Seems overblown. They said crypto, gaming, gambling, advertising, and marketing sites were the biggest targets. Not exactly critical stuff.
As far as botnets… Let orgs or agencies either patch the devices or disconnect them. Seems like there should be an agency that scans for problematic devices and takes action automatically.