BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
CIPHER
The Vault
Threat Actors
Privacy Threats
Malware IoC
Dashboard
CVEs
Tags
Intel
CIPHERThe VaultThreat ActorsPrivacy ThreatsMalware IoCDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Week in Review: Russian Botnet Conviction, Critical Router Flaws, and Infrastructure Attacks

Week in Review: Russian Botnet Conviction, Critical Router Flaws, and Infrastructure Attacks

March 26, 2026Nation-State & APT3 min readhigh

Originally reported by Security Affairs, The Record

#russian-cybercrime#botnet#infrastructure-attacks#ransomware#router-vulnerabilities#supply-chain#government-shutdown
Share

TL;DR

A Russian national received 24 months in prison for operating botnets used in ransomware attacks against U.S. companies. Meanwhile, active ransomware campaigns disrupted operations at Spain's Port of Vigo and Puerto Rico's driver licensing agency, while TP-Link patched critical authentication bypass flaws in enterprise routers.

Why high?

Multiple high-impact incidents including active ransomware attacks on critical infrastructure (Spanish port) and government services (Puerto Rico), combined with critical router vulnerabilities affecting enterprise networks.

Russian Botnet Operator Sentenced for U.S. Corporate Attacks

Russian national Ilya Angelov, 40, received a 24-month prison sentence for operating a botnet infrastructure used to conduct ransomware attacks against dozens of U.S. companies. According to Security Affairs, Angelov was also ordered to pay a $100,000 fine and a $1.6 million judgment.

The conviction demonstrates ongoing efforts to prosecute cybercriminals operating from sanctioned jurisdictions, though the relatively light sentence may not serve as a significant deterrent for similar operations.

Critical Authentication Bypass Patched in TP-Link Routers

TP-Link released security updates for its Archer NX router series addressing multiple vulnerabilities, including CVE-2025-15517, a critical authentication bypass flaw with a CVSS score of 8.6. The vulnerability affects multiple enterprise router models including NX200, NX210, and NX500 series.

The authentication bypass could allow attackers to install malicious firmware on affected devices, potentially compromising entire network infrastructures. Organizations using these router models should prioritize immediate patching.

Third-Party Breach Exposes HackerOne Employee Data

A data breach at benefits provider Navia Benefit Solutions exposed personal information of nearly 300 HackerOne employees. The incident highlights the persistent risk of supply chain attacks, where threat actors target third-party vendors to access data from their primary targets.

The breach underscores the challenge organizations face in securing data held by external partners, particularly in the benefits and HR technology sector where sensitive employee information is routinely processed.

UK Sanctions Chinese Crypto Platform Over Scam Operations

British authorities sanctioned Xinbi, a Chinese-language cryptocurrency marketplace accused of facilitating large-scale online fraud and human exploitation. The sanctions target the financial infrastructure supporting global scam networks, particularly those operating from Southeast Asian compounds.

The action represents part of broader international efforts to disrupt the cryptocurrency payment rails that enable pig butchering and other romance scam operations.

Government Shutdown Degrades CISA's Cyber Defense Capacity

CISA's acting director warned that the ongoing government shutdown is limiting the agency's cybersecurity operations and contributing to staff resignations. The agency is currently restricted to responding to imminent threats, protecting life and property, and maintaining its 24/7 operations center.

The reduced capacity comes at a time of heightened cyber threats and could impact the agency's ability to coordinate national cyber defense efforts and vulnerability disclosure programs.

Ransomware Disrupts Spanish Port Operations

A ransomware attack forced Spain's Port of Vigo to disconnect network systems and manage cargo operations manually. The port, a major fishing hub, represents the latest critical infrastructure target in an ongoing campaign against transportation and logistics facilities.

The attack follows a pattern of ransomware groups increasingly targeting maritime and port operations, recognizing their economic importance and potential for disruption.

Puerto Rico Licensing Agency Cancels Services After Cyber Incident

Puerto Rico's Centros de Servicios al Conductor (CESCO) canceled all driver's license and vehicle registration appointments following a cyber incident. The agency handles critical government services including license issuance and vehicle registrations across the territory.

The disruption affects essential government services and highlights the vulnerability of state and local government IT infrastructure to cyber attacks.

Sources

  • https://securityaffairs.com/189987/cyber-crime/russian-national-convicted-for-running-botnet-used-in-attacks-on-u-s-firms.html
  • https://securityaffairs.com/189980/iot/patch-now-tp-link-archer-nx-routers-vulnerable-to-firmware-takeover.html
  • https://securityaffairs.com/189969/data-breach/recent-navia-data-breach-impacts-hackerone-employee-data.html
  • https://therecord.media/xinbi-crypto-marketplace-sanctioned
  • https://therecord.media/cisa-acting-chief-warns-shutdown-increasing-risks-leading-to-retention-issues
  • https://therecord.media/port-of-vigo-ransomware
  • https://therecord.media/puerto-rico-gov-agency-cancels-driver-license-appointments-cyber-incident

Originally reported by Security Affairs, The Record

Tags

#russian-cybercrime#botnet#infrastructure-attacks#ransomware#router-vulnerabilities#supply-chain#government-shutdown

Tracked Companies

🇨🇳TP-Link

Related Intelligence

  • Nation-State Roundup: North Korea Hits Crypto Platform, Iran War Escalates Cyber Threats, Healthcare Under Fire

    highMar 18, 2026
  • APT Activity Roundup: Iran-Linked Energy Targeting, Major DeFi Breach, and Critical Infrastructure Vulnerabilities

    highMar 24, 2026
  • Weekly Threat Roundup: npm Supply Chain Attacks, Mirai Evolution, and Router Security Policy

    highMar 26, 2026

Related Knowledge

  • Threat Intelligence Deep Training

    reference
  • MITRE ATT&CK / D3FEND Deep Reference

    reference
  • CIPHER Training: Emerging Threats Deep Dive (2025-2026)

    reference

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Weekly Threat Roundup: npm Supply Chain Attacks, Mirai Evolution, and Router Security Policy

Next Article

Ubuntu Plans GRUB Feature Reduction in 26.10 to Strengthen Secure Boot→