❌

Reading view

There are new articles available, click to refresh the page.

Bitdefender first to launch free 'temporary' VPN for AI Agents because they're worth it — but you can only use it on Apple M-series Macs for now

  • Bitdefender launches privacy tool built specifically for autonomous AI agents
  • Each agent task gets a disposable, temporary connection that deactivates when the task is done
  • VPN for AI Agents runs on a Model Context Protocol server architecture entirely

Bitdefender has introduced VPN for AI Agents, a standalone privacy tool built specifically for the autonomous software agents now browsing, researching, and transacting on behalf of everyday users.

The company says this public beta is a direct answer to the growing anxiety over machine-driven data exposure.

Unlike a conventional privacy tool that stays connected at all times, this tool activates only when an AI agent needs it, then deactivates once the task is done.

Why agents need their own privacy layer

Cybersecurity researchers have increasingly warned that autonomous agents occupy an ambiguous identity space, often borrowing a person's own credentials or shared workload logins to complete tasks online.

Without a clear separation, every website an agent visits and every transaction it completes remains traceable back to a single household IP address.

Recent Pew Research Center data found 71% of adults in the United States believe wider AI adoption will make their personal data less secure, a fear that extends well beyond American borders.

Bitdefender's new offering, built on a Model Context Protocol server architecture, spins up a disposable digital workspace for each prompt and discards it when the task is done.

Each prompt opens its own encrypted tunnel and exits through the VPN server's IP address, so no cookies, cache, or session state carries over to the next task.

The tool covers network transport and IP masking only, leaving the actual content of a prompt exchanged directly between the user and whichever AI provider is running it.

"AI agents are quickly becoming an extension of the people who use them, showing up in both our workdays and our personal lives," said Ciprian Istrate, senior vice president of operations, Consumer Solutions Group at Bitdefender.

"That means security can no longer stop at protecting the person behind the screen; it has to extend to the agent itself acting on their behalf."

This approach treats each agent like an independent team member requiring its own security boundary rather than inheriting the user's existing protections wholesale.

Bitdefender also describes this as clean-IP browsing, useful for QA checks on pages that display different content depending on the visitor's country.

The tool supports up to four simultaneous exit locations, or eight under the recommended testing configuration.

Access remains limited during the beta period

For now, the tool works only on macOS devices, though Bitdefender has confirmed plans to expand to additional operating systems after beta testing.

The beta specifically requires macOS 13 or later and an Apple silicon processor, meaning Intel Macs are not supported.

Bitdefender recommends macOS 15, 16 GB of memory, and roughly 10 GB of free disk space for smoother testing.

Once installed, it operates automatically across several popular AI platforms, including Claude Desktop, Cursor, Codex, and OpenCode, without requiring manual configuration from the user.

Bitdefender lists several practical use cases, including letting an agent compare prices across regions or complete multi-country research in one session.

The company frames these tasks as a productivity gain too, since they would otherwise need manual, country-by-country effort from a person.

Bitdefender is explicit about the tool's limits as well. It does not protect a device's other apps or browser.

It also does not hide prompts from the AI provider running them, and does not override a site's terms of service, rate limits, or an existing IP ban.

"With Bitdefender VPN for AI Agents, we're giving students, workers, and everyday consumers the confidence to let their AI agents work freely, knowing their identity and activity stay protected," Istrate added.

VPN for AI Agents public beta is currently available for free, but whether the free offering continues after the beta testing remains to be seen.

Google logo on a black background next to text reading 'Click to follow TechRadar'

Amnezia VPN boosts stability of all apps with a new update

  • AmneziaVPN rolls out version 5.0.3.0 across all apps
  • It brings new XRay-core, TProxy, and minor user updates
  • It includes upgrades for Self-hosted and Premium users

Anti-censorship Amnezia VPN has released a new app version that improves stability, introduces an updated Xray-core, and brings updates for both self-hosted and Premium users.

The move comes after the VPN provider spent months strengthening its security measures to counter the attacks launched by Russian organisations that specifically targeted the best VPNs operating in the region.

Version 5.0.3.0 is available on all devices (version 5.0.3.1 for Android); users can download it from the Amnezia website, GitHub, and the Android and iOS app stores.

Amnezia VPN — censorship-resistant VPN
Amnezia VPN is an affordable, privacy-focused service that prioritizes essentials like security and censorship unblocking over unnecessary extras. All its apps are open-source, albeit more basic than some competitors. It offers both Free and Premium protection, with the latter billed at $28 for six months and $48 for a year. You have 14 days to decide if you like it or not, risk-free, thanks to its money-back guarantee. View Deal

Amnezia VPN 5.0.3.0: what's new?

Rather than a major update with dramatic new features, the new version emphasises general clean-up, maintenance and connection stability.

For example, the XRay protocol, the core component of the proxy that allows users to bypass censorship, has been updated from version 1.3 to 1.4, in line with the adoption of a newer protocol system in the new version.

Additional support for the TProxy container has also been introduced. The Linux support is useful for routing traffic through the VPN at the transparent proxy level, essentially allowing Linux systems to make the traffic appear as if it originates from the user, thereby making it more difficult to block WireGuard connections.

The update also enables self-hosted users to set up a proxy for Telegram by directly going to the “Self-hosted” section to install it.

⚡️The new app version 5.0.3.0 is here.It is now available for all devices (version 5.0.3.1 for Android). Download it from our website or directly from your app store.In this release, we have improved connection stability, updated Xray-core, and added several important updates…September 22, 2026

For Premium users, the VPN has also improved performance when connecting via the VLESS anti-censorship routing protocol.

Additional fixes addressed Android warning log levels, alongside self-hosted default values, links, and other minor issues that have been corrected.

In terms of user changes, the new release includes a Google Play billing library, which was added as a small feature component to handle In-App Purchases (IAP), and a new country was added to the supported dataset, overall boosting the user experience with minor tweaks.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

Relentlessly updating

Amnezia's efforts to combat censorship had largely focused on previous updates, designed to strengthen its anti-detection capabilities in response to the Russian government's increasingly sophisticated Internet censorship regime.

In June, the open-source VPN said it fixed a bug in its AmneziaWG protocol that had previously left its infrastructure vulnerable to a coordinated cyberattack, allegedly carried out by Russia's media regulator, Roskomnadzor (RKN).

In August, the VPN focused again on security by updating its anti-censorship protocol, AmneziaWG, introducing greater variability in traffic patterns to increase the VPN’s invisibility against new detection methods. During the same month, the provider also strengthened its blocking capabilities with a 'mandatory update' for Premium and Free users.

The move came after a crackdown by the government blocked access to more than 20 widely used privacy services, with the scale of the attack suggesting that Roskomnadzor is continuing to boost new sophisticated ways to filter VPNs.

These governmental repressive measures are making it increasingly difficult for citizens to access the free internet. Additionally, the more repressive these attacks are, the more they seem to influence citizens' perception of VPNs as an everyday tool they need, rather than the opposite.

Indeed, research recently showed that they are developing new forms of collaboration to use VPNs, and view the associated costs as just as essential as those for mobile Internet and routine bills.

'Using VPNs is not criminal:' digital rights advocates return for a second Defend VPNs Day of Action

  • Fight for the Future is running its 2nd annual Defend VPNs Day of Action
  • VPN restrictions are increasingly being tucked inside new internet laws
  • Utah, Michigan, the UK, Russia are among those targeting VPNs this year

Digital rights advocates are once again asking people around the world to stand up for VPNs, as lawmakers increasingly treat privacy tools as a loophole to be closed.

September 25 marks the second annual Defend VPNs Day of Action, organized by digital rights group Fight for the Future. The campaign asks users to sign an open letter and call their representatives, urging them not to ban or restrict VPNs.

Whether you rely on the best VPN on the market or a free app to stay safe on public Wi-Fi, the rules around how you can use it are changing fast.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

What is the Defend VPNs Day of Action?

The campaign launched in 2025, when Fight for the Future says it engaged around 20,000 people. This year, the group wants to build on that number.

Supporters can sign a letter to government leaders at DefendVPNs.com, which calls VPNs an essential tool for privacy and access to information. The site can also connect users directly to their lawmakers' offices by phone, and it provides a suggested script.

VPN providers are getting involved, too. Amnezia VPN and IPVanish have already announced their support and are encouraging users to sign the petition, while Surfshark is also listed as a supporter.

Why VPNs need defending

According to Fight for the Future, VPN bans and restrictions rarely appear on their own. Instead, they are most often bundled into age verification bills, or "online ID checks," that require people to prove their age before accessing certain sites.

Advocates argue the stakes go far beyond adult content. Fight for the Future says the most vulnerable people rely on VPNs to reach loved ones, seek healthcare, and find information that is increasingly locked behind ID checks and biometric scans.

"Using VPNs is not criminal," said Sarah Philips, Campaign Director at Fight for the Future, adding that "Using VPNs is a right that must be defended at all costs from governments who are doing their best to break down what little privacy we have in the current tech landscape."

A year of attacks on VPNs

VPN world map

A screenshot of Opear VPN Pro (Image credit: Getty)

Here's a quick look at the biggest threats since last year's Day of Action.

Despite lawmakers in Wisconsin scrapping a provision forcing sites to block VPN users after widespread backlash, SB 73 made Utah the first US state to target VPNs in an age verification law.

A proposed "public morals" bill in Michigan would make ISPs block VPNs, with fines of up to $500,000 for promoting them. It remains in play.

In the UK, Ministers ruled out age-gating or banning VPNs, but platforms are now expected to stop users from circumventing age checks themselves.

Australia's officials explored ways to block age verification workarounds, while the EU has signaled VPNs could be next in line after announcing a social media ban for teens.

In Brazil, VPN use became an aggravating factor in crimes, Reclaim The Net reported.

In Russia, Human Rights Watch reported this week that at least 469 VPNs had been blocked by February, with authorities now turning to bulk IP blocks and app store takedowns. Amnezia VPN itself was targeted in June and needed around six weeks to fully recover.

With youth social media bans spreading to Indonesia, Malaysia, and the UAE, Fight for the Future warns that VPNs will only face more scrutiny.

Anyone who wants to add their voice can do so at DefendVPNs.com.

We are telling AI chatbots our biggest secrets, but Proton warns our privacy is at huge risk

  • 66% of UK AI users have discussed highly sensitive topics with a chatbot
  • Yet, 64% of respondents are worried that chats will be used to profile them
  • Proton's privacy-first chatbot, Lumo, aims to fix this trust gap

Late at night, when you need to vent about a relationship, ask for career advice, or check a worrying health symptom, who do you turn to? For a rapidly growing number of people, it isn't a friend, family member, or doctor; it's a chatbot.

A new piece of research published today by Proton, the Swiss tech firm behind some of the best VPN services on the market, reveals that a staggering 66% of British AI users have discussed at least one sensitive topic with an artificial intelligence assistant.

However, there is a massive contradiction at the heart of this new digital relationship: we are pouring our hearts out to these chatbots, but we do not actually trust them. According to the survey, 42% of UK users have little or no trust in AI companies to protect their private information, and 11% don't trust them at all.

Despite these glaring privacy reservations, 55% of Brits admit that AI has fundamentally changed their everyday decision-making.

Proton VPN – best for privacy
Based in Switzerland, this privacy-first VPN offers good speeds, advanced anti-censorship features, and a server network that spans 145 countries around the world — including across Africa and Asia, where other providers tend to struggle. While its free VPN plan is handy, it comes with limitations. The good news is that upgrading to a premium subscription will cost you only the equivalent of $2.99 per month.View Deal

The ultimate judgment-free zone

So, why are we sharing our most intimate thoughts with machines we don't trust? The answer is simple: freedom from judgment.

While friends and family remain the preferred choice for most sensitive discussions, AI offers a 24/7 digital confidant that won't react with surprise or embarrassment.

Proton's data shows personal finance is the most commonly discussed sensitive topic (33%), followed closely by work or career problems (32%), mental health struggles (27%), and relationship issues (20%).

66% of people have told an ai chatbot something sensitive.Their finances. Their mental health. Their sex life.At most 1 in 5 trust the companies holding that information.1/6 🧵September 24, 2026

"AI is learning far more about us than a search engine ever could," said Eamonn Maguire, Director of AI Engineering at Proton. "We’re not just asking questions. We’re sharing deeply personal context about our health, finances and relationships. And when technology knows that much about us, privacy can't be an afterthought."

The primary worry isn't just about the AI remembering a single chat, or even the risk of human reviewers reading your logs. Users are increasingly terrified of the bigger picture.

In the UK, 64% of respondents are concerned that their vulnerable conversations are being weaponized to build detailed advertising or marketing profiles. Meanwhile, 52% are worried their secrets are being fed back into the machine to train future AI models.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

How Lumo promises a private alternative

Lumo AI by ProtonVPN

(Image credit: Lumo/Edited with Gemini)

Despite these valid fears, Brits are highly receptive to a more secure way forward. A massive 82% of users said they would be more likely to use an AI chatbot specifically designed around privacy, and 44% would be far more willing to share sensitive information if they were given a cast-iron guarantee that their chats wouldn't be used for AI training.

This is exactly where Proton hopes to fill the gap with Lumo. Built with the same end-to-end encryption ethos as the company's famous email client, Lumo is an open-source, privacy-first ChatGPT alternative.

To help users understand the scale of their digital footprint, Proton recently launched AI Paper Trail, a tool from Lumo that visually demonstrates exactly how much personal information an average AI conversation leaks about a user's inner life.

"People have already decided that AI is useful enough to hear their money worries, doubts and everyday concerns. They are handing AI companies their inner lives and biggest secrets on the assumption that they will protect them when it's actually the opposite. AI's business model depends on learning from them" Maguire added.

Forget to turn on your VPN? Opera's free browser VPN now does it for you on public Wi-Fi

  • Opera's free built-in VPN can now switch itself on public, unsecured Wi-Fi
  • The opt-in feature is rolling out to users in the US and France first
  • Opera VPN Free still only protects your browser

Opera browser is making it harder to forget about your VPN.

The company's free, built-in VPN for desktop can now turn itself on when you connect to a public or unsecured Wi-Fi network.

The feature is opt-in, so you'll need to enable it in settings first, and it's rolling out to desktop users in the US and France starting today.

Even the best VPN can't protect you if it isn't switched on, and Opera is betting that removing that manual step will get more people covered on risky networks.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

Opera VPN Free goes on autopilot

Opera has offered its built-in VPN since 2016. It's free, doesn't require an account, and has no fixed bandwidth cap. Its no-logs policy has also been independently audited by Deloitte. Until now, though, you had to remember to switch it on yourself.

With this new setting, however, the Opera browser turns the VPN on automatically when it spots a public network. So, working from a café, studying on campus, or browsing at an airport no longer means activating the VPN manually every time.

The option first surfaced in testing earlier this month, when release notes for Opera Developer 137 listed an option for the VPN to connect automatically on public networks.

Arjan van Leeuwen, Head of Opera One Engineering, said VPNs "are a vital part of users' digital hygiene".

The company also notes that competitors like Chrome and Safari still don't offer built-in browser VPN features by default. It also cites We Are Social data showing that only 23% of internet users worldwide used a VPN as of Q4 2025.

Why public Wi-Fi is a risk

Public Wi-Fi is convenient, but open networks can be joined by anyone nearby, who can then snoop on or inject malicious traffic.

A trustworthy VPN encrypts your traffic, which makes it much harder for attackers to intercept and steal your data.

Automating that step closes the gap between knowing you should use a VPN and actually doing it.

Opera VPN Free vs Pro: a quick overview

Revamped Opera VPN Pro – promo image

A screenshot of Opear VPN Pro (Image credit: Opera)

Opera VPN Free is built into the browser and costs nothing. However, it only protects traffic inside Opera, so apps like Spotify, Steam, or a standalone email client still use your regular connection.

Opera VPN Pro, which launched as a paid tier in 2022, is a system-wide VPN. It covers up to six Windows, macOS, or Android devices, and it has run on ExpressVPN's Lightway protocol since mid-2025, with 48 server locations.

Lightway also brings post-quantum protection by default. Opera lists Pro from $4 per month, and new users can try it with a 7-day free trial.

If you mainly want to keep your browsing safe on the odd café hotspot, the free VPN with auto-connect is an easy win. If you want every app on your device protected, you'll need Pro or a dedicated VPN app.

Obscura VPN finally arrives on Linux — with a GUI, a CLI, and a new open-source license

  • Obscura VPN has released a native Linux app, with both GUI and CLI
  • Official packages cover Debian, Ubuntu, Fedora, Arch, and other derivatives
  • The provider has also switched to an open-source GPLv3 license

Obscura VPN has finally arrived on Linux. The privacy-focused provider has launched a native desktop app for the platform, meaning Linux users no longer need to set up the service manually.

This rounds off a busy year for the newcomer, which only recently landed on Windows. With this release, Obscura now supports macOS, iOS, Android, Windows, and Linux.

For privacy-minded Linux fans hunting for the best VPN for their setup, Obscura's unusual two-party design makes it one of the more interesting options.

The company is also relicensing its code under GPLv3, which will appeal to open-source purists.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

What's new in Obscura's Linux app

Obscura's Linux app ships with a full graphical interface, alongside an experimental command-line interface for users who prefer the terminal. Until now, Linux users had to rely on a manual WireGuard setup guide to connect. The native app means no more juggling configuration files, making the service far more accessible.

Obscura offers official packages for Debian, Ubuntu, Fedora (including Atomic Desktops like Silverblue), and Arch, as well as derivatives like Linux Mint, RHEL, Silverblue, CachyOS, and Omarchy. Minimum requirements include Ubuntu 24.04, Debian 13, Fedora 44, and RHEL 10, and the app is installed through Obscura's own package repository.

The Linux client also supports Obscura's QUIC-based stealth protocol, which makes VPN traffic look like ordinary HTTP/3 web browsing. This can help you get past networks that block VPNs.

To mark the launch, Obscura is offering 25% off for a limited time with the promo code LINUX26. The service normally costs around $8 per month, with no free tier.

🐧🚨 OBSCURA FOR LINUX IS HERE 🚨🐧Now available for Ubuntu, Fedora (+Atomic Desktops), Arch, Debian, and derivatives.To celebrate, we’re giving everyone 25% off with code LINUX26.THAT'S NOT ALL: Obscura is also GPLv3 licensed now, making us fully Open Source!👇 Links pic.twitter.com/IIAzAgSOm7September 22, 2026

Obscura goes GPLv3

Alongside the launch, Obscura has moved from the PolyForm Noncommercial License 1.0.0 to the GNU General Public License v3.0, which it says furthers its commitment to open-source software.

Obscura's code has been public since day one, but GPLv3 is a true open-source license, giving the community more freedom to inspect, modify, and share it. It's the same license Mullvad uses for its own apps.

What is Obscura VPN?

Obscura was founded by Carl Dong, a former Bitcoin Core contributor, and first launched on macOS in February 2025. It promised to set the standard for next-gen VPNs, and has since expanded to iOS, then Android, Windows, and now Linux.

Its big selling point is a two-party relay. Obscura acts as the entry node and sees your real IP address, while Mullvad VPN handles the exit node and sees the websites you visit. This means no single provider knows both who you are and what you browse.

That design has already been tested. Security firm Cure53 audited Obscura and found no major security vulnerabilities, as we reported last December.

Your ExpressVPN app on Windows, Mac, and Linux just got more flexible and more reliable

  • ExpressVPN has released version 14.3.1 for its Windows, Mac, and Linux apps
  • Advanced Protection's ad and tracker blocking now works beyond the Lightway protocol
  • The update also brings a rebuilt speed test, stronger screen reader support, and fixes for each platform

ExpressVPN has pushed out another update for its desktop VPN apps, and this one packs in more than the last few. Version 14.3.1 landed on Windows, Mac, and Linux on September 22.

The biggest change is that Advanced Protection, ExpressVPN's set of ad, tracker, and malicious site blockers, now works across all VPN protocols. There's also a rebuilt speed test, smarter split tunneling, and plenty of reliability fixes.

It's the latest in a busy year for one of TechRadar's best VPN recommendations, following a visual makeover and a stable MCP server for AI tools in June.

ExpressVPN: Starting from $2.49 per month
ExpressVPN is the easiest VPN to use on our list, making it a great option for anyone slightly less tech-savvy. It’s also very fast thanks to the Lightway Turbo protocol and has great unblocking skills, making it an ideal streaming VPN. Subscriptions start at $2.49 per month on the two-year plan. As with most VPNs, there’s a 30-day money-back guarantee.View Deal

Advanced Protection finally works on every protocol

Until now, Advanced Protection on ExpressVPN's desktop apps only functioned with the VPN switched on and the Lightway or Automatic protocol selected.

Version 14.3.1 lifts that restriction, so you can now block ads, trackers, and harmful sites while using OpenVPN or WireGuard.

That's a welcome change for anyone who switches protocols to cope with tricky networks, since you no longer have to give up those protections to do it. ExpressVPN notes the feature is rolling out gradually, so not everyone will see it straight away.

Faster speed tests and smarter split tunneling

The built-in speed test has been rebuilt to run faster and deliver more precise results, which should make choosing the quickest server an easier job.

Split tunneling is more reliable for apps you exclude from the VPN, and the setup guidance has been refreshed. On Windows, the feature no longer keeps scanning for new apps when it's switched off, which cuts CPU usage. On Mac, split tunneling now leaves DNS traffic alone, so it can run alongside Advanced Protection.

On the accessibility side, screen readers can now navigate the location list, protocol settings, split tunneling, and auto-connect rules. The app also announces connection status and settings changes. That builds on the accessibility push in version 14.1.0, an area where our review rated the app just three out of five.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

Fixes for every platform

Mac users get a fix that stops Docker containers from disrupting networking while connected, and the app now launches even when there's no network after waking or booting.

On Windows, the VPN stays connected when your screen turns off on Modern Standby PCs, and installation is more reliable on ARM64 devices.

Linux users benefit from improved Lightway routing and DNS configuration on systems that use resolvectl, including Pop!_OS, along with native desktop notifications. It's another step forward for ExpressVPN as a Linux VPN option, following the arrival of its rebuilt Qt-based Linux app in late 2025.

If you already use ExpressVPN, the update should install automatically. Otherwise, you can download the latest build from ExpressVPN's website. To confirm you're on 14.3.1, check the app version, which now sits at the bottom of the sidebar.

US bill threatens to turn your VPN into a piracy blocklist

  • A new US proposed law would force internet providers and VPN services to block "foreign piracy sites" via expedited court orders
  • The legislation would apply to ISPs, DNS resolvers, and any VPN provider with at least 100,000 monthly US subscribers
  • Digital rights groups warn the fast-track legal process risks massive overreach, citing similar policies in Europe

A newly introduced bill in the US House of Representatives is threatening to fundamentally change how virtual private networks operate within the country. If passed, the legislation would force VPN providers to actively block access to piracy websites, turning vital privacy tunnels into heavily filtered exit ramps.

The American Copyright Protection Act (ACPA), formally numbered H.R. 10364, was introduced by Representative Darrell Issa (R-CA) on September 16, 2026. The bill aims to give copyright holders a fast-track judicial process to obtain blocking orders against platforms accused of copyright infringement.

Crucially, the ACPA explicitly names VPN services alongside traditional broadband providers and DNS resolvers as entities that must enforce these blocklists. For users who rely on the best VPN software to ensure unrestricted, unmonitored internet access, this legislation poses a direct threat to the core promise of the technology.

The blocking obligations would apply to any VPN service with at least 100,000 monthly US subscribers. This threshold catches almost all major consumer VPN brands, effectively forcing the industry's biggest players to implement nationwide web filters or risk severe legal consequences.

Laura Tyrylyte, privacy advocate at NordVPN, told TechRadar that there are thousands of VPN solutions available for users worldwide; however, "these blocking measures primarily target reputable, paid VPN providers, leaving free VPN services largely untouched."

"Free VPNs are often harder to regulate, and since users who seek to avoid paying for content are unlikely to pay for a VPN either, these services will continue to operate without any impact," she added.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

Fast-track censorship "at the speed of light"

Under the ACPA, a copyright holder can petition a designated federal judge to declare a website a "foreign piracy site." The evidentiary bar for this is surprisingly low, requiring only a "preponderance of the evidence." Once approved, covered providers are given 14 days to object before the blocking order takes effect, though crackdowns on live sports and other time-sensitive material could be executed even faster.

Rep. Issa has made no secret of his desire for aggressive enforcement. Speaking at a June hearing, he framed his goal bluntly: “Can we do it at the speed of sound? Can we do it at the speed of light?”

Digital rights organizations have heavily criticized the proposal. Meredith Rose of Public Knowledge warned that the bill would force any service provider "to disrupt traffic from targeted websites simply accused of copyright infringement."

Meanwhile, Brandon Butler of Re:Create argued the legislation codifies "a one-sided legal process modeled on European site-blocking laws" and "violates American due process, First Amendment rights, and American ingenuity."

To mitigate the risks of false positives, the bill includes an error provision allowing companies wrongly blocked to claim up to $250,000 in damages, though critics argue this offers little financial comfort to innocent small businesses taken offline.

A growing global threat to unfiltered internet

A mobile phone with a generic VPN screen and a world map of the server network in the background.

(Image credit: Getty Images / NurPhoto)

This isn't the first time US lawmakers have targeted VPNs in 2026. The ACPA arrives on the heels of Utah's SB 73, a controversial state law that attempted to regulate VPN use for age verification before facing an enforcement freeze. The ACPA also joins other pending federal proposals, such as the Block BEARD Act and the Foreign Anti-Digital Piracy Act.

However, the real warning signs come from overseas. As Butler noted, the ACPA heavily mirrors aggressive European anti-piracy campaigns, which have already put VPNs in the crosshairs. In countries like Spain and France, court-ordered VPN blocking is already a reality.

These systems have already shown their potential for collateral damage. An analysis by Re:Create found that in Italy, innocent websites remained blocked for an average of 320 days due to overzealous filters. In Spain, over 500,000 websites were wrongly blocked during LaLiga matches, temporarily restricting access to 5.8% of the popular internet.

If the ACPA advances, a VPN's legal jurisdiction will become more vital than ever. US courts cannot automatically enforce orders against providers incorporated in privacy havens like Panama or the British Virgin Islands. Until then, the battle for the open internet continues on Capitol Hill.

Apple's iOS 27 found to break NordVPN's scam and phishing protection — and it isn't the only privacy tool impacted

  • Apple's latest iOS update has been found to undermine NordVPN's anti-phishing tool
  • The feature that causes the issue, Connectivity Assist, is turned on by default as part of the update
  • According to NordVPN, the issues could have been prevented

Apple's new iOS 27 operating system update is undermining NordVPN’s anti-phishing tool, leaving users exposed to privacy vulnerabilities, the VPN has warned.

Connectivity Assist, a Wi-Fi Assist feature included in Apple’s twentieth operating system release, conflicts with NordVPN’s real-time protection, preventing it from working properly, the provider has found.

What’s worse? The tool is enabled by default, meaning users may not even know. What's more, other privacy tools on your phone may also have been compromised.

The problem with Connectivity Assist

NordVPN

(Image credit: NordVPN)

Connectivity Assist optimises your Wi-Fi connection by supplementing slow or unreliable Wi-Fi connections with mobile data, detecting connection issues, and redirecting requests to your mobile operator’s DNS servers instead.

However, when NordVPN’s anti-fraud protection blocks a phishing site, Apple may also interpret the failed connection as a Wi-Fi issue and switch to mobile data—outside the VPN’s protection—thereby compromising the functionality of the NordVPN tool.

The only option currently available to ensure full protection is to disable Connectivity Assistant, so it can’t switch to mobile data when real-time protection blocks a website.

Alternatively, you can choose only to enable real-time protection when using a VPN by disabling NordVPN’s ‘always on’ option - but this still leaves them unprotected when using mobile data - just now by choice.

“People are being made to choose between two things they shouldn't have to choose between, and there's no good way for us to fix it,” Laura Tyrylyte, Head of Public Relations at NordVPN, tells TechRadar.

Can this be prevented?

Could Apple have helped resolve these issues before the release? Perhaps, according to the VPN representative. “Apple knew the feature interferes with DNS-based filtering before it shipped,” Tyrylyte notes. “Their own support page tells people running an ad blocker to switch Connectivity Assist for that network. Somebody spotted the conflict, it just didn’t get fixed.”

Users of Pi-hole, Firewalla, and other DNS-based filtering tools had previously reported the same behaviour, and Cloudflare's WARP also stopped blocking malicious sites following the update, NordVPN stressed.

Apple engineers have suggested alternative solutions in the forums, but these only work if users configure the DNS settings themselves, notes Tyrylyte.

“Deciding to treat deliberate filtering as a failed connection is a choice somebody made. They could have written it the other way: if a user-installed DNS service decides to resolve or block the query, leave that judgement alone,” Tyrylyte adds.

“Instead, the problem got handed to users, who now need to end up fielding the support tickets for something we can’t change,” she stresses.

NordVPN states that this is not the first time a change made by Apple to the network has compromised a security feature on iOS, with the VPN having to inform users.

In 2023, Apple’s VPN API contained vulnerabilities that disrupted NordVPN operations. “Both times users ended up having to pick between an Apple feature and their own protection, and both times Apple was the only one who could have prevented that,” Tyrylyte says.

“Apple makes the call, and we find out what the call was when the release lands, she stressed.

Whoever’s responsibility this is, one thing is for certain: it is users who stand to pay the highest price when tools quietly stop working. And reporting the issue in the press as a solution seems a poor substitute for preventing the problem in the first place.

Apple is yet to respond to a request for comment.

VPN Deal of the Week: NymVPN drops low-commitment price plans – a cheaper way to try out its class-leading mixnet security

NymVPN's latest update has shaken up its entire pricing structure. Two-year plans are completely gone, and, oddly, some prices have gone up, but, with the product better than ever before, it may be time to take notice.

NymVPN has rapidly been maturing. Most recently, its v2026.12 update added improved connection stability on WireGuard and a simpler onboarding experience to its deliberately complex VPN architecture.

All the best VPNs use complex security methods to ensure your data is never at risk, but NymVPN's mixnet takes this one step further.

Data you send from your device bounces between five different servers, and is encrypted at each, before exiting at the designated end server. In short, it adds five times the number of steps of additional security to your connection before sending you where you desire online. The idea is that it makes you next to impossible to identify and track.

Before subscriptions to NymVPN were for 1 month, 1 year or 2 years but they company has now switched that around by axing the 2-year plan and adding in a 6 month version.

Monthly plans are comparatively cheap for the VPN industry at $8 per month. That's about half what you'd pay for NordVPN, for example. Equally, at $4 per month, the 1-year plans are also good value.

And the 6-month plan is smack in the middle at $6/month.

NymVPN: 12 months of protection for $4 per month.

NymVPN is pick of the bunch if you're after unquestionable privacy. Its decentralized mixnet architecture means your VPN connection is untraceable and encrypted at every point of its journey, without losing any functionality you'd expect from a VPN. You can also pay for it completely anonymously. Give it a go with a true 7-day free trial.View Deal

Is NymVPN only good for security?

NymVPN's security technology is among the most sophisticated available. There are no other VPNs that run a decentralized noise-generating mixnet, but that doesn't mean that it lacks any of the more consumer-friendly features.

It offers over 70 server locations, split tunnelling capabilities, kill switch protection, obfuscation technology, and streaming unblocking.

When we completed our NymVPN review, back in 2024, at the time of its launch, far fewer of these capabilities were deemed possible. Now, its combination of security and functionality makes NymVPN a must-watch VPN over the coming months.

If you want a more mature product right away, then one of the very best VPNs might suit you better.

NordVPN, for example, performs best for overall performance. Surfshark is the best cheap VPN available, and Proton VPN is the next best thing if you're looking for privacy.

Either way, Nym is a sure-fire up-and-comer, and not a VPN to ignore.

NymVPN’s massive new update adds one-click connections, advanced split tunneling, and fresh pricing

  • NymVPN has launched a new version of its app - v2026.12
  • It introduces a host of speed-focused improvements, alongside improved usability, better onboarding, and new anti-censorship capabilities
  • Alongside the technical changes, a new pricing structure has removed the 2-year plan entirely

NymVPN's latest update marks its latest move to put the best VPNs in its crosshairs. The provider has launched version 2026.12, bringing a massive wave of usability improvements, anti-censorship tools, and a brand-new pricing structure across its desktop and mobile apps.

According to the Nym Core Team, this release is laser-focused on "getting the safest connection to more people, in more places, with less in the way."

To that end, NymVPN has completely reworked its WireGuard handshake to deliver faster, more stable cellular connections. This means your VPN is far less likely to drop when switching from Wi-Fi to a spotty mobile data network. It also introduced a new onboarding experience to help you get started smoothly with the VPN's unique, decentralized mixnet.

One-click routing and smarter split tunneling

The most immediate change users will notice is the introduction of one-click connections. NymVPN has introduced a "Safest" default setting that automatically picks a strong-performing server in a country next to yours, ensuring your entry point sits safely outside your home jurisdiction. Users can also select "Random" to constantly break traffic analysis patterns, or rely on "Favorites" and "Recents" for instant access to trusted nodes.

NymVPN is also expanding on its earlier beta tests by officially launching geo-exclusion alongside traditional split tunneling for desktop (macOS, Windows, Linux).

While basic split tunneling lets you send a whole app outside the VPN, geo-exclusion is far more precise. It splits a single app's traffic by destination, allowing you to route local services (like a banking app) outside the tunnel while keeping international traffic protected. The team notes this feature is currently available for Chinese IPs, with more countries coming soon.

NymVPN Geo-exclusion settings screen

(Image credit: NymVPN)

Beating censorship on the go

For users in restrictive regimes, simply having a VPN app visible on your phone can be dangerous. Following earlier iOS icon disguises, NymVPN has now brought a camouflage icon feature to Android, allowing users to hide the software behind a discreet alternative logo in their device settings.

The provider is also expanding its global accessibility, launching five new languages: Traditional Chinese, Traditional Chinese (Hong Kong), Japanese, Italian, and Indonesian. As the developer noted in its release, "for people living under censorship, a VPN they can actually read is a necessity, not a nicety."

Pricing shake-up and what's next

NymVPN is tweaking its subscription model to reflect the app's growing feature set. The provider has introduced a new six-month plan at $6 per month, while maintaining a standard monthly tier at $8.

However, the company is retiring its two-year subscription tier. The best value is now the one-year plan at $4 per month. NymVPN confirmed that existing two-year subscribers will keep their current plan, but it will automatically renew as a one-year plan when it expires.

The provider claims it remains one of the most affordable options on the market, adding that its "privacy is guaranteed by design, not by a promise a centralized VPN structurally can't keep."

Looking ahead, the NymVPN roadmap promises QR-code support for faster activations, expanded geo-exclusion for Russia, and customizable entry-and-exit server profiles.

Mullvad has silently revamped its Android VPN app — here’s what you need to know

  • Mullvad has released version 2026.10 of its Android app
  • A rotatable globe and advanced multi-hop feature are the main highlights
  • The VPN has also reported a glitch affecting connection

Mullvad has released version 2026.10 of its Android VPN app, introducing new features designed to boost speed and security while making the overall user experience more fun.

An interactive map showing VPN server locations and an advanced multi-hop feature, alongside a few bug fixes, are the key additions in this release, currently available on GitHub.

Interestingly, Google Play has yet to list the upgrade, with Mullvad still showing the previous version 2026.08 as its latest release on the official website, too.

The new redesign was quietly announced on the cloud platform over the past two days, following months of meticulous preparation that had already included the release of new features in beta in August, with the VPN testing them for almost a month before the launch.

Meanwhile, the Sweden-based VPN continues to ensure transparency, alerting users to an issue with the new version and reflecting the accountability expected by the best VPNs.

Mullvad: best VPN for anonymity
A major player in the industry and a great advocate for privacy, Mullvad is one of the only VPNs that still lets you pay with cash for true anonymity. Offering advanced security features, it effectively blocks ads and malicious domains, with great speeds too.View Deal

More interaction, please

The new version features a rotating globe that highlights server locations available to users, making the discovery process more immersive and playful. Users can now zoom in, pan, scroll, and explore the globe region by region to discover the exact locations of all VPN servers, as well as view their own connection routes.

Additionally, its multi-hop function, which routes traffic through two servers for additional privacy and to make it easier to route your traffic, can now be enabled automatically when relevant settings require it and off when it is unnecessary.

The multi-hop feature is a staple of Mullvad’s functionality — indeed, it first reached Android in 2025, following earlier arrivals on desktop and iOS, when Mullvad had labelled it “a tunnel within a tunnel.”

However, by selecting the new button, you won’t need to manually enable the function, as the Android VPN app will now activate it automatically when it’s called for.

This becomes particularly relevant when DAITA, a security technique that obscures network traffic patterns to prevent interception, is enabled and the selected servers do not support it directly, but you still desire a high level of security.

Specifically, the system will now recognise this preference and will automatically activate multihop mode, as DAITA requires it or benefits from it in order to function effectively. If you disable DAITA, the system will automatically revert to a faster, single-server connection to save you bandwidth, allowing the VPN to maintain its fast speeds reputation.

The VPN has also optimised the server location search function. Specifically, the results displayed in the ‘Select location’ field are now sorted by relevance, based on how closely they match users’ queries. Approximate search results have also been included to recognise imperfect matches and improve the overall user experience.

Finally, a few bugs have also been fixed, such as the sorting of the list of positions in English and previous revocation flags appearing during an API rejection.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance. Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

Fixing the bugs

Only two days ago, Mullvad released version 2026.09. However, the release contained an error that could cause the tunnel to get stuck in connecting and disconnecting when the QUIC obfuscator is used, causing the entire tunnel state machine to freeze and requiring the app to be restarted.

While the new version has indeed fixed the glitch in the previous version— and for this reason, the VPN explicitly advised to abandon version number 09 — it also warned that 2026.10 may cause the first connection attempt to fail when using features such as quantum-resistant tunnels or Daita.

A future release is expected soon to fix the connection issue, Mullvad said.

iPhone VPN users? CyberGhost has finally released a new update

  • CyberGhost has rebuilt the server list in its iOS app from the ground up
  • Browse, Streaming, and Favourites now live in their own tabs
  • The overhaul is CyberGhost's most meaningful iPhone update in a while

CyberGhost has pushed out a new update for its iOS app, and this time it's one iPhone users will actually notice. The update includes a completely rebuilt server list, the part of the app you touch every time you pick a location.

According to the release notes, Browse (All), Streaming, and Favourites now sit in their own tabs. You can search for any country or city instantly, and scrolling and animations have been smoothed out throughout.

CyberGhost is not on our list of the best VPN services currently, but it remains one of the fastest, most reliable picks for streaming, so any polish to the everyday experience is welcome.

The move also mirrors what we have seen elsewhere. Private Internet Access, another Kape-owned service, recently broke a long silence with a wave of app and network upgrades of its own.

CyberGhost — a VPN veterans
Part of the Kape conglomerate, CyberGhost is a popular VPN that's good for beginners. While a lack of innovation and a frustrating device-limit system hold it back from entering TechRadar's top picks, its impressive speeds and unblocking power make it a reliable pick for streamers and gamers. With subscription starting at the equivalent of $2.19 a month and a generous 45-day money-back guarantee, why not try it out?

What's new in CyberGhost's iOS update

The core change is structural. Instead of one long scrolling list, the server picker is now split into three tabs: Browse for all countries, Streaming for servers optimised for platforms like Netflix, and Favourites for the locations you have saved.

A new search bar sits alongside those tabs, so you can type a country or city and jump straight to it rather than thumbing through the whole roster. CyberGhost offers servers in 100 countries, so it's a much-needed shortcut.

This is a quality-of-life update, not a new feature drop, and it targets friction most users feel daily: finding the right server quickly.

Splitting streaming servers into their own tab is especially useful given CyberGhost's strong unblocking record, and instant search removes the guesswork when you need a specific city for local content.

It's worth noting the update does not touch privacy tooling, and CyberGhost's no-logs policy was last put under an independent Deloitte audit back in 2024.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

How to use the new features

After updating the iPhone app, tap the location area on the home screen to open the rebuilt server list.

Use the tabs along the top to switch between Browse, Streaming, and Favourites, or tap the search bar to find a country or city by name.

To save a location, tap the star next to it and it will appear under Favourites next time.

Proton VPN joins the race to secure Amazon's new Vega OS Fire TV Sticks

  • Proton VPN adds a native app for Amazon Fire TV Sticks running on Vega OS
  • Users can download the app directly from their smart TVs
  • Proton joins a few major VPNs in supporting Amazon's latest OS

Amazon's transition to its brand-new operating system has caused quite a stir in the streaming world, but the industry's top security providers are catching up. Proton VPN is now the latest provider to release a dedicated app for Amazon Fire TV Sticks running Vega OS.

If you've recently upgraded to one of Amazon's next-generation streaming devices, you might have noticed that older Android-based apps no longer work. By rolling out a native application tailored specifically for this new Linux-based ecosystem, Proton VPN ensures you won't have to sacrifice your privacy just to watch your favorite shows.

When looking for the best VPN for streaming, device compatibility is just as crucial as connection speed. Securing a smart TV or streaming stick shouldn't require complex manual router configurations, which is why native apps are so vital for the average consumer.

Proton VPN – best for privacy
Based in Switzerland, this privacy-first VPN offers good speeds, advanced anti-censorship features, and a server network that spans 145 countries around the world — including across Africa and Asia, where other providers tend to struggle. While its free VPN plan is handy, it comes with limitations. The good news is that upgrading to a premium subscription will cost you only the equivalent of $2.99 per month.View Deal

Unblocking your favorite streams on Vega OS

Amazon's shift from its traditional Android-based Fire OS to the streamlined Vega OS meant that app developers had to build entirely new software from the ground up. For VPN users, this initially caused a major headache, as older Fire Stick applications simply wouldn't install on the new hardware architecture.

With Proton VPN's new release, users can easily secure their internet connection, hide their IP address, and unblock geo-restricted streaming libraries directly from their television.

Whether you want to avoid bandwidth throttling from your internet service provider or keep your late-night binge-watching habits out of the hands of third-party trackers, a dedicated TV app makes the entire process seamless.

To get the new app running on your smart TV setup, Vega OS users can find detailed download instructions on Proton's dedicated support page.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

The growing Vega OS VPN ecosystem

Proton isn't the only provider that has scrambled to accommodate Amazon's sweeping software changes over the past year. In fact, the race to build the ultimate Vega OS application has been fiercely competitive among the industry's biggest players.

When VPN support first landed on the next-gen Amazon Fire TV Stick, consumer options were severely limited. However, the streaming privacy landscape has rapidly expanded. NordVPN was among the first to break ground with its Linux-based VPN app, setting a high standard for speed and usability on the platform.

Shortly after that initial wave, IPVanish joined NordVPN in the race to support the new hardware, bringing its simultaneous connections to the Vega OS ecosystem. Following suit, Surfshark launched its own native app, with ExpressVPN also joining this list more recently.

With Proton VPN now entering the fray, consumers have a highly robust lineup of premium privacy tools to choose from. If you value open-source transparency, Proton's arrival on Vega OS is a massive win for your smart home security.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Malicious streaming devices sold online that enroll the user's home Internet address in a residential proxy service. Image: Synthient. Pictured are 8 different TV boxes, including the X96 Mini Box, stick, and other no-name brands.

Malicious streaming devices sold online that enroll the user’s home Internet address in a residential proxy service. Image: HUMAN Security.

Popa is a massive botnet, but by all accounts it is unlike traditional botnets that enlist compromised systems in destructive activities, such as coordinating huge distributed denial-of-service attacks. Rather, Popa appears designed with a singular purpose: Implementing a persistent communications layer capable of registering a device, maintaining long-lived encrypted connections, and opening communication tunnels on demand.

Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes. These devices, which are marketed under thousands of brand names and model numbers and broadly available for purchase at top e-commerce destinations, all advertise the ability to stream hundreds of subscription video services for an up front one-time fee.

But as the FBI and security industry experts have warned repeatedly, these streaming boxes typically bundle or come pre-installed with software that turns the user’s TV into a “residential proxy” — allowing anyone to route their Internet traffic through that device for as long as it remains plugged into a wall socket and connected to a local network. More concerning, some of these proxy networks do little to stop malicious customers from communicating with and even compromising systems on the local network of the unsuspecting device owner.

The first clues about Popa’s origins came in a 2025 report from the Chinese security company XLAB, which flagged at least nine domain names that were used to register and direct the activities of compromised devices. In a report released today, the security firm Qurium described how it stumbled on some of those same domains while investigating a series of disruptive and expensive data scraping events targeting the company’s hosted organizations in May 2026, in which the scraping activity was scattered evenly across more than 1.4 million Internet addresses.

Qurium said it found several dozen domains used to control Popa that were all hosted in lockstep across multiple Internet addresses over time, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. Digging deeper, Qurium discovered gmslb[.]net was referenced in dozens of pirated or modded video content streaming apps, such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob and HD/OceanStreams.

Qurium’s report notes that most of the domains long used to control the Popa botnet were seized or dismantled in July 2025, after Google, HUMAN Security and Trend Micro teamed up to disrupt Badbox 2.0, a botnet that is closely associated with Vo1d. Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Ninjatech is a company founded by Moishi Kramer, whose LinkedIn profile says he is vice president of research and development at NetNut. That resume credits Kramer for helping NetNut to build from the “ground up,” “designing the architecture,” and “scaling the NetNut” before the company was acquired by Alarum Technologies. A self-created listing at the job board F6S references Kramer as the sole owner of the Ninjatech domain (a screen capture of it is pictured below).

Image: F6S.com.

Responding via email, Mr. Kramer said Ninjatech ceased operations approximately five years ago, when the company sold a software development kit (SDK) called Popa that was designed to use a small portion of a device’s bandwidth and to run only after the host application obtained user consent.

“That code was sold and licensed to third parties including resellers years ago,” Kramer said. “Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it.”

Kramer said neither he nor NetNut builds, operates or maintains the infrastructure being described as Popa, nor does he control the Ninjatech domain.

“I didn’t register the June 2025 domains you mention, and I don’t know who did,” he continued. “I have no control over, or visibility into, that infrastructure. I can only tell you it isn’t operated by me or by NetNut.”

But in a separate Popa research report released today, the proxy-tracking company Synthient said a recent analysis of the Popa SDK revealed outbound traffic clearly associated with NetNut.

“The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients,” Synthient wrote. “This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool.”

Synthient’s platform receiving outbound traffic from Popa. Image: Synthient.com.

Alarum Technologies, NetNut’s Tel Aviv-based parent company, said the reports by Synthient and Qurium contained “demonstrably inaccurate assertions and flawed deductions rather than verified facts.” Alarum shared a statement saying they reject the basic characterization of the SDKs and technologies discussed in the reports as a “botnet.”

“The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems or otherwise compromise the devices on which they operate,” the statement reads. “Netnut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services.”

Alarum said NetNut places “significant emphasis on appropriate notice and consent mechanisms, conducts customer due diligence, monitors for potential misuse, and takes steps intended to detect and mitigate suspicious or unauthorized activity.”

“This method of operation is supported both by internal procedures and policies, including performing KYC checks and additional due diligence of NetNut’s customers, as well as employing various technological measures, designed to assist in identifying and addressing suspected misuse of the network,” their statement continued.

However, in a report released on June 8, the proxy tracking service Spur asserted that NetNut does not require corporate verification or meaningful “know your customer” procedures before allowing customers to purchase proxy access.

“An individual can sign up, pay, and route traffic through partner address space, including space belonging to institutions whose users never opted in,” Spur wrote. “The ‘verified corporations only’ claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies.”

“Nor is NetNut the only front door,” Spur continued. “A number of downstream white labelers and resellers repackage the same ISP proxy pool under their own brands. These outlets typically perform no KYC at all, less scrutiny than NetNut itself, who at the very least might assign an account manager to potential users. Anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto.”

Synthient found that although the most recent builds of Popa (as of three months ago) have added the ability to ask the user for consent before installing proxy components, not all variants or previous versions of Popa contain this functionality.

“Of the over 20 genuine Popa publishers analyzed, none of them were observed asking for user consent,” Sythient wrote.

THE PREVALENCE OF POPA

Chris Formosa is senior lead information security engineer for Black Lotus Labs, a division of the Internet backbone carrier Lumen Technologies.

“What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing,” Formosa said, explaining that many other proxy services simply resell NetNut proxies rather than building out their own far-flung proxy networks. “So these Popa IPs appear in tons of different services all over the ecosystem, which makes it one of the most problematic and dangerous proxy botnets on the market currently.”

Formosa said the Popa botnet averages between 1.5 million to 2.5 million distinct IP addresses each day, relying on between 250 and 300 Internet addresses that are used to direct its activities.

“That’s why Popa is so dangerous,” Formosa said. “It may not be the largest botnet we have seen, but it is spread all over the industry, making its power very amplified.”

Formosa said while that makes Popa one of the larger botnets out there today, its numbers pale in comparison to those previously boasted by IPIDEA, a China-based proxy provider that until recently operated a daily pool of nearly 10 million devices that they resold as proxies to anyone. In January 2026, Synthient published research showing that multiple new large DDoS botnets had grown rapidly by tunneling through IPIDEA proxies into the local networks of unsuspecting TV box owners and infecting other Android-based devices behind the user’s firewall.

IPIDEA is based largely on SDKs used to view pirated streaming content on a vast number of TV box devices, but the service’s numbers have dwindled since January, when Google and industry partners took legal action to seize domain names that IPIDEA used to control devices and proxy traffic through them.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates. Meyer told KrebsOnSecurity that Nokia is monitoring 26 of at least 359 known relay nodes for the botnet, and estimates that each relay node handles between 35,000 and 60,000 clients simultaneously.

“On the relay node subset I am looking at (26 of them), 750,000 unique sources in 24 hours,” Meyer wrote in response to questions.

Nokia Deepfield released its own report today on RoboVPN, a VPN app tied to the Vo1d botnet’s Popa plugin that Qurium attributes to NetNut/Alarum Technologies.

THE SYMBIOSIS OF PROXIES AND DATA SCRAPING

Experts say many of the world’s largest proxy providers have updated their public-facing branding to highlight their utility for training AI platforms, implying it is a primary use case for their residential proxies. That’s because AI services tend to rely on constantly mass-scraping the Internet for new text, images and video content that can be used to train large language models (LLMs).

NetNut and other proxy services have recast themselves as critical infrastructure for the AI scraping economy. Image: Synthient.com.

“AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search,” reads a report this month from Include Security that examines the prevalence of proxy SDKs in smart TV apps. “But the modern web isn’t scrapeable from a datacenter. Cloudflare, DataDome, HUMAN, among others throttle or block requests from known cloud IPs. The workaround is residential proxies. A scraping job routed through a Comcast or T-Mobile subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer.”

This non-stop content scraping has spawned more than 70 copyright infringement lawsuits against major tech companies that have acknowledged large-scale data scraping as a major source of the “brains” behind their commercial AI offerings. Ironically, much of that scraping is being aided by proxy services that are intimately tied to unofficial Android TV boxes and associated SDKs whose stated purpose is streaming pirated content.

The scraping activity has become so aggressive that it often overwhelms the targeted websites, preventing them from being reachable by legitimate visitors. In many reported cases, nonprofit organizations, libraries and universities have complained of constantly battling to keep their services online in the face of relentless data-scraping firms hiding behind residential proxy services.

A survey conducted last year by the Confederation of Open Access Repositories (COAR) found while some content scraping bots are rather innocuous, “others are sufficiently aggressive that they are increasingly causing service disruptions in repositories and other scholarly communications infrastructures.” More than 90 percent of survey respondents indicated their repository is encountering aggressive bots, usually more than once a week, and often leading to slow downs and service outages.

“Automated web scraping is nothing new, and has been the key technology underlying search engines such as Google for over 30 years,” wrote Brendan O’Connell, platform manager at the Directory of Open Access Journals (DOAJ), a free, community-curated index of peer-reviewed academic journals. “However, the current investor-fueled AI startup craze means there are now thousands of well-funded companies developing and deploying their own scraping tools to train AI models, alongside existing major players like OpenAI and Google.”

DON’T TOUCH THAT DIAL!

Across the United States, local communities are pushing back against the proliferation of new data centers aimed primarily at improving the capabilities of AI. But security experts say the general public remains largely unaware that using one of these unsanctioned Android TV boxes means their “smart TV” is almost certainly using a significant amount of bandwidth each month to help train modern AI models.

Even households without these sketchy TV boxes can still have their smart TVs turned into residential proxy nodes, just by downloading one of thousands of apps made available on Samsung and LG smart TVs. Spur said it recently scraped the LG and Samsung app stores and found that each had approximately 3,000 apps available for download. Many of these apps are simple games or utilities that state in the fine print that the user’s Internet connection will be used to download data and that they can opt out at any time.

Spur said it found that more than 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found.

Image: Spur.us.

Experts say it’s questionable whether TV apps with proxy SDKs can obtain meaningful consent from users for installing an always-on proxy connection, particularly when anyone in a household — including children — can effectively opt the family TV into a residential proxy network just by installing a simple game or app.

“Privacy-policy disclosure is the wrong control surface for a TV,” Include Security wrote. “It is hard to scroll through a legal document navigated by arrow keys on a remote, and the in-app consent dialog doesn’t convey that a paying customer is about to route their scraping traffic through the user’s home internet.”

Spur’s head of research Sean Simmons told KrebsOnSecurity that most people do not have a working mental model for what it means to sell access to their residential IP address, no matter what device they are using.

“And on a TV, the gap is even wider,” Simmons said. “A one-time prompt navigated with a remote can disappear into the setup flow, while the app keeps monetizing the connection long after anyone remembers what they accepted.”

Simmons said LG and Samsung should follow the lead of other TV platforms that have already drawn a line against residential proxy providers, pointing to policies by Amazon that prohibit apps facilitating proxy services for third parties. Likewise the TV streaming device maker Roku reportedly now bars developers from using proxy SDKs and has removed apps that bundled them.

Piracy related apps pushing proxy SDKs onto unconsenting users. Image: Synthient.

Apps that turn one’s device into a residential proxy node are not limited to smart TVs and no-name streaming boxes, of course. As noted by the security firm Infoblox, mobile app developers can embed SDKs provided by the residential proxy networks into their products to monetize their software, allowing them to receive a small amount of money on each installation.

The result, Infoblox said, is that devices are frequently enrolled without the owner’s knowledge, typically through free applications such as VPNs, streaming apps, screensavers and “productivity” apps such as PDF viewers and break reminders.

All too often, these proxy services are beaconing out from employee devices brought into the workplace, Infoblox found. In a blog post earlier this month, Infoblox said it discovered that fully 65% of its customer base was querying one or more residential proxy related domains.

“We saw steady growth in these queries in 2025, with a 25% increase over the year to over 500 billion per month,” Infoblox wrote. “Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators. Perhaps even more concerning is that over 60% of government and banking customers have as well.”

Infoblox researchers Nick Sundvall and David Brunsdon warned that with residential proxies in the corporate environment, external access is granted to an organization’s IP space.

“If threat actors were to abuse the residential proxy to attack a third party, the third party’s incident response would, correctly, identify your residential proxy as the source,” they wrote. “Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation. The stunning prevalence of these services within customer environments warrants attention from both network defenders and policy makers who should consider how the risks posed by residential proxies could be impacting their security posture.”

Webcast: Pandemic Paradigm Shift: Remote Working is the New Normal

What does it mean to work from home across your corporate VPN? What exactly is VPN? Is your home office prepared? How can you improve and better secure your home […]

The post Webcast: Pandemic Paradigm Shift: Remote Working is the New Normal appeared first on Black Hills Information Security, Inc..

💾

❌