NetNut proxy network disrupted, 2 million infected devices cut off
2026-07-04T07:23:28Z•c367198eeb0a9baad9c5196747a471cff96dc711d192ecb2a83fef474726760f
ARTokenAndroidChocoPoCCisco Unified CMClickFixConsentFixEvilTokensFortiBleedINCLynxMFA-bypassMicrosoft 365NetNutPaste-ProtectPhaaSRATSharePoint RCEShinyHuntersbotnetcredential-theftdata-breachphishingransomwareremote-code-executionresidential-proxy
What happened
Multiple high-impact incidents and active threats were reported: law enforcement and Google disrupted the NetNut residential-proxy network controlling ~2 million compromised Android devices; CISA and others warned that a Microsoft SharePoint RCE patched in May and a Cisco Unified CM flaw patched in June are being actively exploited; the FortiBleed credential-theft campaign has been tied to INC/Lynx ransomware operators; and a ShinyHunters data exposure affected Medtronic. New attacker tooling and tactics are also emerging: the ARToken PhaaS (affiliate of EvilTokens) exposes a Microsoft 365 ph‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- c367198eeb0a9baad9c5196747a471cff96dc711d192ecb2a83fef474726760f
- Enrichment time
- 2026-07-04T07:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.