The Week in Threats: Fake Logins, AI-Powered Botnets, and Shrinking Patch Windows

From a 296,000-device botnet to hackers borrowing AI tools, this week's threat roundup shows attackers getting faster, quieter, and stranger.

ThreatVectr Newsdesk· 4 min read
Full-frame photoreal editorial image of a cluttered desk with a small home Wi-Fi router glowing faintly, tangled ethernet cables, a laptop screen showing lines
Share

Key points

  • A botnet of roughly 296,000 internet-connected devices, tracked across multiple vendor reports this week, is being used to launch attacks and hide criminal traffic.
  • More than 100 water utility systems were targeted in scans and intrusion attempts, according to reporting first surfaced by The Hacker News.
  • A SharePoint remote code execution chain, meaning a way to run attacker commands on a company's servers, is being actively used against unpatched systems.
  • Criminals are increasingly using AI services and public cloud platforms to disguise their command traffic as normal web activity.
  • The gap between a security patch being released and criminals attacking unpatched systems is shrinking to days, sometimes hours.

This week's threat picture is not one story. It is a pattern. Fake login pages. Fake security scans. Fake productivity apps. Old tricks, still working.

And behind them, quieter shifts: botnets that borrow artificial intelligence, malicious tools that sit still before misbehaving, and attackers who scan the whole internet the moment a flaw is disclosed.

Let's walk through what stood out.

What is the 296,000-device botnet doing?

It is being used as a giant relay network. A botnet is a collection of hacked internet-connected devices, often home routers or cameras, that criminals control from afar. This one is unusually large.

Researchers describe the network as a mix of consumer routers and Internet of Things gear, meaning everyday smart devices. The operators rent it out. Some customers use it for denial-of-service attacks, which flood a target website with junk traffic until it falls over. Others use it to hide the origin of hacking traffic.

Attribution is thin. No single vendor has publicly tied the botnet to a named group with high confidence. Treat any cluster name you see this week as preliminary.

Why are water utilities being targeted?

Because they are soft targets with real-world consequences. More than 100 water systems, mostly small municipal operators in North America and Europe, saw scanning activity and intrusion attempts this week.

Most of the activity looks opportunistic rather than surgical. Attackers probe exposed control panels, try default passwords, and see what opens. A smaller subset of the activity overlaps with tactics previously linked to Russia-nexus groups such as Sandworm (Mandiant's naming) and pro-Russia hacktivist crews. That is medium confidence at best. Capability to disrupt is not the same as intent to disrupt.

For residents: your tap water is not at immediate risk from a port scan. But small utilities do need to get their remote access panels off the open internet.

The SharePoint problem

A chain of flaws in Microsoft SharePoint, the document-sharing platform many companies run internally, is being exploited to run attacker code on servers. Microsoft has published guidance in its security update guide. If your organisation runs on-premises SharePoint, patch now and check for signs of intrusion, not later.

The week at a glance

Story Scale What it means
IoT botnet ~296,000 devices Rented out for attacks and traffic laundering
Water systems 100+ utilities Scans and intrusion attempts, mostly opportunistic
SharePoint chain Active exploitation Unpatched servers at risk of full takeover
AI-abusing malware Multiple families Using public AI APIs to look like normal traffic

Why the patch window keeps shrinking

Because attackers automate. When a vendor publishes a fix, criminals read the advisory, work out what changed, and scan the internet for unpatched systems. What used to take weeks now takes days. Sometimes hours.

A useful mental model: assume any internet-facing system with a fresh advisory against it is under attack by the end of the week. Plan patch cycles accordingly.

What ordinary readers should take from this

Two practical things. Reboot your home router occasionally, and change the default admin password if you never have. That alone would strip thousands of devices out of botnets like this one.

And if a login page looks slightly off, check the web address before you type your password. Fake sign-in pages remain the single most reliable way criminals get in.

© 2026 Threat Vectr