A Chinese state-aligned botnet now has 1,500 of your neighbors’ routers building a map of the internet, and it’s faster than the one you’re paying Shodan for.

Lumen’s Black Lotus Labs calls the network JDY, and it does one thing well: discover, fingerprint, and continuously remap exposed services from residential and small-business IP space. That’s reconnaissance as a service, run by an operator who doesn’t want you to see it coming. It changes the math on every cybersecurity program that still treats internet-side scanning as background noise.

Meanwhile, on the other end of the recon-to-exploit pipeline, attackers are burning a fresh path traversal bug (CVE-2026-5027) in Langflow, the AI dev platform. The flaw lets unauthenticated callers write arbitrary files on exposed servers. Two stories, one pipeline.

Recon is the new cybersecurity perimeter

JDY runs more than 1,500 small office and home office devices as a coordinated scanner fleet. Centrally controlled. Continuously updated. Operating from IP space that most defender tools rank as benign because it belongs to consumer ISPs.

This matters for a specific reason. Your firewall’s geo-blocking, your threat-protection IP reputation feeds, your SIEM correlation rules all lean on the assumption that residential IPs aren’t actively scanning you. JDY breaks that assumption on purpose.

The botnet maps services at scale. When a new CVE drops with a public proof of concept, the time between “vulnerability disclosed” and “we have a list of every exposed instance” is now measured in hours. And the target list usually comes from a separate recon network that sells, shares, or hands it off to the operators who run the actual exploit.

That’s the part defenders keep underestimating.

Langflow shows the handoff in action

The Langflow story is the other half of the pipeline. CVE-2026-5027 is an unauthenticated path traversal in an AI dev platform that organizations are spinning up in record numbers, often outside IT’s inventory. Active exploitation began before most teams even knew Langflow was running in their environment.

The attackers didn’t have to look hard. Recon networks like JDY had already done that work.

This is the part where defense in depth either pays off or doesn’t. With an accurate edge inventory, mandatory authentication on every internet-exposed service, and threat detection tuned to alert on writes to unusual paths, the Langflow flaw is a bad afternoon. Without those things, it’s an incident response engagement that runs into the weekend.

Notice what’s missing from that paragraph. The patch matters. The lever sits elsewhere. CISA just compressed federal patching deadlines for the worst flaws to three days, which is excellent policy and still slower than the exploit cycle. The recon network finds you before your patch window opens.

Practical moves while the scanners are scanning

Stop treating residential IP space as low-priority noise. Pull six months of edge logs and look for repeat hits from consumer ASNs against your management interfaces, login portals, and API endpoints. The pattern is usually obvious once you look.

Then do the unglamorous inventory work:

  • Map every internet-exposed service you own, including ones spun up by data science and AI teams in the last 90 days.
  • Put authentication and brute-force controls in front of every dev tool, including AI platforms like Langflow, n8n, and their lookalikes.
  • Alert on file writes to anything outside expected directories on web-facing servers.
  • Block or sharply rate-limit known residential proxy ranges hitting management planes.
  • Rehearse an incident response playbook that assumes initial access came through a tool nobody officially deployed.

Security hardening on edge devices matters here too, and not just yours. The SOHO routers that make up JDY are running because nobody patched them. If your workforce has remote employees, your contractor agreements should include consumer-grade router lifecycle requirements. Treat that IP space as a first-class part of your attack surface, because your traffic egresses from it.

One more thing. If you’re running AI development platforms in production or near production, treat them like the unauthenticated APIs they often are. Most ship with weak default auth, generous file system access, and unpatched dependency trees. Put them behind your identity provider. Segment them off your crown jewels. Log every call.

The thread connecting JDY, Langflow, and the new CISA directive is that the attacker workflow is industrialized end to end while the defender workflow isn’t. Recon is automated and continuous. Exploitation runs on a CI/CD cadence. Patching is now a three-day federal mandate. Inventory is still a spreadsheet someone updates when they remember.

Fix the inventory problem first. The rest gets easier.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.