❌

Reading view

There are new articles available, click to refresh the page.

IMDb Adds 'Digital Creator' Profiles For the First Time

IMDb is introducing "Digital Creator" as a new professional category on IMDb and IMDbPro, giving streamers, vloggers, influencers, video essayists, and other online creators a "dedicated way to represent [their] work and connect with audiences, industry peers, and potential employers," according to IMDb. Variety reports: The category includes sub-professions to further specify their work, including "Streamer," "Vlogger," "Video Essayist," "Video Creator," "Gaming Creator" and "Influencer." The "Digital Creator" designation functions as a professional category on IMDb and IMDbPro. Creators can feature multiple professions on their page, so someone who is both a digital creator and an actor can "represent the full scope of their work in one place," per the company. No existing film or TV credits are required to establish a profile as a Digital Creator.

Read more of this story at Slashdot.

Four Major AI Models Suffer Rare Overlapping Downtime

ChatGPT, Claude, Grok, and Gemini all suffered significant service disruptions within roughly the same few-hour window Thursday morning. OpenAI and Anthropic reported elevated errors and later restored service, while Grok remained impaired and third-party monitoring indicated a likely Gemini outage despite no public acknowledgment from Google. Ars Technica reports: Other major Internet services, including Amazon Web Services, Microsoft Azure, and Cloudflare, have not reported any major issues as of press time Thursday, though issue reports on DownDetector did spike somewhat for all three this morning. While the affected frontier models go down occasionally, having all four experience interruptions in the same short period is practically unheard of. Claude reports 99.4 percent uptime for its services over the last 90 days and last reported a similar three-hour "partial outage" on August 24. OpenAI reports 99.63 percent uptime for ChatGPT and 100 percent uptime for ChatGPT Codex in the same period. ChatGPT's so-called "Work Mode" reported an hours-long period of "elevated latency" on August 31.

Read more of this story at Slashdot.

Dogged Russia-based botnet dismantled after 23-year run

Sality, a Russia-based botnet that infected more than 11 million devices during a 23-year run of operations, was dismantled Monday by law enforcement, CrowdStrike and the Shadowserver Foundation. 

CrowdStrike, which announced the takedown Tuesday alongside authorities, said it played a crucial role dismantling the botnet’s technical infrastructure, rendering the malware-spreading operation irrecoverable. 

The peer-to-peer botnet was a persistent piece of criminal infrastructure that evaded disruption for an exceptionally long period because it lacked centralized architecture. 

Sality used infected machines to communicate peer-to-peer, creating a decentralized structure that made system-wide disruption efforts more difficult than botnets that rely on a core server. 

“The same properties that made Sality resilient also created the conditions for its undoing,” CrowdStrike wrote in a blog post. The company said it targeted Sality’s peer list of infected machines and tricked the network into permanently cutting off access to those devices.

“From the operator’s perspective, infected machines simply disappear,” CrowdStrike wrote, adding that the botnet is no longer under the operator’s control.

Sality’s domains were seized by a globally coordinated effort supported by the FBI, Justice Department and authorities from Europol, Bulgaria, Hungary and Romania, officials said. Shadowserver is working with internet service providers to identify devices infected by Sality and aid with remediation. 

“Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy,” Bill Essayli, first assistant U.S. attorney, said in a statement. 

Europol said the Sality takedown was the culmination of work spanning global law enforcement back to 2017. 

CrowdStrike said Sality’s operator was primarily financially motivated, but it attributed three DDoS attacks to Sality, suggesting the operator was occasionally willing to use the botnet for personal or political aims. 

The botnet enabled cryptocurrency theft and cyberattacks on victims in the United States and abroad, the Justice Department said. Officials did not name the person or cybercrime group behind Sality.

“This operation demonstrates that peer-to-peer architecture, long considered a shield against disruption, is not invincible,” CrowdStrike wrote. 

“Operating for decades without consequence does not mean operating without risk,” the company added. “The calculus has changed. We will find you, we will dismantle your infrastructure, and we will impose costs that make the enterprise untenable.”

The post Dogged Russia-based botnet dismantled after 23-year run appeared first on CyberScoop.

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

A record available at this identity theft service that includes the drivers license for U.S. Defense Secretary Pete Hegseth, one of several high-ranking U.S. government officials whose drivers licenses can be found for sale.

On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.

The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.

A quick look around Nexus finds they are likely not exaggerating about that 153 million number: Running a blank search in Nexus (with no search parameters entered) returns approximately 11.5 million pages of results, with roughly 15 results displayed per page. It includes documents from people in both Canada and the United States, but the bulk of these records are on Americans: searching for just Canadian drivers licenses returns approximately 1.1 million results, with the largest concentration from Ontario (473,673 records).

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards. Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.” Other records carry the source notation of “CAC,” which may refer to Common Access Cards, government issued identity cards that grant physical access to government buildings and secure rooms.

The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.

The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.

“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”

Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.

The record featuring my drivers license includes six image files: three pairs of photos of the license’s front and back, a basic image scan, as well as infrared and ultraviolet versions of the same images. A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the midwest United States to attend a family funeral.

Some of the 153 million+ license scans — including mine — feature six image files with date and timestamps appended to the filenames. Not all records include photos, and some that do feature photos do not display the associated filenames.

Intent on discovering the source of this data, KrebsOnSecurity asked more than a dozen friends and family members for permission to search for their licenses in this service. Each person whose license could be found (nine of them) confirmed having traveled on or very close to the dates in the timestamps attached to their images. It is unclear what timezone these timestamps are in, but from reviewing car rental records shared by several people who helped with this research, it appears the timezone is set to Greenwich Mean Time (GMT).

At first, I thought the source of the data might have something to do with airports. However, that theory went out the window when it became apparent there were no passports in this data set. Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel. One person whose license was in Nexus hadn’t flown at all recently, but was renting a car from Hertz for several months around the date of their timestamp.

Two of those who agreed to help are federal employees who said they shared other forms of government identification when passing through airport security. However, those individuals each said they shared their state-issued drivers licenses later that day when renting vehicles at their respective destinations, and that both rented their cars from Hertz.

After finding a note in my calendar for the day of my June 2025 flight reminding me to bring my passport, I remembered that I also never actually shared my drivers license when I went through security at Reagan National Airport on that day because I did not yet have a Real ID, a security-enhanced drivers license that is now required by the Transportation Security Administration (TSA) for all domestic travel. Instead, I showed the TSA agent my government-issued U.S. passport.

Here’s where it gets interesting: I was able to find my mother’s drivers license in this service as well, and the timestamps for her images are just a few seconds apart from mine. That’s notable because we both handed our licenses to the Hertz rental car representative at the same time.

According to my mom, the only place she gave her drivers license to that day was the rental car company, and if memory serves that is also true for me. I don’t recall if the rental car representative inserted our licenses into any kind of machine, but I remember they held onto them for several minutes behind the counter while we were signing various forms. KrebsOnSecurity sought comment from Hertz and will update this story in the event they reply.

Zach Edwards is a well-known security and privacy researcher who recently launched a service called DecryptAds to help people better understand how online advertisers are tracking them. A scan of Edwards’s drivers license is available for purchase on this identity theft service, and Edwards said the timestamp on his record corresponds to the middle of a trip last month to Las Vegas for the annual DEFCON security conference.

Edwards told KrebsOnSecurity that although he did not rent a car in Vegas, he did hand over his license at the TSA checkpoint, at a marijuana dispensary in Vegas, and at his hotel (the Aria). But he said the only one of those three that for sure scanned his ID in some kind of device was the dispensary.

To enter Planet13’s weed dispensary in Las Vegas, one must pass through a red telephone booth. Image: Zach Edwards.

Edwards said the dispensary he visited that day was Planet13, a multi-state chain with stores in California, Florida, Illinois and Nevada. In 2022, the New Orleans-based identity provider idscan.net published a press release announcing an exclusive identity verification agreement with Planet13’s dispensaries nationally. IDScan says it processes ID verification for more than 1,000 marijuana dispensaries in 19 U.S. states.

The “trust” page of idscan.net states that the company provides identity verification services for numerous big brands, including Hertz, Target, Fedex, Motorola Solutions, the financial services giant Jack Henry, and Caesars Entertainment. And as idscan.net’s own documentation states, the technology scans IDs with both infrared and ultraviolet light. Idscan.net says the company’s systems and technology perform more than 21 million verifications monthly, at more than 20,000 locations around the world.

Image: idscan.net.

Contacted by KrebsOnSecurity, idscan.net said it was investigating the matter, but the company has not yet shared an official statement or a substantive reply to specific questions sent via email.

“At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” wrote Jillian Kossman, a marketing and operations leader at idscan.net.

During the course of my research for this story, word got around to the FBI that I was poking at the apparent source of this new identity theft service’s data. Probably they were tipped off when I shared with a trusted source that Nexus also is selling the drivers license information for the assistant director of the FBI (I did not find FBI Director Kash Patel’s license in Nexus).

Earlier this afternoon, I was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency’s cyber division. During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net.

Edwards said that as more in-person and online experiences require sharing drivers licenses, vendors who collect this sensitive data need to be held to a higher standard.

“This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids,” Edwards told KrebsOnSecurity. “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.”

Larry Baldwin is principal intelligence researcher at the cybersecurity firm Cybera. Baldwin said a front and back scan of his drivers license available at Nexus contains timestamps that correspond to the date of a car rental from Hertz on a recent vacation.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).

This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.

“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.

Update, Sept. 8: IDscan.net published a brief notice saying it has “determined that an unauthorized third party may have accessed and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers.” The statement said IDscan.net is notifying affected individuals and offering credit protection services.

Update, Sept. 2, 6:05 p.m. ET: A spokesperson for Caesars Entertainment said Caesars has not been a client of IDScan.net and has not used VeriScan since February 2025, despite IDScan.net listing them as a client on their website. That person said Caesars had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from its accounts, and that IDScan.net said the incident should have no impact on Caesars Entertainment.

Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”

This is a potentially fast-moving story. Any changes or updates will be noted here along with a timestamp.

‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help

The Trump administration rolled out a six-month test program in Texas on Monday that will draw on volunteer expertise and technology from cyber and artificial intelligence companies to protect the water sector.

“Project Watershed 250” is the first of the state-based, industry-centric pilot projects to cross the finish line that the Office of the National Cyber Director has previewed since the publication of its national cybersecurity strategy earlier this year. Water systems have long been viewed as among the most vulnerable and neediest critical infrastructure sectors, and in recent months the sector has been the victim of a spree of attacks.

“Project Watershed 250 is a commitment from the states, industry and federal government that we will continue to prioritize our nation’s safety and deliver on America-first policies for the American people,” National Cyber Director Sean Cairncross said at a rollout event in San Antonio Monday.

“U.S. companies are providing world-class cyber capabilities, red teaming that tests utilities’ current defenses, system hardening using the latest private sector cyber tools and AI tooling that helps utilities’ frontier cyber defenders to protect Texas water systems and scale proven solutions across the country,” he said. “This six-month pilot program is designed to make our water and wastewater critical infrastructure more resilient and resistant to cyber attacks by proactively finding and fixing system weaknesses.”

The pilot program, featuring collaboration between federal and state governments, stands in contrast to how the Biden administration tried to tackle the issue, with audit requirements that some GOP states challenged in court, forcing Biden’s Environmental Protection Agency to withdraw its rule.

“For too long, at least on the federal level, the government has admired the problem of cybersecurity in water systems,” Cairncross said. “We are going to find out what works. We’re going to target that, and we are going to scale off of this and learn lessons.”

A dozen companies — Parsons, Microsoft, Fortinet, Google Cloud, Palo Alto Networks, Amazon Web Services, Reflection AI, Cloudflare, Zscaler, Forescout, Abnormal AI and Dragos — appeared at the rollout Monday to praise the initiative and tout their contributions to it.

Not everyone praised the initiative elsewhere, however. One cyber professional who works on water security issues, speaking on condition of anonymity, said the program was “all smoke” and that “there’s no real money behind it.”

“The White House did what it always does — reached out to industry with their hands out asking for industry to pay for things the government should be doing, at least in part,” the person said.

Texas Gov. Greg Abbott said the program would be overseen by Cairncross’s office and Texas Cyber Command, which was established just last year. Abbott cited the need for the program by mentioning “an Iranian-backed cyberattack” on 30 water systems across 12 states and a 2024 attack on the water system in Muleshoe, Texas, suspected to be the work of Russian hackers.

“The need for cyber resilience is overwhelming,” Abbott said. “Many rural providers simply don’t have the resources they need to be able to protect themselves.”

Watershed 250 isn’t the only federal effort to bolster water cybersecurity, with lawmakers introducing legislation in the aftermath of the recent attacks. Past legislation that Congress has enacted also sought to tackle the problem.

Updated 8/31/26: with comment from cyber professional.

The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help appeared first on CyberScoop.

MS-DEFCON 3: Side effects for some — but not all

ISSUE 23.34.1 • 2026-08-25 By Susan Bradley I am lowering the MS-DEFCON level, but only to 3. August updates have proven themselves to be less than clean. Generally speaking, none of the issues is widespread. They depend upon whether you have specific hardware or are using specific software. And some problems have been reported only […]

Kimwolf botnet rebuilt to survive takedowns, researchers say

The developers of a notorious botnet that’s powered mostly by hijacked Android TV boxes and other internet-connected devices have released a new version built to blend attack traffic in with ordinary web browsing and to keep its command channels from being seized by law enforcement, researchers at Palo Alto Networks said in a report published Tuesday.

The company’s Unit 42 threat intelligence group, which tracks the botnet as Kimwolf or Aisuru, said the newest version has been active since February, a month before authorities seized infrastructure powering previous versions of the botnet. 

The biggest change, according to the report, is a new flood method built on HTTP/2, the protocol that carries most web traffic today. A flood is the crude heart of a DDoS attack: thousands of infected devices send a target far more requests than it can answer. Rather than fire raw packets, this latest Kimwolf version operates with full browser fingerprints, copying the header order and behavior of the Chrome web browser. That matters because the usual defense against a flood is for tools to spot the fake traffic and drop or block it before it reaches the server. Traffic that looks like Chrome does not get dropped, so a site under attack must either serve every request and fall over, or start turning away the customers it cannot tell apart from the bots.

The second change, according to researchers, looks like it was done to withstand further takedowns. Every bot has to ask a command server for orders, which is also what authorities aim to disrupt in botnet takedowns. Normally, the command server address sits inside the malware as a web domain name, so investigators who take that name from its registrar are able to disrupt an entire botnet. 

This Kimwolf version moves its command beyond registrar controls. The malware now looks up its command address in the Ethereum Name Service, a directory that lives on the Ethereum blockchain. A web address using this service can display the way a normal domain does, but the domain’s record sits in a ledger copied across thousands of computers worldwide. The malware carries five public Ethereum services and shuffles the order before each attempt, making it harder for defensive tools to block. Additionally, there is no company to serve with a law enforcement order and no domain record to seize.

Additionally, if all five addresses fail, the botnet falls back to a fixed Tor hidden service address written into the code. Tor resolves that address through its own network rather than the ordinary domain system, and it hides where the server actually sits, which leaves investigators without a host to contact.

Researchers’ infrastructure analysis pointed to the machines powering the command structure to be located in Russia. Four of these servers shared a SSH host key, with further analysis finding that the servers sit in one network registered in Saint Petersburg.

It’s unclear if this version was made by people behind previous iterations of the botnet, or a new person or threat group looking to capitalize on the botnet’s notoriety among malicious actors. 

Unit 42 did not respond to CyberScoop’s request for comment. 

Kimwolf, which splintered off from the record-setting Aisuru DDoS botnet last year, gained the widespread attention of security researchers when it temporarily claimed the top spot in Cloudflare’s global domain rankings in late October 2025. Previous versions of the botnet were disrupted by an international law enforcement operation in March that ended with Kimwolf’s infrastructure being seized.

A Canadian man alleged to run the botnet was arrested in May and extradited to the United States.
  

The post Kimwolf botnet rebuilt to survive takedowns, researchers say appeared first on CyberScoop.

Freenet Creator Ian Clarke Shares Progress on Its New Decentralized Network

Ian Clarke (aka ancient Slashdot reader Sanity), designer of the peer-to-peer communication platform Freenet, is back with an update on the project's progress following the launch of its P2P network in March. He writes: Earlier this year, Slashdot covered the launch of the completely redesigned Freenet. I recently gave a talk about what we've been building since then. Unlike traditional web applications, apps on Freenet have no central server or database; instead application state is distributed across the network. These now include decentralized group chat, publishing, search, and fully decentralized Git hosting. The talk also gets into some of Freenet's internals, including how we use machine learning for network routing.

Read more of this story at Slashdot.

Taiwan 'Throttles' Mobile Internet For First Time During Annual War Games

Taiwan deliberately throttled mobile internet across the Taichung area during its annual Han Kuang war games, "simulating communication disruption in the event of a Chinese attack or natural disaster," reports Reuters. The drill accompanied air-raid exercises and military rehearsals aimed at defending strategically important areas such as the Penghu Islands. From the report: Democratically governed Taiwan, which China claims as its own territory, has long lived with the threat of a Chinese invasion and holds air raid drills along with its war games every year, clearing people from the streets for 30 minutes. During the internet "throttling" drill, centered on Monday on the major central metropolis of Taichung, only basic mobile phone services worked, though other functions including ATMs, traffic signals, landlines and fixed internet services were not affected. Air raid sirens rang out in Taichung "and people cleared the streets from 2:30 p.m. (0630 GMT) as the government sent simultaneous text messages in Chinese and English telling mobile phone users of "simulated air attacks on communication infrastructure." The government had widely flagged the drill ahead of time, including posting details on social media, and most people Reuters spoke to at the Taichung train station were prepared. [...] The same exercise will be repeated on Thursday in northern Taiwan, including the capital Taipei.

Read more of this story at Slashdot.

Open-source software’s archenemy TeamPCP goes back further than anyone thought

TeamPCP, the threat actor behind an unrelenting flurry of attacks on open-source software this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop. 

The threat actor, which gained notoriety and has captivated threat hunters as it compromised and injected malicious code into more than 1,000 software packages in less than four months earlier this year, was also responsible for attacks dating back to 2020, Oligo Security found. 

The security vendor’s research team found multiple attacks that bear the markings of TeamPCP, including a late 2025 campaign involving the exploitation of a ShadowRay vulnerability that resulted in the first self-propogating botnet running on hijacked AI infrastructure.

Evidence uncovered during that investigation into the ShadowRay 2.0 campaign was linked to more historical attacks originating from the same IPs, domains and other infrastructure TeamPCP used in attacks that captured widespread attention earlier this year. 

“The scariest thing in this campaign is the speed at which the payloads evolved and changed and adapted to the environment they run in. We saw changes in the speed that we’re not used to seeing in these kinds of attacks. They’re usually slow, careful,” said Uri Katz, director of research at Oligo Security. “This was clearly with the help of AI — the payloads changed rapidly to adjust and change to the environment that they were trying to attack.”

One of the domains that Oligo Security identified in July 2025 was in the profile of TeamPCP’s official GitHub account, said Avi Lumelsky, AI security researcher at Oligo Security. “It’s public, they’re not even trying to hide their identity,” he said. 

From there, Oligo linked TeamPCP to activity tracked under multiple names, including TA-NATALSTATUS and IronErn, spanning from 2020 to late 2025. Much of that activity was traced to the same IPs, domain names, a file server and command-and-control server, researchers said. 

TeamPCP emerged publicly as a brand in late 2025. Soon after, “TeamPCP started to go really broad and do campaigns, which are much more noisy,” said Gal Elbaz, co-founder and CTO at Oligo Security. 

Widespread adoption of AI and TeamPCP’s use of the technology supported this growth as the threat actor built a brand, got more active on social media and boasted publicly about its activities and claimed victims.

“The ability to control the infrastructure and orchestrate the attack with AI was also super new, and I’m sure it helps them,” Elbaz said. 

“All of the companies in the world are in this race to adopt AI because they are afraid their business will die, and they understand, of course, the opportunity. But it’s also what gives the attacker this power to go into it,” he added. “If you don’t really have visibility in what’s going on there or how it behaves, that’s exactly what attackers are after.”

TeamPCP’s more recent attacks have capitalized on new security gaps created by developers’ increasing reliance on AI and the automated systems companies use to deploy code. The threat actor is also consistently wrecking the open-source frameworks and software packages these systems rely on. 

“Most AI infrastructure is open source by design because nobody has the manpower and money to develop everything from scratch,” Lumelsky said. 

“We love open source. We use many of these products ourselves, but it’s all about reading the documentation, and I think many of these tools place the responsibility of using it right and security on the user, and developers are not used to these new kinds of animals,” he added. “That’s why the trust can be exploited at scale.”

As it uncovered a long operational history spanning multiple campaigns, Oligo Security has gained more confidence in understanding how TeamPCP operates. It also means TeamPCP was likely involved in other attacks that haven’t been attributed to it yet or attacks that haven’t been detected. 

“There’s a lot more out there that we haven’t caught or been able to prove up until now,” Elbaz said.

The post Open-source software’s archenemy TeamPCP goes back further than anyone thought appeared first on CyberScoop.

As Reddit Stock Falls, CEO Questions Value of Google's AI Overviews

Reddit CEO Steve Huffman criticized Google's AI Overviews for summarizing publishers' content without delivering the traffic benefits of traditional search, arguing that users increasingly value Reddit's human perspectives and firsthand experiences. Ars Technica reports: First, there was a letter to investors (PDF), wherein Huffman spun his narrative about Reddit's value proposition and general strategic direction amid the proliferation of AI tools. He wrote: "As the internet becomes flooded with synthetic content, people are craving real human perspective. We are the antidote to an automated web. AI compresses the internet into summaries. Reddit delivers the opposite: deep discussions, passionate debates, and lived experiences. People don't want a summary of Reddit; they want Reddit." The letter also said: "As AI makes information more abundant, the challenge is no longer finding content -- it's finding context, personal opinion, and first-hand accounts. Everything online feels flat, polished, generated, or sponsored, so consumers are overwhelmed and increasingly skeptical. We've never had more information, but we've never trusted it less." And then, in comments around the earnings report, he added: "What we see is, 10 blue links has driven tremendous value and growth to the broader ecosystem... from where we sit, AI Overviews has yet to make a similar level of positive impact, and I think that's consistent across the broader landscape, right? As businesses, publishers, retailers, we're still looking for that win-win." Reddit shares nevertheless fell more than 20 percent as investors worried that unstable Google referrals could undermine its growth, even after a strong earnings report.

Read more of this story at Slashdot.

As New York Finalizes New Social Media Rules, US Senate Considers Nationwide 'SCREEN' Act

New York has finalized new rules that will govern social media apps in the state starting on January 25, 2027. The law prohibits social media platforms from sending notifications to minors between midnight and 6 a.m. without parental consent. And minors "will only be shown content from other accounts they follow or otherwise select in a set sequence, such as chronological order," rather than "the default algorithmically personalized feeds... unless they get parental consent for an addictive feed." (Social media companies "must offer at least one alternative method for age assurance besides providing a government-issued ID," the announcements points out, and any information used to determine age "must not be used for any other purpose and must be deleted or de-identified immediately after its intended use.") But meanwhile, the EFF writes that a committee in the U.S. Senate is considering the SCREEN ACT, "a sweeping age-verification bill that would require online services to verify users' ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech." Unlike many state-age verification laws — which have been harmful in their own right — the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content... Under the SCREEN Act, the "bouncer" will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time. The consequences of the bill won't be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults. Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people's private information... The SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users' ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking... The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users.

Read more of this story at Slashdot.

Despite multiple takedowns, botnets continue to grow

Botnets powered by residential proxy networks are proliferating, enabling cybercriminals of all types to evade detection by blending in with seemingly legitimate traffic, Lumen Technology’s Black Lotus Labs said in a report Friday.

The global scale of botnets observed by Lumen is currently approaching 60 million victim IP addresses, Chris Formosa, senior lead information security engineer at Black Lotus Labs, told CyberScoop. Roughly 1 in 4 of those compromised IPs are based in the United States, and the true number of infected devices is much greater because there are networks beyond Lumen’s visibility and multiple devices are often unknowingly running a malicious proxy network on the same IP. 

Super-sized botnets are also gaining momentum, according to Lumen, with an average of 10 distinct botnets controlling their own populations of about 1 million active victims daily.

“The only reason these botnets keep getting more and more victims is because there is clearly a market. Aside from criminal activity, who wants access to millions of IPs regularly?” Formosa said. 

That demand for botnets fuels opportunities for growth, reselling, collaboration, and quick rebounds following massive disruptions.

IPIDEA, one of the largest residential proxy networks in operation when its infrastructure was disrupted by coordinated strikes in January, recovered at nearly half-strength within hours and earlier this surpassed its pre-disruption botnet size with a current botnet population of about 10 million IPs, researchers said.

“Their rebuild was eye-opening as they began to rebound from that interdiction,” Ryan English, information security engineer at Black Lotus Labs, told CyberScoop. “Even for how quickly some botnets can rebound, theirs was surprising. We’ve seen them all rebuild, but we haven’t seen anybody do it that fast.”

Meanwhile, botnets are continuously growing, as cybercriminals seek out the cover they provide, more cheap and poorly defended devices hit the market and vendors stop providing security updates for older but still usable products. 

“Your available pool for those proxy hunters grows every year, and it will continue to grow every year,” English said, adding that more than 1 billion devices are currently vulnerable and available to be unknowingly sucked up into botnets.

The challenge for defenders is lopsided, and while disruptions and seizures occur relatively often, botnet operators have formed a global supply chain with pathways that are difficult to break. 

“We have observed multiple residential proxy services collaborating to form what amounts to the largest cooperative network ever seen on the internet,” researchers wrote in the report.

Black Lotus Labs currently tracks more than 30 distinct malicious proxy botnet clusters, and most of those regularly boast more than 100,000 daily victims.

“Our understanding of the various botnets in this space, along with experience in multiple disruptions, leads us to a very important conclusion: taking down a single malicious proxy provider or their botnet in isolation is likely to result in a short-lived solution,” researchers wrote. 

“In recent years, the malicious proxy environment has essentially created the largest collective botnet currently active on the internet, capable of moving millions of IPs within hours to wherever they are needed,” they added. “Until the malicious proxy landscape is properly addressed and regulated on both the private industry and law enforcement sides, this issue will grow and, along with the DDoS botnet landscape, will most likely become a greater problem in the long term.”

The post Despite multiple takedowns, botnets continue to grow appeared first on CyberScoop.

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.

The NetNut homepage today was replaced by this seizure banner from the FBI.

On June 19, three different security firms issued similar findings: That NetNut is a residential proxy network which populates a botnet called Popa, and distributes software for devices commonly found in homes, such as smart TVs and streaming boxes. NetNut’s software turns those systems into always-on residential proxy nodes that are rented to others, who predominantly use them to relay abusive and intrusive Internet traffic, such as mass content scraping, advertising fraud, and account takeover activity.

Earlier today, NetNut’s homepage was replaced with a seizure notice from the FBI and the Internal Revenue Service Criminal Investigation division. The seizure notice thanked Google, Lumen, Shadowserver and other industry partners for their help in dismantling hundreds of domains tied to the Popa botnet, which experts say has long been synonymous with NetNut’s residential proxy infrastructure.

In a blog post published today, the Google Threat Intelligence Group (GTIG) said NetNut’s proxy network is widely resold and white-labeled by a number of third-party proxy providers, and that its services are heavily sought out by cybercriminals seeking to obfuscate the source of their malicious traffic. The GTIG said that in a single week during June 2026, they observed 316 distinct clusters of threat actors using suspected NetNut exit nodes, including cybercriminal and espionage groups.

“These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks,” Google’s GTIG wrote. “Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats.”

Google said it disabled Google accounts and services used by NetNut for malware command and control, and that it shared technical intelligence on NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement and research firms. The company also disabled apps known to bundle NetNut’s various SDKs.

Omer Weiss, legal counsel for NetNut parent Alarum Technologies, said the company was aware of the FBI seizure and cooperating with investigators.

“Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account,” Weiss said in a written statement.

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies. Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

Brundage said NetNut’s apparent demise is likely to be a great disadvantage for the cybercrime community, which was already reeling from legal actions by Google earlier this year that seized infrastructure for NetNut’s biggest competitor — IPIDEA.

“I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown,” he said. “Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it.”

NetNut’s infrastructure, in a nutshell. Image: Black Lotus Labs, Lumen.

The NetNut and Popa botnet takedown may have another added benefit, Brundage said: Lessening the impact of large distributed denial-of-service botnets that have been built on the backs of poorly configured residential proxy services. In January, Synthient revealed how cybercriminals had built the world’s largest DDoS botnet (Kimwolf) by tunneling through IPIDEA proxy connections into the local networks of TV box owners, and infecting other Android-based devices behind the victim’s firewall.

While many of the bigger proxy providers took steps to block this activity, resellers of the major proxy networks have been far slower to respond to the threat, Brundage said.

“In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there,” he said.

For its part, Google reckons today’s actions have caused “significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions.” But the company warns that proxy networks can rebuild themselves by effectively reselling other proxy services, as IPIDEA has done over the past few months.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes. “While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers.”

As KrebsOnSecurity has warned repeatedly, most of the no-name TV streaming boxes for sale on the major e-commerce websites either come pre-installed with residential proxy software, or require the installation of proxy SDKs in order to use the device for its stated purpose (streaming pirated movies, sporting events and TV shows). Google’s advice here is sound: When it comes to TV boxes, stick to name brands from reputable manufacturers, and then be sparing and judicious with any apps you choose to install.

The sketchy TV boxes that are being commandeered by the Popa botnet and other threats all come with or require the user to install unofficial Android operating systems that do not operate within the confines of Google’s Official Play Protect store. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by following these instructions.

Even people without TV streaming boxes can find their smart TVs enrolled in residential proxy networks, just by installing one of thousands of apps available for download on Samsung and LG smart TVs. In a report released last month, the proxy tracking company Spur found 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found.

Image: Spur.us.

Update, 4:24 p.m. ET: Included a statement shared post-publication from an attorney representing NetNut parent Alarum Technologies.

Update, July 8, 2:34 p.m. ET: The website for Alarum Technologies — alarum[.]io — now also features a seizure notice from the FBI. The company’s stock has taken a beating since the FBI action, and is currently trading at $2.62 a share, a roughly 67 percent decline over the past week.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Malicious streaming devices sold online that enroll the user's home Internet address in a residential proxy service. Image: Synthient. Pictured are 8 different TV boxes, including the X96 Mini Box, stick, and other no-name brands.

Malicious streaming devices sold online that enroll the user’s home Internet address in a residential proxy service. Image: HUMAN Security.

Popa is a massive botnet, but by all accounts it is unlike traditional botnets that enlist compromised systems in destructive activities, such as coordinating huge distributed denial-of-service attacks. Rather, Popa appears designed with a singular purpose: Implementing a persistent communications layer capable of registering a device, maintaining long-lived encrypted connections, and opening communication tunnels on demand.

Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes. These devices, which are marketed under thousands of brand names and model numbers and broadly available for purchase at top e-commerce destinations, all advertise the ability to stream hundreds of subscription video services for an up front one-time fee.

But as the FBI and security industry experts have warned repeatedly, these streaming boxes typically bundle or come pre-installed with software that turns the user’s TV into a “residential proxy” — allowing anyone to route their Internet traffic through that device for as long as it remains plugged into a wall socket and connected to a local network. More concerning, some of these proxy networks do little to stop malicious customers from communicating with and even compromising systems on the local network of the unsuspecting device owner.

The first clues about Popa’s origins came in a 2025 report from the Chinese security company XLAB, which flagged at least nine domain names that were used to register and direct the activities of compromised devices. In a report released today, the security firm Qurium described how it stumbled on some of those same domains while investigating a series of disruptive and expensive data scraping events targeting the company’s hosted organizations in May 2026, in which the scraping activity was scattered evenly across more than 1.4 million Internet addresses.

Qurium said it found several dozen domains used to control Popa that were all hosted in lockstep across multiple Internet addresses over time, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. Digging deeper, Qurium discovered gmslb[.]net was referenced in dozens of pirated or modded video content streaming apps, such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob and HD/OceanStreams.

Qurium’s report notes that most of the domains long used to control the Popa botnet were seized or dismantled in July 2025, after Google, HUMAN Security and Trend Micro teamed up to disrupt Badbox 2.0, a botnet that is closely associated with Vo1d. Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Ninjatech is a company founded by Moishi Kramer, whose LinkedIn profile says he is vice president of research and development at NetNut. That resume credits Kramer for helping NetNut to build from the “ground up,” “designing the architecture,” and “scaling the NetNut” before the company was acquired by Alarum Technologies. A self-created listing at the job board F6S references Kramer as the sole owner of the Ninjatech domain (a screen capture of it is pictured below).

Image: F6S.com.

Responding via email, Mr. Kramer said Ninjatech ceased operations approximately five years ago, when the company sold a software development kit (SDK) called Popa that was designed to use a small portion of a device’s bandwidth and to run only after the host application obtained user consent.

“That code was sold and licensed to third parties including resellers years ago,” Kramer said. “Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it.”

Kramer said neither he nor NetNut builds, operates or maintains the infrastructure being described as Popa, nor does he control the Ninjatech domain.

“I didn’t register the June 2025 domains you mention, and I don’t know who did,” he continued. “I have no control over, or visibility into, that infrastructure. I can only tell you it isn’t operated by me or by NetNut.”

But in a separate Popa research report released today, the proxy-tracking company Synthient said a recent analysis of the Popa SDK revealed outbound traffic clearly associated with NetNut.

“The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients,” Synthient wrote. “This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool.”

Synthient’s platform receiving outbound traffic from Popa. Image: Synthient.com.

Alarum Technologies, NetNut’s Tel Aviv-based parent company, said the reports by Synthient and Qurium contained “demonstrably inaccurate assertions and flawed deductions rather than verified facts.” Alarum shared a statement saying they reject the basic characterization of the SDKs and technologies discussed in the reports as a “botnet.”

“The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems or otherwise compromise the devices on which they operate,” the statement reads. “Netnut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services.”

Alarum said NetNut places “significant emphasis on appropriate notice and consent mechanisms, conducts customer due diligence, monitors for potential misuse, and takes steps intended to detect and mitigate suspicious or unauthorized activity.”

“This method of operation is supported both by internal procedures and policies, including performing KYC checks and additional due diligence of NetNut’s customers, as well as employing various technological measures, designed to assist in identifying and addressing suspected misuse of the network,” their statement continued.

However, in a report released on June 8, the proxy tracking service Spur asserted that NetNut does not require corporate verification or meaningful “know your customer” procedures before allowing customers to purchase proxy access.

“An individual can sign up, pay, and route traffic through partner address space, including space belonging to institutions whose users never opted in,” Spur wrote. “The ‘verified corporations only’ claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies.”

“Nor is NetNut the only front door,” Spur continued. “A number of downstream white labelers and resellers repackage the same ISP proxy pool under their own brands. These outlets typically perform no KYC at all, less scrutiny than NetNut itself, who at the very least might assign an account manager to potential users. Anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto.”

Synthient found that although the most recent builds of Popa (as of three months ago) have added the ability to ask the user for consent before installing proxy components, not all variants or previous versions of Popa contain this functionality.

“Of the over 20 genuine Popa publishers analyzed, none of them were observed asking for user consent,” Sythient wrote.

THE PREVALENCE OF POPA

Chris Formosa is senior lead information security engineer for Black Lotus Labs, a division of the Internet backbone carrier Lumen Technologies.

“What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing,” Formosa said, explaining that many other proxy services simply resell NetNut proxies rather than building out their own far-flung proxy networks. “So these Popa IPs appear in tons of different services all over the ecosystem, which makes it one of the most problematic and dangerous proxy botnets on the market currently.”

Formosa said the Popa botnet averages between 1.5 million to 2.5 million distinct IP addresses each day, relying on between 250 and 300 Internet addresses that are used to direct its activities.

“That’s why Popa is so dangerous,” Formosa said. “It may not be the largest botnet we have seen, but it is spread all over the industry, making its power very amplified.”

Formosa said while that makes Popa one of the larger botnets out there today, its numbers pale in comparison to those previously boasted by IPIDEA, a China-based proxy provider that until recently operated a daily pool of nearly 10 million devices that they resold as proxies to anyone. In January 2026, Synthient published research showing that multiple new large DDoS botnets had grown rapidly by tunneling through IPIDEA proxies into the local networks of unsuspecting TV box owners and infecting other Android-based devices behind the user’s firewall.

IPIDEA is based largely on SDKs used to view pirated streaming content on a vast number of TV box devices, but the service’s numbers have dwindled since January, when Google and industry partners took legal action to seize domain names that IPIDEA used to control devices and proxy traffic through them.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates. Meyer told KrebsOnSecurity that Nokia is monitoring 26 of at least 359 known relay nodes for the botnet, and estimates that each relay node handles between 35,000 and 60,000 clients simultaneously.

“On the relay node subset I am looking at (26 of them), 750,000 unique sources in 24 hours,” Meyer wrote in response to questions.

Nokia Deepfield released its own report today on RoboVPN, a VPN app tied to the Vo1d botnet’s Popa plugin that Qurium attributes to NetNut/Alarum Technologies.

THE SYMBIOSIS OF PROXIES AND DATA SCRAPING

Experts say many of the world’s largest proxy providers have updated their public-facing branding to highlight their utility for training AI platforms, implying it is a primary use case for their residential proxies. That’s because AI services tend to rely on constantly mass-scraping the Internet for new text, images and video content that can be used to train large language models (LLMs).

NetNut and other proxy services have recast themselves as critical infrastructure for the AI scraping economy. Image: Synthient.com.

“AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search,” reads a report this month from Include Security that examines the prevalence of proxy SDKs in smart TV apps. “But the modern web isn’t scrapeable from a datacenter. Cloudflare, DataDome, HUMAN, among others throttle or block requests from known cloud IPs. The workaround is residential proxies. A scraping job routed through a Comcast or T-Mobile subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer.”

This non-stop content scraping has spawned more than 70 copyright infringement lawsuits against major tech companies that have acknowledged large-scale data scraping as a major source of the “brains” behind their commercial AI offerings. Ironically, much of that scraping is being aided by proxy services that are intimately tied to unofficial Android TV boxes and associated SDKs whose stated purpose is streaming pirated content.

The scraping activity has become so aggressive that it often overwhelms the targeted websites, preventing them from being reachable by legitimate visitors. In many reported cases, nonprofit organizations, libraries and universities have complained of constantly battling to keep their services online in the face of relentless data-scraping firms hiding behind residential proxy services.

A survey conducted last year by the Confederation of Open Access Repositories (COAR) found while some content scraping bots are rather innocuous, “others are sufficiently aggressive that they are increasingly causing service disruptions in repositories and other scholarly communications infrastructures.” More than 90 percent of survey respondents indicated their repository is encountering aggressive bots, usually more than once a week, and often leading to slow downs and service outages.

“Automated web scraping is nothing new, and has been the key technology underlying search engines such as Google for over 30 years,” wrote Brendan O’Connell, platform manager at the Directory of Open Access Journals (DOAJ), a free, community-curated index of peer-reviewed academic journals. “However, the current investor-fueled AI startup craze means there are now thousands of well-funded companies developing and deploying their own scraping tools to train AI models, alongside existing major players like OpenAI and Google.”

DON’T TOUCH THAT DIAL!

Across the United States, local communities are pushing back against the proliferation of new data centers aimed primarily at improving the capabilities of AI. But security experts say the general public remains largely unaware that using one of these unsanctioned Android TV boxes means their “smart TV” is almost certainly using a significant amount of bandwidth each month to help train modern AI models.

Even households without these sketchy TV boxes can still have their smart TVs turned into residential proxy nodes, just by downloading one of thousands of apps made available on Samsung and LG smart TVs. Spur said it recently scraped the LG and Samsung app stores and found that each had approximately 3,000 apps available for download. Many of these apps are simple games or utilities that state in the fine print that the user’s Internet connection will be used to download data and that they can opt out at any time.

Spur said it found that more than 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found.

Image: Spur.us.

Experts say it’s questionable whether TV apps with proxy SDKs can obtain meaningful consent from users for installing an always-on proxy connection, particularly when anyone in a household — including children — can effectively opt the family TV into a residential proxy network just by installing a simple game or app.

“Privacy-policy disclosure is the wrong control surface for a TV,” Include Security wrote. “It is hard to scroll through a legal document navigated by arrow keys on a remote, and the in-app consent dialog doesn’t convey that a paying customer is about to route their scraping traffic through the user’s home internet.”

Spur’s head of research Sean Simmons told KrebsOnSecurity that most people do not have a working mental model for what it means to sell access to their residential IP address, no matter what device they are using.

“And on a TV, the gap is even wider,” Simmons said. “A one-time prompt navigated with a remote can disappear into the setup flow, while the app keeps monetizing the connection long after anyone remembers what they accepted.”

Simmons said LG and Samsung should follow the lead of other TV platforms that have already drawn a line against residential proxy providers, pointing to policies by Amazon that prohibit apps facilitating proxy services for third parties. Likewise the TV streaming device maker Roku reportedly now bars developers from using proxy SDKs and has removed apps that bundled them.

Piracy related apps pushing proxy SDKs onto unconsenting users. Image: Synthient.

Apps that turn one’s device into a residential proxy node are not limited to smart TVs and no-name streaming boxes, of course. As noted by the security firm Infoblox, mobile app developers can embed SDKs provided by the residential proxy networks into their products to monetize their software, allowing them to receive a small amount of money on each installation.

The result, Infoblox said, is that devices are frequently enrolled without the owner’s knowledge, typically through free applications such as VPNs, streaming apps, screensavers and “productivity” apps such as PDF viewers and break reminders.

All too often, these proxy services are beaconing out from employee devices brought into the workplace, Infoblox found. In a blog post earlier this month, Infoblox said it discovered that fully 65% of its customer base was querying one or more residential proxy related domains.

“We saw steady growth in these queries in 2025, with a 25% increase over the year to over 500 billion per month,” Infoblox wrote. “Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators. Perhaps even more concerning is that over 60% of government and banking customers have as well.”

Infoblox researchers Nick Sundvall and David Brunsdon warned that with residential proxies in the corporate environment, external access is granted to an organization’s IP space.

“If threat actors were to abuse the residential proxy to attack a third party, the third party’s incident response would, correctly, identify your residential proxy as the source,” they wrote. “Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation. The stunning prevalence of these services within customer environments warrants attention from both network defenders and policy makers who should consider how the risks posed by residential proxies could be impacting their security posture.”

❌