‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

2026-06-22T01:23:28Z4a86a1fea4b987b5e8b014a8c678fffb3bfaa1d05e3ba72c3d37230f7e289a7c
AI social engineeringAWS GovCloudAlarum TechnologiesAndroid botnetCISACanvas breachInstagram compromiseIoT botnet arresteserver seizuresKimwolfMetaMicrosoft vulnerabilitiesNetNutPatch TuesdayPopaThe Gentlemenaccount takeoveradvertising fraudbotnetcredentials leakdata exfiltrationdata scrapingeducation data extortionpublic exploitsransomwareresidential proxy

What happened

A collection of high-impact security stories from May–June 2026 describing multiple large-scale incidents and investigations: researchers link the Popa Android TV-box botnet to NetNut/Alarum Technologies, a major record-setting Microsoft Patch Tuesday fixed nearly 200 flaws (dozens critical, some with public exploits), attackers abused Meta’s AI support bot to hijack Instagram accounts, a CISA contractor publicly leaked AWS GovCloud credentials on GitHub prompting congressional inquiries, the Canvas edtech platform suffered a massive data extortion incident affecting millions, and law-enforc e

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
4a86a1fea4b987b5e8b014a8c678fffb3bfaa1d05e3ba72c3d37230f7e289a7c
Enrichment time
2026-06-22T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm · Baitaphish