❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdaySecurity/Privacy

The Brain Is Actually Two Completely Separate Organs

20 September 2026 at 12:04
"New research led by Stanford Medicine reveals that what we call the brain is two distinct organs that evolved independently over hundreds of millions of years," Stanford Medicine announced this week: The new research finding shows that the human brain consists of two ancient nervous systems cleverly packaged together — a more primitive part that regulates our hearts' beating, our breathing and other functions, and another that makes us distinctly human, capable of poetry, mathematics and wondering about our own origins. The discovery could help explain why scientists have struggled for decades to grow certain types of brain cells in the laboratory — and it opens new avenues for studying devastating diseases that affect the brain stem... [S]cientists have struggled for decades to generate human hindbrain neurons in the laboratory. This gap has hampered research into devastating diseases affecting the brain stem, including spinal muscular atrophy and amyotrophic lateral sclerosis... The researchers' breakthrough came from studying the earliest moments of embryonic development... [Study co-authors Carolyn Dundes and Rayyan Jokhai] discovered that the hindbrain follows a separate developmental path, running in parallel to — rather than branching off from — the pathway that creates the forebrain and midbrain... This revelation explained decades of frustration in the field — scientists had been trying to turn one type of progenitor cell into another that it is fundamentally incapable of becoming... Armed with this knowledge, the researchers for the first time successfully coaxed human pluripotent stem cells (a kind of cell that can create any cell in the human body) to become functional hindbrain motor neurons in the laboratory... Finally, the researchers looked back over 550 million years of evolutionary time. They found the same two-origin brain pattern in chickens; zebrafish; and, remarkably, in acorn worms, tiny creatures living on the ocean floor that share a distant common ancestor with humans. Jellyfish, which diverged from humans about 600 to 700 million years ago, have two nervous systems at different ends of their body. "Our research suggests that evolution took two existing neural systems and pushed them together spatially," Loh said. "Having the brain as one organ would probably be more efficient, but we rely on this primordial way to make the brain as two separate pieces." Thanks to Slashdot reader Beeftopia for sharing the article.

Read more of this story at Slashdot.

Revolut’s paperwork breach shows why insurers are rethinking what counts as a ‘cyber attack’

By: Dissent
15 September 2026 at 07:49
Matthew Sellers reports: Revolut wasn’t hacked in the usual sense. No one broke into its servers or slipped malware past its defences. Someone asked for customer data, from what looked like a genuine government email address, and Revolut handed it over. That email is now behind one of the stranger data incidents to hit a...

Source

Hackers demand 10,000 Bitcoin from Revolut following data breach

By: Dissent
15 September 2026 at 07:49
Dev Kundaliya reports: Revolut recently disclosed a security incident in which an unauthorised third party obtained sensitive customer information by sending fraudulent requests from the email domain of a legitimate government agency. People claiming responsibility for the incident have posted samples of the allegedly stolen information across several Telegram groups and the material appears to...

Source

'She Lost Her Sight. Her Billionaire Father Bet On a Daring New Treatment.'

7 September 2026 at 10:34
"Billionaire Bill Ackman's life was upended this February when his 26-year-old daughter collapsed in her Brooklyn apartment, suffering a brain hemorrhage that would render her unable to move, speak or see," writes the Washingon Post. But then... The hedge fund manager did what any good father would do — at least, any father with vast financial resources and what friends describe as a "Mr. Fix-It" tendency. He sprung into action, getting her topline care at New York City's Mt. Sinai Hospital and consulting a network of well-connected friends all over the world. He helped her access a novel cell therapy that has been gaining traction among longevity enthusiasts, who are seeking ways to prolong human life. And then — motivated by a newfound desire to accelerate scientific research — he vowed to spend more than $400 million to launch an institute dedicated to longevity and brain health... He posted this week that the U.S. Food and Drug Administration, in May, gave his daughter Lucy's medical team a first-time emergency authorization to transplant mitochondria — the energy-producing part of human cells — from her leg muscle to her eyes, in the hopes that the tiny cell powerhouses would facilitate healing in her optic nerves and perhaps even restore her vision. Ackman's story highlights the increasingly prominent role of the ultra-wealthy in making expensive medical bets on longevity treatments and other novel therapies, altering the direction of research as federal funding for science declines in the second Trump administration. But his saga is a deeply personal one, spurred by his daughter's medical crisis. The focus on longevity by Ackman, who made billions on Wall Street as a hedge fund manager, is aligned with similarly ambitious efforts from some of Silicon Valley's biggest names. OpenAI CEO Sam Altman has backed Retro Biosciences, a start-up whose goal is to add 10 healthy years to the human lifespan through cellular reprogramming. Amazon founder Jeff Bezos is reportedly a funder of Altos Labs, which focuses on cellular rejuvenation and resilience... Billionaire investor Peter Thiel, Google co-founder Sergey Brin and Oracle co-founder Larry Ellison are also deeply invested in life-extension methods and attempts to rewrite the biology of aging... The therapy given to Ackman's daughter Lucy, known as mitochondrial transplantation, is of great interest not only to people who have suffered injuries, but to longevity-focused scientists who believe that mitochondria may hold promise for reversing some of the effects of aging... In recent years, scientists have discovered that mitochondria have many other functions beyond converting food into energy. They serve as clearinghouses for damaged cells, opening up the possibility that they can help with cell regeneration and healing, said Daria Mochly-Rosen, professor of chemical and systems biology at the Stanford University School of Medicine and co-author of " The Life Machines: How Taking Care of Your Mitochondria Can Transform Your Health." "I am one of those who believes that focusing on mitochondrial health is a way to address many human diseases, including aging itself," she said. "It's exciting."

Read more of this story at Slashdot.

End-of-summer wrap-up

31 August 2026 at 03:42
TAME YOUR TECH End-of-summer wrap-up By Susan Bradley Are you ready for 26H2 and new Apple devices? The end of August has always been a time for me to stop, reflect on the summer, determine if I got anything on my summertime to-do list done, and see whether I’m ready for fall. When I was […]

FDA Approves First Alzheimer's Blood Test For Americans As Young As 40

By: BeauHD
24 August 2026 at 13:00
The FDA has cleared the first Alzheimer's blood test for symptomatic patients as young as 40. The test measures amyloid and tau biomarkers from a single blood draw and identified positive biomarkers with 97.6% accuracy in a validation study. New Atlas reports: PrecivityAD2 is a single blood test that quickly assesses the proteins amyloid and tau, using mass spectrometry to measure plasma AB42/40 and p-tau217/np-tau217. The results are then scored, qualifying as negative, likely positive, or positive for AD. "Just over a year ago, there were no FDA-cleared blood tests for Alzheimer's, and now we have three," Isobel Coleman, chief executive officer of the Alzheimer's Drug Discovery Foundation (ADDF), said in a statement. "This is a proof point that sustained, early investment in translational science plays a catalytic role in moving promising ideas from the lab to patients." In a recent clinical validation study, 1,142 symptomatic adults were tested using PrecivityAD2. The process accurately identified 97.6% of positive biomarkers. What's more, the results remained consistent even in patients with comorbidities like chronic kidney disease and diabetes, which can distort plasma amyloid samples. It's worth noting that the test isn't intended for general health screenings, but for patients who already show some cognitive decline. "As PrecivityAD2 and tools like it move further into clinical practice, they will enable earlier detection, sharpen clinical trials, and build the foundation for precision medicine and combination therapies," Coleman added.

Read more of this story at Slashdot.

Moderna-Merck Vaccine Cuts Recurrence And Spread of Melanoma, Raises New Treatment Hope

22 August 2026 at 14:00
Reuters reports "a major success in a new field of cancer treatment this week, as Moderna and Merck announced a personalized mRNA cancer vaccine "reduced the risk of recurrence and spread of melanoma in a late-stage trial". The vaccine was tested with Merck's widely used immunotherapy drug Keytruda: Thousands of patients who have undergone surgery to remove high-risk melanoma tumors could benefit as soon as next year if regulators approve the vaccine, Moderna President Stephen Hoge said in an interview. This is the first positive late-stage trial result for an mRNA cancer vaccine, which trains a patient's immune system to fight tumors by targeting specific mutations in those cells, and the first such study to show that adding a treatment to Keytruda worked better than that therapy alone... Interim results of the ongoing study, released on Wednesday, found the treatment, Intismeran, met both its primary target of reducing cancer recurrence and its secondary goal of preventing tumors from spreading to other parts of the body, compared with Keytruda alone. When the vaccine is injected into a patient, the patient's cells produce copies of mutations for the immune system to recognize and destroy... Merck said the companies are already in talks with regulators about the treatment. "Merck, Moderna and other companies are testing similar approaches against lung, breast and pancreatic cancers," the article points out. It adds that Karen Knudsen, CEO of the Parker Institute for Cancer Immunotherapy, "said the Moderna results could signal a new era for treating solid-tumor cancers." More from CNN: The trial result is "a monumental leap forward," validating mRNA technology as a cancer treatment, said Dr. Julie Gralow, chief medical officer of the American Society of Clinical Oncology... Roche and BioNTech, whose mRNA technology was used in the Pfizer COVID vaccines, are testing a similar treatment called autogene cevumeran in mid-stage studies in colon and pancreatic cancer patients who have undergone surgery. Results of the colon cancer trial are expected in 2027, with pancreatic trial results to follow in 2031. "We should be hearing results from multiple studies over the next few years and there's every reason to hope now, with this news, that many of them will be positive," said Dr. Robert Vonderheide, director of Penn Medicine's Abramson Cancer Center and president-elect of the American Association for Cancer Research.

Read more of this story at Slashdot.

Translation at home and abroad

17 August 2026 at 03:44
TRAVELING TECH By Peter Deegan A good translation app on your phone is useful for travel abroad — and also locally in our diverse, globalized world. Both Apple and Google offer free translation apps that handle typed text, spoken conversations, and even live camera translation of signs, menus, and food labels. I rarely need a […]

Wetherspoons bars smart glasses from filming customers

10 August 2026 at 09:20
Wetherspoons has stopped short of banning Meta-style smart glasses from its pubs, but told The Register that customers should switch off their cameras and refrain from filming. "Like many hospitality companies, Wetherspoon has CCTV cameras for security reasons, but their use is strictly controlled by data legislation," a spokesperson said. "Apart from that, the general code that applies in our pubs, and most pubs, is that you can't film customers or employees without their permission. "Meta glasses seem to breach this code, and common sense, by enabling surreptitious surveillance, so our instinct is to say turn off the cameras. This is akin to our efforts to stop audible playing of videos in our pubs, which also invades people's space." The Register asked whether customers who refused to stop recording would be ejected, but Wetherspoons declined to elaborate. Wetherspoons' statement suggests that recording, rather than merely wearing the glasses during a wallet-friendly session, would attract the attention of security staff. The policy is therefore less strict than those adopted by venues and events that have banned recording glasses outright over privacy concerns. DEF CON, which concluded last week, was the latest in a series of organizations to issue outright bans on Meta-style recording glasses, even for those who use them with prescription lenses. Conference organizers told delegates to pack "non-violating eyewear" if they needed them. Monopoly Events, which runs UK Comic Cons among other events, recently imposed a ban after talent agencies and guests raised concerns about privacy and the effect of covert recording on personal interactions. Scottish ferry operator CalMac also temporarily suspended unplanned visits to ships' bridges after a passenger made crew members feel uncomfortable during a crossing in June. Restaurateur Jeremy King, who owns London's Arlington, The Park, and Simpson's in the Strand, has said the glasses should not be worn in his establishments. Similarly, private members' club Soho House does not allow recording inside its venues, a policy that extends to Meta-style glasses. Brighton's Yellow Book Bar called the glasses "creepy and intrusive" when announcing its ban, and theatre companies ATG Entertainment and Trafalgar Entertainment do not permit them either. Meta's smart glasses have become shorthand for the wider category of camera-equipped eyewear. Google unveiled Glass in 2012 but failed to turn it into a mainstream consumer product. Meta and EssilorLuxottica launched their first Ray-Ban Stories glasses in 2021, followed by the second-generation Ray-Ban Meta range in 2023 and an expansion into Oakley-branded models. Meta's glasses have become the most prominent products in the category, prompting other tech companies to work on rivals. The next-gen eyewear has proven especially popular among social media users, allowing them to record high-res, hands-free, and first-person footage with ease. Unlike Google Glass, however, the wearables are largely indistinguishable from their analog counterparts, which makes their recording capabilities all the more problematic. The camera in Meta's specs is small and embedded neatly inside the glasses' frame. The company routinely highlights that each pair is fitted with a recording light, which activates when the user begins shooting video, and that if this light is covered up, then recording immediately stops. The feature has done little to appease those who feel the cameras are an invasion of privacy. UK law does not generally prevent individuals from filming in public, although pubs are private premises and may set their own rules. Smart glasses make those rules harder to enforce because recording is far less conspicuous than when someone points a smartphone at the scene. Researchers have shown that Meta's glasses can be paired with apps that can dox passersby in seconds. Others have worked up projects that inform Android users of nearby glasses-wearers using Bluetooth signals. Meta faces a UK data protection probe concerning the cross-border data flows of its glasses' footage after Kenyan reviewer teams reported seeing footage from wearers' more intimate moments. ®

Framework loses customer data in Metabase zero-day attack

10 August 2026 at 07:21
Modular laptop maker Framework has warned customers that an attacker exploited a zero-day at analytics provider Metabase to access names, email addresses, phone numbers, physical addresses, and login IP addresses, according to an email shared on Reddit. For business customers, the exposed information may also include company names, phone numbers, VAT or Employer Identification Numbers (EINs), and billing email addresses. Framework said order and payment details were not affected. "We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors," Framework said, adding that it's notifying regulators where required, though it noted that names, email addresses, phone numbers, and physical addresses don't cross the mandatory reporting threshold in many regions. Customers are getting the heads-up regardless. Framework didn't immediately reply to The Register's questions, but told TechCrunch that the breach had affected "all customers." The intrusion began with a zero-day vulnerability in Metabase, the business intelligence platform Framework uses to analyze its data. In its own blog post, Metabase said an attacker targeted its cloud service using a previously unknown vulnerability affecting versions 1.58 and later. The company blocked the endpoints used in the attack, patched the bug, and deployed the fix across its cloud service. Framework's account provides a timeline for the break-in. Metabase discovered the attack on August 3 and notified Framework at 9am Pacific Time on August 6, telling the laptop maker that its instance had been vulnerable and that the attacker had successfully gained access to it. Framework said it then rotated credentials for every database connected to its Metabase instance and found no changes to admin access or evidence that systems outside Metabase had been accessed. The company has also brought in a third-party forensics firm to investigate, and cautioned that its findings so far are preliminary. According to Metabase, exploitation can allow an attacker to inject arbitrary SQL against the application's database and potentially gain administrator access. From there, they could alter configuration settings, steal credentials for databases connected to Metabase, query data those connections can access, and export the results. Metabase told anyone running their own instance to patch immediately. If the vulnerable password-reset endpoint was exposed to the internet, admins have more work ahead of them: killing active sessions, checking for rogue API keys or admin accounts, rotating database credentials, and digging through logs for anything suspicious. Framework is reviewing how customer information is made available through external analytics services, but hasn't yet said what changes that review might produce. The breach lands during an already bumpy spell for Framework and its customers. In July, the repairable PC maker warned that the price it was being charged for LPCAMM2 memory used in its Laptop 13 Pro had more than doubled, forcing it to raise memory prices rather than swallow the increase. It also warned that CPU prices were heading upward and could push overall system prices higher in the coming weeks. Being able to replace almost every part of your laptop is handy. Finding your home address exposed through an analytics service is rather less so. ®

98 years of technology

10 August 2026 at 03:42
TAME YOUR TECH By Susan Bradley As my dad turns 98 years young today, I am reminded that technology is deeply integrated into his daily life. Yet, much of this daily tech is not geared toward his needs. Although he is — thankfully — not in an assisted-living space, we have friends who are. They […]

Scientists Make First Viruses Designed By AI

By: BeauHD
6 August 2026 at 23:30
An anonymous reader quotes a report from The Guardian: Scientists have made the first viruses designed by artificial intelligence in a milestone that raises hopes for new medicines but also concerns over how to ensure the technology remains safe. The viruses are specific kinds known as bacteriophages, which only infect bacteria and are used around the world to treat patients with persistent infections. In lab tests, a cocktail of the AI-designed viruses killed E coli bugs that were resistant to natural bacteriophages. Dr Brian Hie, a chemical engineer at Stanford University in California, used genome language models, the genetic equivalent of the large language models behind AI chatbots, to design functioning genomes for bacteriophages. The viruses were then made in the laboratory and pitted against E coli in a dish. The ability to "rapidly design" genomes and tune them for specific bugs while overcoming resistance could "transform phage therapy" and "expand biotechnological toolkits," the researchers wrote in the journal Science. But beyond the potential benefits, the scientists said the work raised "important biosafety, biocontainment and biosecurity considerations" and urged others who were designing whole genomes to "consult both safety and security professionals throughout the project." In an accompanying article, Prof Tom Inglesby and Dr Moritz Hanke at the Center for Health Security at Johns Hopkins University in Baltimore, reinforced the warning, writing: "Although this is promising for life sciences applications, it also raises urgent biosafety and biosecurity questions. The ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not." Tom Ellis, a professor of synthetic genome engineering at Imperial College London, said the work was impressive, but revealed how hard it would be to make more complex genomes. "This is literally the smallest and easiest genome to make," he said. An AI trained on the genetic code of dangerous bugs could be used to design more harmful viruses, Ellis said, but controlling access to genetic data and having restrictions on making genomes that look dangerous would help. "Governments are working hard to do this already," he added. "But honestly," he said, "the threat from full AI design and writing of a genome of a virus or bacteria is very overblown when we consider that just taking existing pathogens and making gain-of-function changes to their genomes is so much easier and much more likely to be a real pathogenic threat." Dr Filippa Lentzos, a reader in science and international security at King's College London, said the most important point to intervene at the moment was when DNA was being manufactured. "It's important to see the bigger governance picture and not focus regulation solely on the AI model," she said. "A layered approach makes more sense: safeguards around model development and access, responsible research review, synthesis screening, and established laboratory biosafety and biosecurity."

Read more of this story at Slashdot.

FDA Approves First mRNA Flu Shot

By: BeauHD
6 August 2026 at 07:00
The FDA has approved the first mRNA flu vaccine in the United States after a clinical trial found it was about 27% more effective than a standard flu shot. Manufactured by Moderna and marketed as mFlusiva, the vaccine is expected to be available this fall for adults ages 50 to 64 and those 65 and older, though approval for the older group is conditional on Moderna conducting an additional clinical trial, NBC News reports. From the report: Many scientists and public health experts have touted the idea of an mRNA-based flu vaccine, which uses the same messenger RNA platform as the Covid vaccines from Moderna and Pfizer. That's because mRNA vaccines can be manufactured much faster than traditional vaccines, allowing scientists to better match circulating influenza strains. Moderna said it takes two to three months from picking the strain to rolling out its flu shot, compared with about six months for traditional flu shots.

Read more of this story at Slashdot.

Getting full value from your tech

6 July 2026 at 03:45
ISSUE 23.27 • 2026-07-06 TAME YOUR TECH By Susan Bradley Microsoft’s surprising decision to add another year to the Windows 10 Extended Security Update program was welcome news to those stunned by the dramatic price increases of core system components. It means the urgency to acquire new Windows 11–compatible hardware is gone, at least for […]

The extremes of tech

22 June 2026 at 03:41
TAME YOUR TECH By Susan Bradley Data centers are in the headlines these days, from the number being built to the energy and water they consume and to the noise they produce. But because neither you nor I will ever own a data center, I’m going to discuss some of the extremes that impact our […]

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

18 June 2026 at 13:37

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Malicious streaming devices sold online that enroll the user's home Internet address in a residential proxy service. Image: Synthient. Pictured are 8 different TV boxes, including the X96 Mini Box, stick, and other no-name brands.

Malicious streaming devices sold online that enroll the user’s home Internet address in a residential proxy service. Image: HUMAN Security.

Popa is a massive botnet, but by all accounts it is unlike traditional botnets that enlist compromised systems in destructive activities, such as coordinating huge distributed denial-of-service attacks. Rather, Popa appears designed with a singular purpose: Implementing a persistent communications layer capable of registering a device, maintaining long-lived encrypted connections, and opening communication tunnels on demand.

Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes. These devices, which are marketed under thousands of brand names and model numbers and broadly available for purchase at top e-commerce destinations, all advertise the ability to stream hundreds of subscription video services for an up front one-time fee.

But as the FBI and security industry experts have warned repeatedly, these streaming boxes typically bundle or come pre-installed with software that turns the user’s TV into a “residential proxy” — allowing anyone to route their Internet traffic through that device for as long as it remains plugged into a wall socket and connected to a local network. More concerning, some of these proxy networks do little to stop malicious customers from communicating with and even compromising systems on the local network of the unsuspecting device owner.

The first clues about Popa’s origins came in a 2025 report from the Chinese security company XLAB, which flagged at least nine domain names that were used to register and direct the activities of compromised devices. In a report released today, the security firm Qurium described how it stumbled on some of those same domains while investigating a series of disruptive and expensive data scraping events targeting the company’s hosted organizations in May 2026, in which the scraping activity was scattered evenly across more than 1.4 million Internet addresses.

Qurium said it found several dozen domains used to control Popa that were all hosted in lockstep across multiple Internet addresses over time, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. Digging deeper, Qurium discovered gmslb[.]net was referenced in dozens of pirated or modded video content streaming apps, such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob and HD/OceanStreams.

Qurium’s report notes that most of the domains long used to control the Popa botnet were seized or dismantled in July 2025, after Google, HUMAN Security and Trend Micro teamed up to disrupt Badbox 2.0, a botnet that is closely associated with Vo1d. Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Ninjatech is a company founded by Moishi Kramer, whose LinkedIn profile says he is vice president of research and development at NetNut. That resume credits Kramer for helping NetNut to build from the “ground up,” “designing the architecture,” and “scaling the NetNut” before the company was acquired by Alarum Technologies. A self-created listing at the job board F6S references Kramer as the sole owner of the Ninjatech domain (a screen capture of it is pictured below).

Image: F6S.com.

Responding via email, Mr. Kramer said Ninjatech ceased operations approximately five years ago, when the company sold a software development kit (SDK) called Popa that was designed to use a small portion of a device’s bandwidth and to run only after the host application obtained user consent.

“That code was sold and licensed to third parties including resellers years ago,” Kramer said. “Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it.”

Kramer said neither he nor NetNut builds, operates or maintains the infrastructure being described as Popa, nor does he control the Ninjatech domain.

“I didn’t register the June 2025 domains you mention, and I don’t know who did,” he continued. “I have no control over, or visibility into, that infrastructure. I can only tell you it isn’t operated by me or by NetNut.”

But in a separate Popa research report released today, the proxy-tracking company Synthient said a recent analysis of the Popa SDK revealed outbound traffic clearly associated with NetNut.

“The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients,” Synthient wrote. “This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool.”

Synthient’s platform receiving outbound traffic from Popa. Image: Synthient.com.

Alarum Technologies, NetNut’s Tel Aviv-based parent company, said the reports by Synthient and Qurium contained “demonstrably inaccurate assertions and flawed deductions rather than verified facts.” Alarum shared a statement saying they reject the basic characterization of the SDKs and technologies discussed in the reports as a “botnet.”

“The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems or otherwise compromise the devices on which they operate,” the statement reads. “Netnut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services.”

Alarum said NetNut places “significant emphasis on appropriate notice and consent mechanisms, conducts customer due diligence, monitors for potential misuse, and takes steps intended to detect and mitigate suspicious or unauthorized activity.”

“This method of operation is supported both by internal procedures and policies, including performing KYC checks and additional due diligence of NetNut’s customers, as well as employing various technological measures, designed to assist in identifying and addressing suspected misuse of the network,” their statement continued.

However, in a report released on June 8, the proxy tracking service Spur asserted that NetNut does not require corporate verification or meaningful “know your customer” procedures before allowing customers to purchase proxy access.

“An individual can sign up, pay, and route traffic through partner address space, including space belonging to institutions whose users never opted in,” Spur wrote. “The ‘verified corporations only’ claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies.”

“Nor is NetNut the only front door,” Spur continued. “A number of downstream white labelers and resellers repackage the same ISP proxy pool under their own brands. These outlets typically perform no KYC at all, less scrutiny than NetNut itself, who at the very least might assign an account manager to potential users. Anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto.”

Synthient found that although the most recent builds of Popa (as of three months ago) have added the ability to ask the user for consent before installing proxy components, not all variants or previous versions of Popa contain this functionality.

“Of the over 20 genuine Popa publishers analyzed, none of them were observed asking for user consent,” Sythient wrote.

THE PREVALENCE OF POPA

Chris Formosa is senior lead information security engineer for Black Lotus Labs, a division of the Internet backbone carrier Lumen Technologies.

“What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing,” Formosa said, explaining that many other proxy services simply resell NetNut proxies rather than building out their own far-flung proxy networks. “So these Popa IPs appear in tons of different services all over the ecosystem, which makes it one of the most problematic and dangerous proxy botnets on the market currently.”

Formosa said the Popa botnet averages between 1.5 million to 2.5 million distinct IP addresses each day, relying on between 250 and 300 Internet addresses that are used to direct its activities.

“That’s why Popa is so dangerous,” Formosa said. “It may not be the largest botnet we have seen, but it is spread all over the industry, making its power very amplified.”

Formosa said while that makes Popa one of the larger botnets out there today, its numbers pale in comparison to those previously boasted by IPIDEA, a China-based proxy provider that until recently operated a daily pool of nearly 10 million devices that they resold as proxies to anyone. In January 2026, Synthient published research showing that multiple new large DDoS botnets had grown rapidly by tunneling through IPIDEA proxies into the local networks of unsuspecting TV box owners and infecting other Android-based devices behind the user’s firewall.

IPIDEA is based largely on SDKs used to view pirated streaming content on a vast number of TV box devices, but the service’s numbers have dwindled since January, when Google and industry partners took legal action to seize domain names that IPIDEA used to control devices and proxy traffic through them.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates. Meyer told KrebsOnSecurity that Nokia is monitoring 26 of at least 359 known relay nodes for the botnet, and estimates that each relay node handles between 35,000 and 60,000 clients simultaneously.

“On the relay node subset I am looking at (26 of them), 750,000 unique sources in 24 hours,” Meyer wrote in response to questions.

Nokia Deepfield released its own report today on RoboVPN, a VPN app tied to the Vo1d botnet’s Popa plugin that Qurium attributes to NetNut/Alarum Technologies.

THE SYMBIOSIS OF PROXIES AND DATA SCRAPING

Experts say many of the world’s largest proxy providers have updated their public-facing branding to highlight their utility for training AI platforms, implying it is a primary use case for their residential proxies. That’s because AI services tend to rely on constantly mass-scraping the Internet for new text, images and video content that can be used to train large language models (LLMs).

NetNut and other proxy services have recast themselves as critical infrastructure for the AI scraping economy. Image: Synthient.com.

“AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search,” reads a report this month from Include Security that examines the prevalence of proxy SDKs in smart TV apps. “But the modern web isn’t scrapeable from a datacenter. Cloudflare, DataDome, HUMAN, among others throttle or block requests from known cloud IPs. The workaround is residential proxies. A scraping job routed through a Comcast or T-Mobile subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer.”

This non-stop content scraping has spawned more than 70 copyright infringement lawsuits against major tech companies that have acknowledged large-scale data scraping as a major source of the “brains” behind their commercial AI offerings. Ironically, much of that scraping is being aided by proxy services that are intimately tied to unofficial Android TV boxes and associated SDKs whose stated purpose is streaming pirated content.

The scraping activity has become so aggressive that it often overwhelms the targeted websites, preventing them from being reachable by legitimate visitors. In many reported cases, nonprofit organizations, libraries and universities have complained of constantly battling to keep their services online in the face of relentless data-scraping firms hiding behind residential proxy services.

A survey conducted last year by the Confederation of Open Access Repositories (COAR) found while some content scraping bots are rather innocuous, “others are sufficiently aggressive that they are increasingly causing service disruptions in repositories and other scholarly communications infrastructures.” More than 90 percent of survey respondents indicated their repository is encountering aggressive bots, usually more than once a week, and often leading to slow downs and service outages.

“Automated web scraping is nothing new, and has been the key technology underlying search engines such as Google for over 30 years,” wrote Brendan O’Connell, platform manager at the Directory of Open Access Journals (DOAJ), a free, community-curated index of peer-reviewed academic journals. “However, the current investor-fueled AI startup craze means there are now thousands of well-funded companies developing and deploying their own scraping tools to train AI models, alongside existing major players like OpenAI and Google.”

DON’T TOUCH THAT DIAL!

Across the United States, local communities are pushing back against the proliferation of new data centers aimed primarily at improving the capabilities of AI. But security experts say the general public remains largely unaware that using one of these unsanctioned Android TV boxes means their “smart TV” is almost certainly using a significant amount of bandwidth each month to help train modern AI models.

Even households without these sketchy TV boxes can still have their smart TVs turned into residential proxy nodes, just by downloading one of thousands of apps made available on Samsung and LG smart TVs. Spur said it recently scraped the LG and Samsung app stores and found that each had approximately 3,000 apps available for download. Many of these apps are simple games or utilities that state in the fine print that the user’s Internet connection will be used to download data and that they can opt out at any time.

Spur said it found that more than 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found.

Image: Spur.us.

Experts say it’s questionable whether TV apps with proxy SDKs can obtain meaningful consent from users for installing an always-on proxy connection, particularly when anyone in a household — including children — can effectively opt the family TV into a residential proxy network just by installing a simple game or app.

“Privacy-policy disclosure is the wrong control surface for a TV,” Include Security wrote. “It is hard to scroll through a legal document navigated by arrow keys on a remote, and the in-app consent dialog doesn’t convey that a paying customer is about to route their scraping traffic through the user’s home internet.”

Spur’s head of research Sean Simmons told KrebsOnSecurity that most people do not have a working mental model for what it means to sell access to their residential IP address, no matter what device they are using.

“And on a TV, the gap is even wider,” Simmons said. “A one-time prompt navigated with a remote can disappear into the setup flow, while the app keeps monetizing the connection long after anyone remembers what they accepted.”

Simmons said LG and Samsung should follow the lead of other TV platforms that have already drawn a line against residential proxy providers, pointing to policies by Amazon that prohibit apps facilitating proxy services for third parties. Likewise the TV streaming device maker Roku reportedly now bars developers from using proxy SDKs and has removed apps that bundled them.

Piracy related apps pushing proxy SDKs onto unconsenting users. Image: Synthient.

Apps that turn one’s device into a residential proxy node are not limited to smart TVs and no-name streaming boxes, of course. As noted by the security firm Infoblox, mobile app developers can embed SDKs provided by the residential proxy networks into their products to monetize their software, allowing them to receive a small amount of money on each installation.

The result, Infoblox said, is that devices are frequently enrolled without the owner’s knowledge, typically through free applications such as VPNs, streaming apps, screensavers and “productivity” apps such as PDF viewers and break reminders.

All too often, these proxy services are beaconing out from employee devices brought into the workplace, Infoblox found. In a blog post earlier this month, Infoblox said it discovered that fully 65% of its customer base was querying one or more residential proxy related domains.

“We saw steady growth in these queries in 2025, with a 25% increase over the year to over 500 billion per month,” Infoblox wrote. “Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators. Perhaps even more concerning is that over 60% of government and banking customers have as well.”

Infoblox researchers Nick Sundvall and David Brunsdon warned that with residential proxies in the corporate environment, external access is granted to an organization’s IP space.

“If threat actors were to abuse the residential proxy to attack a third party, the third party’s incident response would, correctly, identify your residential proxy as the source,” they wrote. “Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation. The stunning prevalence of these services within customer environments warrants attention from both network defenders and policy makers who should consider how the risks posed by residential proxies could be impacting their security posture.”

Surge protectors friend or foe

16 June 2026 at 15:20
As I’m starting to put the office back together (my office is the last one being worked on), I am reminded that surge protectors aren’t always your friend. They can cause fires. Someone I know had their master bedroom burned up from a surge protector that caught on fire. While thankfully they were not in […]
❌
❌