{"id":34492,"date":"2020-04-16T21:44:28","date_gmt":"2020-04-16T21:44:28","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/"},"modified":"2020-04-16T21:44:28","modified_gmt":"2020-04-16T21:44:28","slug":"youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/","title":{"rendered":"You&#8217;re a botnet, you&#8217;ve got a zero-day, so where do you go? After fiber, because that&#8217;s where the bandwidth is"},"content":{"rendered":"<p>Researchers are warning owners of fiber routers to keep a close eye on their gear and check for firmware updates following the discovery an in-the-wild zero-day attack.<\/p>\n<p>The team of Yanlong Ma, Genshen Ye, Lingming Tu, Ye Jin <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/blog.netlab.360.com\/multiple-fiber-routers-are-being-compromised-by-botnets-using-0-day-en\/\">at 360 Netlab<\/a> say that for more than two months it has been tracking active attacks on what it says is a two-part remote code execution attack being used to infect the networking gear from multiple vendors.<\/p>\n<p>The exploit results in the attacker getting total control of the vulnerable Netlink Gigabit Passive Optical Networks routers and at least eight other OEMs. One of the steps, <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.exploit-db.com\/exploits\/48225\">detailed by Exploit-db<\/a>, is known to cause remote command execution.<\/p>\n<p>&#8220;The function formPing() in the Web server program \/bin\/boa, when it processes the post request from \/boaform\/admin\/forming, it did not check the target_addr parameters before calling the system ping commands, thereby a command injection becomes possible,&#8221; Netlab&#8217;s team explained.<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2016\/05\/04\/raincloud_teaser.jpg?x=174&amp;y=115&amp;crop=1\" width=\"174\" height=\"115\" alt=\"patch\"><\/p>\n<h2 title=\"Adobe and Intel add their woes\">April 2020 and \u2013 rest assured \u2013 your Windows PC can still be pwned by something so innocuous as an unruly font<\/h2>\n<p><a href=\"https:\/\/www.theregister.co.uk\/2020\/04\/14\/april_patch_tuesday\/\"><span>READ MORE<\/span><\/a><\/div>\n<p>Another vulnerability is needed to gain access, however, and must be chained with the above bug to actually get control of the vulnerable routers. That limits its scope, but not by much.<\/p>\n<p>Netlab says it is aware of what that second exploit is and has seen it being used in the wild by the Moobot botnet, but because the exploits are ongoing and no fix has been posted for the flaw yet, it is keeping that part under wraps.<\/p>\n<p>Indeed, the researchers note that since the partial proof of concept was posted, two other botnets have been spotted attempting to (unsuccessfully) exploit it.<\/p>\n<p>&#8220;Luckily, unlike Moobot, this botnet author was not aware of the aforementioned precondition, so it did not work out as expected and the scans would mostly fail,&#8221; NetLab noted.<\/p>\n<p>The entire incident reflects what Netlab suspects is a growing class divide in the botnet space between well-backed, professional operators and other groups who rely on less-reliable methods.<\/p>\n<p>&#8220;Apparently while most botnets play catchup games, some have deep resources and probably deep pockets to get hold of the public unknown exploits,&#8221; the team noted.<\/p>\n<p>Interestingly, the researchers say that, dating back to March, they have been attempting to contact Netlink but were told this problem should not be happening because the default config of the device should not have this issue (the reality is different).<\/p>\n<p><em>The Register<\/em> has attempted to get in touch with the India-based company for a response to the report. At least eight other unnamed brands, possibly all OEM vendors, are also thought to be vulnerable.<\/p>\n<p>&#8220;The PoC has been published publicly and various botnets are taking advantage of it already, we informed CNCERT all the details, and we think it is necessary to inform the public this ongoing threat,&#8221; the researchers explain. &#8220;We are not going to share the vendor name though, as we have no idea if there is going to be any action taken by them.&#8221;<\/p>\n<p>In the meantime, Netlab recommends that users remember to regularly check for firmware updates to their routers and other gear. \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1916\/-8373\/practical-tips-for-office-365-tenant-to-tenant-migration?td=wptl1916\">Practical tips for Office 365 tenant-to-tenant migration<\/a><\/p>\n<p>READ MORE <a href=\"https:\/\/go.theregister.co.uk\/feed\/www.theregister.co.uk\/2020\/04\/16\/fiber_routers_under_fire\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two-step attack seen on core systems Researchers are warning owners of fiber routers to keep a close eye on their gear and check for firmware updates following the discovery an in-the-wild zero-day attack.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":34493,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-34492","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>You&#039;re a botnet, you&#039;ve got a zero-day, so where do you go? After fiber, because that&#039;s where the bandwidth is 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"You&#039;re a botnet, you&#039;ve got a zero-day, so where do you go? After fiber, because that&#039;s where the bandwidth is 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-04-16T21:44:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"174\" \/>\n\t<meta property=\"og:image:height\" content=\"115\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"You&#8217;re a botnet, you&#8217;ve got a zero-day, so where do you go? After fiber, because that&#8217;s where the bandwidth is\",\"datePublished\":\"2020-04-16T21:44:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/\"},\"wordCount\":554,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/\",\"name\":\"You're a botnet, you've got a zero-day, so where do you go? After fiber, because that's where the bandwidth is 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is.jpg\",\"datePublished\":\"2020-04-16T21:44:28+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"You&#8217;re a botnet, you&#8217;ve got a zero-day, so where do you go? After fiber, because that&#8217;s where the bandwidth is\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"You're a botnet, you've got a zero-day, so where do you go? After fiber, because that's where the bandwidth is 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/","og_locale":"en_US","og_type":"article","og_title":"You're a botnet, you've got a zero-day, so where do you go? After fiber, because that's where the bandwidth is 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-04-16T21:44:28+00:00","og_image":[{"width":174,"height":115,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"You&#8217;re a botnet, you&#8217;ve got a zero-day, so where do you go? After fiber, because that&#8217;s where the bandwidth is","datePublished":"2020-04-16T21:44:28+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/"},"wordCount":554,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/","url":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/","name":"You're a botnet, you've got a zero-day, so where do you go? After fiber, because that's where the bandwidth is 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is.jpg","datePublished":"2020-04-16T21:44:28+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/youre-a-botnet-youve-got-a-zero-day-so-where-do-you-go-after-fiber-because-thats-where-the-bandwidth-is\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"You&#8217;re a botnet, you&#8217;ve got a zero-day, so where do you go? After fiber, because that&#8217;s where the bandwidth is"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/34492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=34492"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/34492\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/34493"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=34492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=34492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=34492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}