Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
2026-07-03T07:24:07Z•1d3c2f6d2b60558f6ab5a53de3475bfc668922705bad9d432ea1a9656cbbddd3
active-exploitationargo-cdbotnet-disruptionchocopoccitrix-bleed-2credential-theftcursorfortibleedgmail-api-compromise","ai-agent-ransomware","langflow-rce","jadekemp-loadmasterknown-exploited-vulnerabilitykubernetes-takeoverlaw-enforcementnetnutoauth-abusepoC-repo-malwareprompt-injectionransomwareratresidential-proxysandbox-escapesharepoint-rcesupply-chain-credentialstoddycatumbrij
What happened
A multi-topic security roundup: Google, working with law enforcement and partners, significantly disrupted the NetNut (aka Popa) residential proxy network by removing millions of devices. Multiple active-exploitation and high-risk vulnerabilities are highlighted — ransomware actors abusing Citrix Bleed 2 (CVE-2025-5777) and supply-chain/credential access patterns; Microsoft SharePoint RCE (CVE-2026-45659) added to CISA KEV; Progress Kemp LoadMaster pre-auth RCE (CVE-2026-8037) seen in exploitation attempts; critical Cursor prompt-escape flaws (CVE-2026-50548, CVE-2026-50549) that allow sandbox
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 1d3c2f6d2b60558f6ab5a53de3475bfc668922705bad9d432ea1a9656cbbddd3
- Enrichment time
- 2026-07-03T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.