Felons, Fraudsters Flog Offensive Cybersecurity Startup

2026-07-12T13:23:32Z0ef0c171a0da69c80850513524270fcf773c698a8b5885768e7e326dea1014db
AWS-GovCloudAlarum TechnologiesCISA-leakDortFBI-seizureKimwolfMeta-AI-abuseMicrosoft-vulnerabilitiesNetNutNetherlands-seizurePatch-TuesdayPopaPopa-botnetScattered-SpiderThe-Gentlemenaccount-takeoverbotnetcredential-exposurefraudhosting-abuseoffensive-security-startuppublic-exploit-coderansomwareresidential-proxy

What happened

KrebsOnSecurity feed (May–Jul 2026) highlights multiple high-impact cyber incidents: the FBI seized hundreds of domains tied to NetNut after researchers linked the company (Alarum Technologies) to the Popa Android-based residential-proxy botnet that enslaved millions of consumer TV boxes for ad fraud, account takeovers and scraping; separate arrests include the alleged Kimwolf botmaster (“Dort”) and Dutch seizures of ~800 servers and two arrests for hosting infrastructure used by Russian ops. Other coverage: a CISA contractor exposed AWS GovCloud credentials and agency secrets (triggering law‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
0ef0c171a0da69c80850513524270fcf773c698a8b5885768e7e326dea1014db
Enrichment time
2026-07-12T13:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.