piyokango[verified]@piyokangoActive Exploitation
CISA catalogs multiple high‑severity CVEs with confirmed in‑the‑wild exploitation, available Proof of Concept code, and vendor mitigations, highlighting active threat exploitation.
のらねこ!中華パーツ自作PC本頒布中[verified]@ragemaxActive Exploitation
A new Mirai variant targeting retired D‑Link routers is linked to CVE‑2025‑29635, but the report offers no PoC, exploit code, patches, or detailed technical information.
Nicolas Krassas[verified]@DinosnActive Exploitation
The Mirai botnet is reportedly exploiting CVE‑2025‑29635 against legacy D‑Link routers, indicating active in‑the‑wild usage, but the post provides no further technical or remediation details.
Vivek | Cybersecurity[verified]@VivekIntelActive Exploitation
CVE‑2025‑29635 is being actively exploited by the Mirai botnet via command injection on D‑Link routers, underscoring the need for immediate patches and device replacement.
Elusive[verified]@ElusivePrivacyActive Exploitation
CISA highlights four vulnerabilities that are actively being exploited—affecting SimpleHelp, Samsung MagicINFO, and a D-Link device—alongside recommendations for patch status and device retirement.
Anavem.com[verified]@Anavem_Active Exploitation
An article reports the Mirai botnet is actively exploiting CVE-2025-29635 on D-Link routers, though details on the vulnerability or mitigation remain sparse.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The tweet indicates Mirai botnet is actively exploiting a command injection flaw in discontinued D-Link DIR-823X routers since March 2026, one year after the PoC was disclosed.
Toad Enjoyer[verified]@pondwatcher_medGeneral
The post notes the presence of CVE-2025-29635 on end‑of‑life D‑Link devices and that MikroTik routers labeled ‘SCADA’ are exposed online, but provides no technical details, exploit code, or patch information.