Isometric network nodes depicting botnet router attacks and ransomware threats.

Daily Cybersecurity News - June 7, 2026

C0XMO Botnet Targets DD WRT Routers

A Gafgyt variant called C0XMO, discovered by FortiGuard Labs in March 2026, spreads by exploiting CVE-2021-27137, a five-year-old stack buffer overflow in the UPnP service of DD-WRT firmware. Its primary payload is DDoS attacks, supporting 19 attack methods.

It infects devices across multiple CPU architectures and then kills competing malware on the same system to claim resources.

The approach reuses familiar botnet tactics but adds a direct anti-rival step that reduces competition for bandwidth and compute.

The variant adapts quickly across device types after initial router compromise.

Silent Ransom Group Hits Law Firms Via Fake IT Calls

The Silent Ransom Group is calling US law firms pretending to be IT support to steal data fast.

They rely on social engineering over the phone and, when that fails, send operatives physically into law firm offices posing as IT staff to steal data directly from computers.

Victims often hand over access within hours.

This approach reuses classic vishing tactics that extortion crews have run for years. The speed from call to data theft stands out in the report.

The FBI and Mandiant jointly disclosed the campaign. Mandiant tracked attacks from January through May 2026 across dozens of organizations.

SRG has claimed over 100 attacks total, with data from more than 38 firms already published on its leak site..