{"podcast":{"title":"CyberWire Daily","slug":"cyberwire-daily-454880","podcast_index_feed_id":454880,"rss_url":"https://feeds.megaphone.fm/cyberwire-daily-podcast","website_url":"https://thecyberwire.com/podcasts/daily-podcast","image_url":"https://megaphone.imgix.net/podcasts/58ab7ae0-def8-11ea-b34c-b35b208b0539/image/8676ed612d7a335a98a9173d70cb11be.png?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress","author":"N2K Networks, Inc.","episode_count":3765,"summary":"The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.","last_synced_at":"2026-09-23T20:18:19.501651+00:00","page_url":"https://stenobird.com/podcast/cyberwire-daily-454880"},"episode":{"title":"The botnet that scouts before it strikes. [Research Saturday]","slug":"the-botnet-that-scouts-before-it-strikes-research-saturday","published_at":"2026-08-15T07:00:00+00:00","page_url":"https://stenobird.com/podcast/cyberwire-daily-454880/the-botnet-that-scouts-before-it-strikes-research-saturday","show_page_url":"https://stenobird.com/podcast/cyberwire-daily-454880","url":"https://thecyberwire.com/podcasts/research-saturday/437/notes","audio_url":"https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW8011515543.mp3","summary":"Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled \"Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation.\" Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The research and executive brief can be found here: Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation","meta_description":"Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1633,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/the-botnet-that-scouts-before-it-strikes-research-saturday/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cyberwire-daily-454880/the-botnet-that-scouts-before-it-strikes-research-saturday.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}