NetNut proxy network disrupted, 2 million infected devices cut off

2026-07-03T19:23:26Z5cf0524dec9539e08b5fe1098469ee129ee1ab486d7f63f1a99b219e11451c56
ARTokenAndroid compromiseCisco Unified CMClickFixConsentFixEvilTokensFortiBleedINC ransomwareKubota breach','ChocoPoC','trojanized PoC','RAT','researcher‑focLynxMFA bypassMedtronicMicrosoft 365NetNutOAuthPhaaSSharePoint RCEShinyHuntersactive exploitationbotnetcredential theftdata breachphishingresidential proxyvulnerability

What happened

BleepingComputer roundup (Jul 1–3, 2026) highlighting multiple high-risk threats and incidents: a joint operation disrupted the NetNut residential proxy network that abused ~2 million compromised Android devices; a new ARToken phishing‑as‑a‑service (affiliate of EvilTokens) exposes a comprehensive Microsoft 365 phishing toolkit; ConsentFix/ClickFix OAuth-based MFA bypasses are being abused and mitigations (e.g., Opera Paste Protect) are being rolled out; CISA warns of active exploitation of a high‑severity Microsoft SharePoint RCE and Cisco confirms active exploitation of a Unified CM flaw; a広

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
5cf0524dec9539e08b5fe1098469ee129ee1ab486d7f63f1a99b219e11451c56
Enrichment time
2026-07-03T19:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.