‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

2026-06-21T19:23:28Z82188c6912cbdff26e0decc77e7d4e29fb5f8fae86eee76d9e6435d7e72f98db
AI social engineeringAWS GovCloudAlarum TechnologiesCISACanvasDDoS botnet (Kimwolf)Instagram hijackMetaMicrosoftNetNutPatch TuesdayPopaThe Gentlemenaccount takeoveradvertising fraudbotnetcredential leakdata breachdata extortiondata scrapingeducation platformpublic exploitransomwareresidential proxy abusezero-day

What happened

KrebsOnSecurity headlines covering June–May 2026 show a surge in high-impact cyber incidents: researchers linked the long-running Android Popa botnet (used for advertising fraud, account takeover and mass scraping) to NetNut/Alarum Technologies; analysis surfaced likely real-world operators behind The Gentlemen ransomware gang; Microsoft issued a record Patch Tuesday (nearly 200 fixes, ~30 rated critical and public exploit code for at least three bugs); attackers abused Meta’s AI support assistant to hijack Instagram accounts; Dutch authorities seized ~800 servers and arrested hosting co-‑own­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
82188c6912cbdff26e0decc77e7d4e29fb5f8fae86eee76d9e6435d7e72f98db
Enrichment time
2026-06-21T19:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.