⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

October 5, 2026

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Ravie LakshmananOct 05, 2026Vulnerability / Malware Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report published last week. "The result is a botnet whose traffic can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling and denial-of-service commands." The operational technology (OT) security company said it observed a spike in attempts to exploit CVE-2021-35394 (CVSS score: 9.8), a critical remote…

CVEs: CVE-2021-35394, CVE-2014-8361, CVE-2016-10372, CVE-2016-20016, CVE-2023-26801, CVE-2023-41011, CVE-2024-3721, CVE-2025-34037, CVE-2026-88772