FBI Seizes NetNut Domains as Google Disrupts 2M Device Proxy Network
2026-07-03T20:51:44Z•82be14f4341799ccc6b4b6dddaf4b7107e48986e7ed90a2f354536cccf9c824d
FBIFortiBleedGoogleINC-ransomwareJADEPUFFERLLM-exploitLangflowLynx-ransomwareNetNutNextcloud-zero-dayPamStealerProton-Drive-delivery','OpenCTI','threat-intelligence','VMware-1agentic-ransomwarebackup-strategybrowser-extensioncredential-theftcrypto-jackingdomain-seizurefake-interpol-emailsmacOS-malwarephishingransomwareransomware-proof-backupresidential-proxywallet-address-swap
What happened
Feed covers multiple high-impact incidents: FBI and Google disrupted NetNut’s residential proxy network and seized related domains, exposing abuse of ~2 million devices; a new macOS malware (PamStealer) spreads via a fake Maccy clipboard app to harvest passwords, browser data and clipboard contents; FortiBleed credential-theft activity is linked to INC and Lynx ransomware with a Nextcloud zero-day under investigation. Additional items include Sysdig’s JADEPUFFER report on the first documented agentic ransomware operation abusing a Langflow flaw to steal creds and destroy production configs, a‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 82be14f4341799ccc6b4b6dddaf4b7107e48986e7ed90a2f354536cccf9c824d
- Enrichment time
- 2026-07-03T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.