‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
2026-06-22T13:23:31Z•abe68a046f6111bf780564ca9b51b5f0677b4ae22768a5c68d575f8ed86aaa6b
account takeoveradvertising fraudai social engineeringalarum technologiesandroidaws govcloudbotnetcisacredential leakdata leakdata scrapingexploit codeinstagram compromisemetamicrosoftnetherlandsnetnutpatch tuesdaypoparansomwareresidential proxyserver seizure/sanctions infrastructure support for russia (stt/the gentlementv boxesvulnerabilities
What happened
A set of high-impact security events: researchers attribute the Popa Android TV-box botnet to NetNut (Alarum Technologies), exposing widespread proxy abuse for ad fraud, account takeovers and mass scraping; reporting on The Gentlemen ransomware group pinpoints possible real-world leadership; Microsoft issued a record Patch Tuesday (~200 fixes, ~30+ critical, public exploit code for at least three bugs); attackers abused Meta's AI support assistant to hijack high-profile Instagram accounts; a CISA contractor leaked AWS GovCloud keys and internal secrets on GitHub, prompting congressional probes
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- abe68a046f6111bf780564ca9b51b5f0677b4ae22768a5c68d575f8ed86aaa6b
- Enrichment time
- 2026-06-22T13:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.