NetNut proxy network disrupted, 2 million infected devices cut off
2026-07-04T13:23:28Z•d82f6759b1ffc66a9f46892d3095523b1550dd2d76995bf427764e2fe9f38466
ARTokenChocoPoCCisco-Unified-CMClickFixConsentFixEvilTokensFortiBleedLynxMFA-bypassMicrosoft-365NetNutOAuthPaste-ProtectPhaaSRATScattered-SpiderSharePoint-RCEShinyHuntersactive-exploitationbotnetdata-breachphishingransomwareresidential-proxytrojanized-PoC
What happened
A batch of high-impact security stories: law enforcement (with Google) disrupted the NetNut residential proxy network, cutting off access to ~2 million compromised Android devices and streaming boxes. A new phishing-as-a-service called ARToken—tied to the EvilTokens ecosystem—exposes a comprehensive Microsoft 365 phishing toolkit; related OAuth-based MFA bypasses (ConsentFix and ClickFix) are highlighted and being mitigated (e.g., Opera's new Paste Protect). CISA and vendors warn that a high-severity Microsoft SharePoint RCE patched in May is now actively exploited, and Cisco confirmed active/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d82f6759b1ffc66a9f46892d3095523b1550dd2d76995bf427764e2fe9f38466
- Enrichment time
- 2026-07-04T13:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.