Threat Brief — 2026-08-16 — Router botnet hits 4 Tbps
Dysphoria, a new botnet targeting outdated home routers via UPnP, has reportedly assembled enough capacity to generate 4 Tbps of attack traffic — a significant escalation in the consumer-router botnet space. Separately, a Chinese open-source AI model (GLM-5.3) claims to have uncovered over a thousand critical vulnerabilities across hundreds of open-source projects, raising the stakes on both AI-assisted offense and the patch backlog it creates for defenders.
Top items
- Dysphoria botnet achieves 4 Tbps via UPnP-hijacked home routers. The botnet separates its proxy functionality from its DDoS module and automates UPnP port forwarding to turn consumer routers into attack infrastructure. This mirrors the recent Evooo1Bot trend of router-based relay nodes but at a potentially much larger scale. Outdated home routers with exposed UPnP are the primary attack surface. (src: RSS:securitylab-ru)
- Chinese GLM-5.3 model finds 1,000+ critical vulnerabilities in open-source code. The open model scanned hundreds of open-source projects and reported over a thousand critical bugs, demonstrating that AI-driven vulnerability discovery at scale is no longer theoretical. This compounds the pressure on OSS maintainers already struggling with AI-generated dependency velocity and reinforces the call from developers for early defensive AI access. (src: RSS:securitylab-ru)
Themes
Router botnets are consolidating as a prime DDoS vector. Dysphoria follows Evooo1Bot (first reported 2026-08-15) in repurposing consumer routers as proxy and attack nodes, suggesting a broader commodification of SOHO router exploitation. UPnP exposure remains a persistent enabler that network teams should audit.
AI is now weaponised on both sides of the vulnerability lifecycle. GLM-5.3's mass discovery of critical flaws parallels ongoing concerns about AI-generated code introducing unvetted dependencies faster than review can keep pace (first reported 2026-08-13). The asymmetry between attacker-side AI scanning and defender-side patching capacity is widening.
