identify and respond to related activity across their networks. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware appeared first on Cyber Security News .
cybersecuritynews.com
March 3, 2026 at 5:23 PM
Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware
cybersecuritynews.com/zerobot-malw...
Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware
Zerobotv9 revives Mirai-style attacks, exploiting Tenda routers and n8n flaws to spread malware via C2 domain 0bot.qzz[.]io.
cybersecuritynews.com
March 3, 2026 at 7:13 PM
Zerobot Malware Exploits Tenda Command Injection Vulnerabilities to Deploy Malicious Payloads
gbhackers.com/zerobot-malw...
Zerobot Malware Exploits Tenda Command Injection Vulnerabilities to Deploy Malicious Payloads
An active Zerobot campaign abusing two critical vulnerabilities CVE-2025-7544 in Tenda AC1206 routers and CVE-2025-68613 in the n8n workflow automation platform.
gbhackers.com
March 3, 2026 at 4:08 PM
Zerobot Malware Targets n8n Automation Platform
Zerobot Malware Targets n8n Automation Platform
www.akamai.com
March 1, 2026 at 5:39 AM
📢 Zerobot (Mirai) exploite des failles Tenda AC1206 et n8n pour propager son botnet
📝 Selon Akamai Security Intelligence and Response Team (SIRT), une campagne …
https://cyberveille.ch/posts/2026-03-02-zerobot-mirai-exploite-des-failles-tenda-ac1206-et-n8n-pour-propager-son-botnet/ #IOC #Cyberveille
March 2, 2026 at 9:00 PM
Zerobot Malware exploiting Tenda Command Injection Vulnerabilities to Deploy Malware:

cybersecuritynews.com/zerobot-malw...
March 4, 2026 at 7:20 AM
Feed: "Cyber Security News"
By: Varshini on Wednesday, March 4, 2026
Tenda Routers Hit By Zerobot Malware Exploiting Command Injection Flaw
Akamai's Security Incident Response Team (SIRT) has discovered an ongoing botnet campaign dubbed Zerobot that exploits recently
cyberpress.org
March 4, 2026 at 6:05 PM
Feed: "Cyber Security News"
By: Tushar Subhra Dutta on Tuesday, March 3, 2026
Zerobot Malware Exploiting Tenda Command Injection Vulnerabilities to Deploy Malware
Zerobotv9 revives Mirai-style attacks, exploiting Tenda routers and n8n flaws to spread malware via C2 domain 0bot.qzz[.]io.
cybersecuritynews.com
March 3, 2026 at 11:23 PM
各位資安先進,早安!我是總編輯。今天這份資安日報,保證讓各位醒腦。先別急著喝咖啡,看看我們今天的頭條:Zerobot殭屍捲土重來,這次盯上了騰達和n8n,提醒各位設備要打好疫苗啊!VMware雲端也出了點小狀況,雲端服務商們繃緊神經!再來聊聊AI和零信任,這兩個夯到爆的議題,別光趕流行,先問問自己夠不夠了解。資安可視性,聽起來很高大上,但可能成為壓垮 SOC 的最後一根稻草?最後,泰坤釣魚平台終於被全球聯手瓦解,大快人心!讓我們一起深入剖析這些事件,提升防禦力,讓駭客哭哭喔!

🔐 協會小編報到!今日資安新聞精選!

📚
icsda.org.tw/security-new...
資安新聞|資安漏洞與個資外洩日報 – 2026年03月05日 今日10大焦點
各位資安先進,早安!我是總編輯。今天這份資安日報,保證讓各位醒腦。先別急著喝咖啡,看看我們今天的頭條:Zerobot殭屍捲土重來,這次盯上了騰達和n8n,提醒各位設備要打好疫苗啊!VMware雲端也出了點小狀況,雲端服務商們繃緊神經!再來聊聊AI和零信任,這兩個夯到爆的議題,別光趕流行,先問問自己夠不夠了解。資安可視性,聽起來很高大上,但可能成為壓垮 SOC 的最後一根稻草?最後,泰坤釣魚平台終於被全球聯手瓦解,大快人心!讓我們一起深入剖析這些事件,提升防禦力,讓駭客哭哭喔!
icsda.org.tw
March 5, 2026 at 1:50 AM
Zerobot malware resurfaces, exploiting Tenda router vulnerabilities to deploy malicious payloads. Stay vigilant and update your devices! #CyberSecurity #Zerobot #TendaRouters #MalwareAlert Link: thedailytechfeed.com/zerobot-malw...
March 4, 2026 at 4:30 PM
zbputils (⭐️ 16)

ZeroBot-Plugin 的工具库

#go
July 4, 2026 at 12:33 AM
CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform

arc-codex.com
April 18, 2026 at 5:50 AM
Tendaルーターがコマンドインジェクション脆弱性を悪用するZerobotマルウェアに攻撃される

Akamaiのセキュリティインシデント対応チーム(SIRT)は、Tenda AC1206ルーターとn8nワークフロー自動化プラットフォームの最近公開された脆弱性を悪用するZerobotという名称のボットネットキャンペーンが継続中であることを発見しました。 このマルウェアキャンペーンはMiraiボットネットファミリーと関連しており、2026年1月中旬に最初に特定され、デバイスに感染して悪意のあるコードを実行するために幅広い脆弱性を標的にしています。…
Tendaルーターがコマンドインジェクション脆弱性を悪用するZerobotマルウェアに攻撃される
Akamaiのセキュリティインシデント対応チーム(SIRT)は、Tenda AC1206ルーターとn8nワークフロー自動化プラットフォームの最近公開された脆弱性を悪用するZerobotという名称のボットネットキャンペーンが継続中であることを発見しました。 このマルウェアキャンペーンはMiraiボットネットファミリーと関連しており、2026年1月中旬に最初に特定され、デバイスに感染して悪意のあるコードを実行するために幅広い脆弱性を標的にしています。 Zerobotマルウェアは、CVE-2025-7544とCVE-2025-68613という2つの特定のCVEを悪用しており、どちらもAkamaiのグローバルハニーポットが活発な悪用を観察する前に公開されていました。 2025年7月中旬に発見されたこの欠陥は、deviceListパラメータへの入力の不適切な処理に起因し、攻撃者がリモートコードを実行し、潜在的にサービス妨害(DoS)攻撃を開始することができます。 この脆弱性を悪用することで、攻撃者は影響を受けるデバイス上で任意のコマンドを実行できます。 この脆弱性の概念実証(PoC)エクスプロイトが公開されており、脆弱性のあるエンドポイントに細工されたリクエストを送信することで簡単にトリガーできます。 この問題により、攻撃者はn8nワークフローにおける不安全な式の評価を悪用して、サーバー上で任意のコードを実行できます。 認証されていないユーザーは、この脆弱性を悪用して環境変数、APIキー、設定ファイルなどの機密データにアクセスできます。 n8nが様々な業界の重要インフラの運用に使用されていることを考えると、この欠陥はネットワーク内での横展開を可能にする可能性があるため注目に値します。 Zerobotマルウェアキャンペーンは、これらの脆弱性を悪用してMiraiベースのボットネットペイロードをデプロイします。AkamaiのSIRTは攻撃が実際に行われているのを観察し、攻撃者はTendaルーターの脆弱性を悪用してバッファオーバーフローを実行していました。 これにより、ボットネットは悪意のあるシェルスクリプトtol.shをインストールでき、その後、プライマリZerobotマルウェアペイロードをダウンロードして実行します。 攻撃はグローバルハニーポットネットワーク全体で観察され、攻撃者は積極的にリモートコードを実行し、侵害されたシステムの制御を獲得していました。 現在のイテレーションのZerobotは、Vercelホストのドメインからペイロードをダウンロードし、悪意のあるスクリプトを難読化するなど、高度な回避技術を使用しています。 デプロイされると、Zerobotボットネットはコマンド&コントロール(C2)サーバーに接続し、様々な攻撃を実行します。 これらには、ブラウザ認証情報、SSHキー、Gitリポジトリを対象とするマルチステージ情報盗聴ツールキットのダウンロードが含まれ、最終的に機密の開発者データを盗みます。 n8nのような広く使用されているIoTデバイスと重要インフラプラットフォームを標的とすることは、一見無関係な技術の脆弱性がどのように兵器化される可能性があるかを示しています。 Tendaルーターまたはn8nプラットフォームを使用している組織は、これらの継続的な悪用がもたらすリスクを軽減するために、システムを迅速にパッチ適用する必要があります。 定期的な更新、異常トラフィックの監視、ネットワーク検出ツールの活用は、このような脅威から保護するために不可欠です。 翻訳元:
blackhatnews.tokyo
March 4, 2026 at 12:06 PM
Zerobotボットネットが変異してTendaルーターとn8n自動化ハブをハイジャック

悪質なZerobotネットワークは、Tendaルーターとn8n自動化プラットフォームに固有の脆弱性を積極的に悪用し始めました。Akamaiのセキュリティインテリジェンスチームは2026年1月にこのキャンペーンを発見し、独自のハニーポット環境内で大量の攻撃を傍受しました。これらのインシデントは、2025年後半の初期開示後にこれらの特定の欠陥が武器化された初めての確認された事例を表しています。…
Zerobotボットネットが変異してTendaルーターとn8n自動化ハブをハイジャック
悪質なZerobotネットワークは、Tendaルーターとn8n自動化プラットフォームに固有の脆弱性を積極的に悪用し始めました。Akamaiのセキュリティインテリジェンスチームは2026年1月にこのキャンペーンを発見し、独自のハニーポット環境内で大量の攻撃を傍受しました。これらのインシデントは、2025年後半の初期開示後にこれらの特定の欠陥が武器化された初めての確認された事例を表しています。 Miraiの基本フレームワークに基づいて設計されたZerobotは、CVE-2025-7544およびCVE-2025-68613として指定された脆弱性に焦点を当てています。前者はファームウェアバージョン15.03.06.23を実行しているTenda AC1206ルーターに深刻な影響を与えます。setMacFilterCfgハンドラ内に潜む悪質なバッファオーバーフロー欠陥により、攻撃者はdeviceListパラメータを介してリモートから任意のコードを実行できます。脆弱性が暴露された直後に公開されたエクスプロイトのプルーフオブコンセプトの迅速な出現は、犯人たちの努力を大きく加速させました。 後者の脆弱性はn8n内の式評価エンジンと密接に関連しています。0.211.0から1.20.4までのバージョン、および1.21.1と1.22.0のイテレーションは、不用意にホストサーバ上での任意のコマンド実行を許可しており、ワークフロー式の処理中の不十分な分離プロトコルに起因する致命的な見落としです。驚くべきことに、管理者権限をまったく持たないアカウントでもこの欠陥を悪用できます。この隙間を突いて、侵入者はファイルを閲覧・操作し、APIキーに満ちた環境変数を抽出し、その後、被侵害のインフラストラクチャ内に深く根付くことができます。n8nが異なる内部サービスとクラウドベースのプラットフォームを結び付けるために頻繁に使用されていることを考えると、このような侵害は、より広いネットワーク全体にわたる横展開の深刻な危険をもたらします。 Akamaiのアナリストたちは、IPアドレス144.172.100.228から発信されたtol.shという名のスクリプトを取得するための一致した努力をカタログ化しました。このスクリプトは、さまざまなシステムアーキテクチャに合わせたzerobotv9ペイロードを体系的にダウンロードして実行します。悪質なモジュールはUPXパッカーに隠されており、暗号的に難読化された文字列を含み、コマンド・アンド・コントロールドメインである0bot.qzz.ioとの通信を確立しています。そのソースコード内に組み込まれているのは、Miraiの特徴的な認識不可能な初期化文字列であり、その不正なトラフィックを巧みに偽装するために設計されたキュレートされたユーザーエージェントのレパートリーが付属しています。 ドシエ内で説明されているように、このキャンペーンの建築家たちは2025年12月以降に操作を開始し、最初はnetcatとsocatを活用してペイロードを取得してから、curlとwgetに転換しました。新しく生まれた脆弱性の悪用を超えて、Zerobotは絶えずデジタル領域で古くて十分に文書化された欠陥—特にCVE-2017-9841、CVE-2021-3129、CVE-2022-22947—を探し続けています。この戦略は、現代のボットネットの典型的な活動方法を完璧にカプセル化しています:公開された脆弱性開示と既製のエクスプロイトの迅速で日和見的な武器化、システム管理者が必要な防御パッチをデプロイできる前に迅速に攻撃します。 「Zerobot」という名称は元々2022年にFortinetのインテリジェンスブリーフィング内で浮上しました。ただし、その祖先のオペレーターとのいかなるつながりも曖昧さで覆われたままです。このnine iteration(9番目のイテレーション)は、スケールと基本的なプログラミング言語の両方において、その原始的な前身から大きく異なります。しかし、特に暗号XORキー0xDEADBEEFであるMiraiの特定の遺跡的要素を堅固に保持しています。 対応として、Akamaiは侵害の指標の包括的な台帳を配布しており、SnortとYARA防御ルールと、関係するIPアドレスと暗号ハッシュの綿密なレジストリを含んでいます。サイバーセキュリティの最前線は、組織にTendaルーターとn8nデプロイメントを監査し、利用可能なすべての予防的アップデートをすぐに適用し、これらのサービスを外部Webの危険な視線から厳密に隔離することを強く促します。 翻訳元:
blackhatnews.tokyo
March 4, 2026 at 6:57 AM