Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices

2026-07-03T07:24:07Z1d3c2f6d2b60558f6ab5a53de3475bfc668922705bad9d432ea1a9656cbbddd3
active-exploitationargo-cdbotnet-disruptionchocopoccitrix-bleed-2credential-theftcursorfortibleedgmail-api-compromise","ai-agent-ransomware","langflow-rce","jadekemp-loadmasterknown-exploited-vulnerabilitykubernetes-takeoverlaw-enforcementnetnutoauth-abusepoC-repo-malwareprompt-injectionransomwareratresidential-proxysandbox-escapesharepoint-rcesupply-chain-credentialstoddycatumbrij

What happened

A multi-topic security roundup: Google, working with law enforcement and partners, significantly disrupted the NetNut (aka Popa) residential proxy network by removing millions of devices. Multiple active-exploitation and high-risk vulnerabilities are highlighted — ransomware actors abusing Citrix Bleed 2 (CVE-2025-5777) and supply-chain/credential access patterns; Microsoft SharePoint RCE (CVE-2026-45659) added to CISA KEV; Progress Kemp LoadMaster pre-auth RCE (CVE-2026-8037) seen in exploitation attempts; critical Cursor prompt-escape flaws (CVE-2026-50548, CVE-2026-50549) that allow sandbox

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
1d3c2f6d2b60558f6ab5a53de3475bfc668922705bad9d432ea1a9656cbbddd3
Enrichment time
2026-07-03T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.