‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

2026-06-18T19:23:29Z4787ce637a650c0a1dbf20a00e2d151a0054a2b4c95a44e48cd2e17560b8680b
AI support botAWS GovCloudAlarum TechnologiesAndroidCISAGitHub leakInstagram hijackMetaMicrosoft Patch TuesdayNetNutNetherlandsPopaRussia-linked operations」「Kimwolf」「IoT botnet」「DDoS」「Canvas dataThe Gentlemenaccount takeoveradvertising fraudbotnetdata leakhosting seizurelawmakers inquirypublic exploitransomwareresidential proxyvulnerabilitiesweb scraping

What happened

This feed aggregates multiple high-impact security stories: researchers link the Popa Android TV-box botnet to NetNut (Alarum Technologies), alleging its use for residential proxying, ad fraud, account takeovers and mass scraping. A new investigation profiles the operator/administrator behind the ransomware group “The Gentlemen.” Microsoft’s June 2026 Patch Tuesday fixed nearly 200 flaws (dozens rated critical) with public exploit code for several. Attackers abused Meta’s AI support assistant to reset Instagram passwords and hijack high-profile accounts. Dutch authorities seized ~800 servers &

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
4787ce637a650c0a1dbf20a00e2d151a0054a2b4c95a44e48cd2e17560b8680b
Enrichment time
2026-06-18T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.