❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

The Wargame uses AI-generated footage to simulate Russian missile attacks on UK soil in shocking new Sky TV documentary series — 'this is not real, but it could be'

For years, major governments around the world have routinely conducted wargames and simulation exercises to test their military readiness, crisis response, and supply chain resilience. For the first time ever, we're about to see how one plays out.

Based on its hit 2025 podcast of the same name, Sky TV has developed four-part docuseries The Wargame, which explores how a fictitious UK cabinet — made up of former MPs from multiple parties — could responded to completely made-up threats and eventual attack from Russia.

Here's how it works. Our cabinet (listed below) will face an escalating simulated crisis, beginning with the suspicious murders of two RAF soldiers. While the Russian side, and any international players, are being given instructions by producers, every decision we see from the UK side is being made in the moment.

With four episodes dropping nightly on both Sky and NOW from September 21, I won't sugar coat it: The Wargame is an absolutely terrifying watch. If you've ever seen anything like Threads, When the Wind Blows or the BBC 1966 film The Wargame, it's the same sense of impending dread... just from the other side of the table.

But, don't get me wrong — this might just be the most important piece of television of the 21st century. As the UK's War Book is being redrafted in real time to advise the public on how best to be prepared, consider that Sky TV is granting us an important head start

We can no longer bury our heads in the sand over just how unprepared the UK is, and artificial intelligence (AI) is one of the main reasons we'll be able to realize this.

The Wargame is the most important TV show you'll stream in your lifetime — just be prepared

Before we drill deeper into what you'll soon see, here's our full list of players and their assigned roles:

  • ● Prime Minister: The Rt Hon. the Lord Gove PC
  • ● Deputy Prime Minister: The Rt Hon. Nicola Sturgeon PC
  • ● Defence Secretary: The Rt Hon. Dame Penny Mordaunt DBE PC
  • ● Home Secretary: The Rt Hon. the Baroness Harman KC PC
  • ● Foreign Secretary: The Rt Hon. Jim Murphy PC
  • ● Attorney General: The Rt Hon. the Baroness Warsi PC
  • ● Director of Communications: The Baroness Hazarika MBE
  • ● Chief of Defence Staff: General Sir Richard Barrons KCB CBE
  • ● National Security Adviser: The Rt Hon. the Lord Kim Darroch KCMG
  • ● Intelligence Chief: Christopher Steele
  • ● Nato Secretary General: The Rt Hon. the Lord Robertson KT GCMG PC
  • ● US Secretary of State: Anthony Scaramucci

As you can see in the above trailer, Sky has been incredibly upfront about its use of generative AI visual effects to create scenes showcasing Russian missiles hitting numerous UK targets. This is normally the part where I'd do my "AI is unnecessary in the creative arts, why couldn't they have just used CGI instead?" tirade, but actually, I'm glad that this decision was made.

Why? Not only is there a poetic irony of using AI to depict missile attacks mere weeks after the global public was told that there's a 10% that AI could kill us all within the next decade, but its use feeds into a wider point that The Wargame is trying to make. We've become so used to a certain type of 'peacetime life' and concerned ourselves with other issues (such as AI) that we've lost any kind of resilience we've ever had since World War II.

While the exact military capabilities of the UK are made up, seeing just how weak and unprepared we are if direct conflict was to strike our shores will hopefully be a wake-up call to anyone watching. As Sturgeon tells us, these choices are often like picking between "bad and worse," and it's nice to see our politicians slightly more humanized, even if the docuseries doesn't fill me confidence as to how international conflict could be handled.

With a fake COBR-style boardroom, military ops room, and press room all in use, it does feel as though this is the closest we'll ever get to an all-politician version of Big Brother. But, fake TikTok clips from real-life influencers capturing their reactions to the fictional breaking news brings the effects straight back home.

What do our players hope we take away from watching? "Governments have to, of course, hope for the best, but prepare for the worst. And that's not just about defence spending," Sturgeon said at the show's launch event. "There's a whole debate about preparedness of the population and some really basic things that we're just not at the races of, in terms of being prepared for even a fraction of this unfolding.

"So, getting rid of the optimism bias that this won't happen, to starting to think seriously about the prospect of this possibly happening." Deep breaths, people.

Paramount Skydance 'Emerges Victorious', Finally Wins Settlement for Warner Bros Takeover

21 September 2026 at 19:34
Paramount Skydance just "emerged victorious" reports Reuters, "from a legal battle over its $110 billion acquisition of Warner Bros Discovery" that will "dramatically concentrate power across Hollywood's film, TV, streaming and news businesses." The victory comes "after settling with a California-led group of US states and a Hollywood writers union, paving the way for one of the largest media mergers in history." Paramount agreed to abide by temporary film quotas and a news oversight committee, avoiding a forced sale of cable assets such as CNN or any of its lucrative film franchises... The Writers Guild of America settled its parallel case against Paramount, while saying it still believes the deal will damage the industry. The states' settlement forced the union to "contend with the reality of forging ahead alone, with no backing from government enforcers" in a complex case that would have cost millions of dollars... Paramount promised in the state settlement to bring more film production to the US — spending at least $300 million more each year in domestic production — and adhere to US theatrical release quotas for five years. The company will produce 30 movies in each of the first two years of the deal, and 32 movies in each of the following three years, Bonta said. Each year, at least four of those films must be independent films and at least 20% must be blockbusters. If it falls below that threshold, it will pay $30 million per film, most of it into funds to support workers. Paramount also promised not to raise rates on theater operators for three years. The article notes that California attorney general Rob Bonta still said "I don't think these two companies should merge" at a press conference announcing the settlement, "but that's not something that we are focused on with our resolution here." He call their agreement "a strong antitrust outcome." And Politico notes that Bonta acknowledged at the press conference that "Some of you who may be watching this may have wanted a different outcome. I understand that." But he argued he'd reached a settlement capable of "providing more film production that protects Hollywood workers and their livelihoods, that places guardrails allowing for robust cable negotiations, that protects competition and creates more choice for consumers about what this merger could mean for the industry." It "resolves the antitrust concerns at the heart of our lawsuit against the company and Warner Brothers," he said... The agreement came as a disappointment to opponents of the transaction, including the Block the Merger Coalition, which cast the settlement as a sweetheart deal for Paramount Chief Executive David Ellison and his father, Oracle Co-Founder Larry Ellison, who is financially backstopping the acquisition. "This is a bad deal for the future of film, entertainment, independent journalism, and a strong democracy in this country," the coalition said in a statement. "We are disappointed and angry that the interests of average Americans have been trampled to benefit oligarch billionaires....." The $111 billion deal allows Paramount to combine its namesake streaming service with HBO Max, creating a new offering with about 200 million subscribers. That would help Paramount compete against companies such as Netflix, which boasts more than 325 million subscribers worldwide.

Read more of this story at Slashdot.

What is the release date for Ted Lasso season 4 episode 8 on Apple TV?

How is Ted Lasso season 4 going to end? Outside of those who worked on it, nobody knows — but I can tell you when its eighth episode will be released on Apple TV.

Indeed, as one of TechRadar's resident entertainment experts, I'm your best source for all manner of release date and launch time information. So, if you're desperate to know more about when this week's chapter — titled 'Follow the Anger' — will premiere, I've got you covered.

What is the launch time for Ted Lasso season 4 episode 8?

Gemma looking unamused in Ted Lasso season 4 episode 8

Cheer up, Gemma, a new episode of Ted Lasso drops soon! (Image credit: Apple TV)

Ted Lasso season 4's next entry is expected to drop in the US and Canada at 6pm PT / 9pm ET on Tuesday, September 22.

Apple has always made a habit of telling us that episodes of its new and returning TV Originals will come out every Wednesday at 12am PT in North America. Nonetheless, every single one of this season's episodes has arrived on Tuesday evenings at the times I mentioned above. It's all but confirmed, then, that season 4 episode 8 will do the same.

As for the rest of the world, Ted Lasso's next installment will be released on Wednesday, September 23. Read on to see what time it'll launch where you live:

  • US — Tuesday, September 22 at 6pm PT / 9pm ET
  • Canada — Tuesday, September 22 at 6pm PT / 9pm ET
  • UK — Wednesday, September 23 at 2am BST
  • India — Wednesday, September 23 at 6:30am IST
  • Singapore — Wednesday, September 23 at 9am SGT
  • Australia — Wednesday, September 23 at 11am AEST
  • New Zealand — Wednesday, September 23 at 1pm NZST

Ted Lasso season 4 full release schedule: when do new episodes come out?

Higgins, Rebecca, Keeley, and Ted looking at someone off-camera in Ted Lasso season 4 episode 8

You heard right, everyone — only two more episodes remain of this season (Image credit: Apple TV)

Unless there's an unexpected alteration to this season's current release schedule, new episodes will make landfall every Tuesday in North and South America, and on Wednesdays on other continents. Read on to see when the final two installments will air near you:

  • Ted Lasso season 4 episode 1 — out now
  • Ted Lasso season 4 episode 2 — out now
  • Ted Lasso season 4 episode 3 — out now
  • Ted Lasso season 4 episode 4 — out now
  • Ted Lasso season 4 episode 5 — out now
  • Ted Lasso season 4 episode 6 — out now
  • Ted Lasso season 4 episode 7 — out now
  • Ted Lasso season 4 episode 8 — September 22/23
  • Ted Lasso season 4 episode 9 — September 29/30
  • Ted Lasso season 4 episode 10 — October 6/7

Roku's 24/7 AI Slop Channel Is Even Worse Than Expected

7 September 2026 at 00:30
A new streaming TV channel shows films made with genAI, reports Engadget. "Fairground AI Creator TV" is free — and supported with ads — describing its material as "AI Cinema": "AI-generated" can make it sound as though someone typed a sentence into a machine and came back five minutes later to find a finished movie. Fairground's catalog shows why that description can be too simple. Take Lost Garden: The Awakening of the Lantern Knight. According to its Fairground page, creator Frank Houbre wrote the world, characters, mythology, emotional arc and screenplay himself. AI tools were used mainly for animation and visual production, with other tools helping create voices and music before the episode was assembled in conventional video-editing software. There's still one question, the article notes: "whether viewers actually want an AI-focused TV channel." More than 100 AI creators have contributed to the 24-hour slate of programming, although Variety points out several of them were discovered on social media. The channel was recently profiled in an article by the Guardian. Its headline? "'Nightmare fodder': Roku's AI slop channel is even worse than expected." (And its subheading calls it "a 24/7 channel devoted to low-quality AI content for viewers sick of watching real people move...") What about people who hate plot and vision and the sight of people speaking convincing dialogue that synchronises perfectly with the movement of their lips? What about the people who just want to watch an unyielding torrent of eerily weightless nightmare fodder? Well, good news. Roku has finally caught up... Early reactions were, to put it mildly, not great. The Verge compared it to eating from a trough, while Futurism called it "bottom-of-the-barrel slop"... On the plus side, the channel is evidence that artificial intelligence has come on in leaps and bounds over the last couple of years... However, it is still awful. Categorically, catastrophically awful. The channel doesn't so much offer shows as a drifting dreamscape of bad ideas rendered as horribly as possible with no thought paid to scheduling. At one point on Wednesday, a shrill high-frequency anime gave way to a long and staid German-language short about Nazi bureaucracy. After that came a sort of Gladiator ripoff that had all the dynamism of an exhibit you'd see at the fourth-best museum on a poorly planned family holiday.

Read more of this story at Slashdot.

TiVo Will Start Charging Fees For Its Automatic Commercial Break-Skipping Feature 'SkipMode'

6 September 2026 at 16:34
TiVo is notifying customers about changes to "one of its longest-standing and most popular DVR features," reports the blog Cord Cutter News: Starting November 2, 2026, the current version of SkipMode that allows users to jump over commercial breaks with a single button press on the remote will no longer be available. The company is instead preparing to test a new paid add-on called Premium Auto Commercial Skip. SkipMode has been a core part of the TiVo experience for years. After a supported show finished recording, the service added markers that let viewers leap from the end of one program segment directly to the start of the next, bypassing the ads in between. On newer TiVo Experience 4 devices, users could even set the feature to automatic so commercials were skipped without any remote interaction. The feature was limited to popular prime-time programming on major networks, typically appearing a short time after a show aired. Under the new plan, that one-button and automatic functionality will disappear from the standard service. Viewers will still be able to skip commercials the traditional way by using the 30-second skip button or the fast-forward control on their remotes. Those manual methods have existed on TiVo boxes for more than two decades and do not rely on the company's commercial-detection data. In November, TiVo will offer a 30-day free trial of the new Premium Auto Commercial Skip service. After the trial ends, customers who want to keep the automatic or one-button skip capability will need to add it to their accounts for an extra monthly fee. The company has not yet published the price. Thanks to long-time Slashdot reader AmiMoJo for sharing the article.

Read more of this story at Slashdot.

Samsung Bans Smart TV Apps That Share Users' Internet Connections

By: BeauHD
3 August 2026 at 14:00
An anonymous reader quotes a report from TechCrunch: Several popular Samsung smart TV apps contain code that share the owner's internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday. Some of these apps claim to have been installed on hundreds of millions of smart TVs in people's homes, per the app developers. At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its "Editor's Choice" section on customers' TV screens. These apps contain software that funnels outsiders' web traffic through ordinary home and office internet connections, known as residential proxy networks (or "resproxies"), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node -- even when the app is no longer open. The security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung's app store, containing code that puts users at risk of having their internet connections tapped by a rogue app. Many of these apps are bare-bone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself. "What was reviewed is not necessarily what is running," wrote Harrison Sand, an offensive security consultant at Mnemonic. After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users' internet connections, and will remove apps that contain the functionality. "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform," said a Samsung spokesperson. "We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components." LG also recently announced plans to suspend apps containing ResProxy software after a security firm found that roughly 42% of apps in its TV app store allowed unknown third parties to route internet traffic through users' televisions without their knowledge.

Read more of this story at Slashdot.

Peacock to Be Included With YouTube Premium In Major Streaming Tie-Up

By: BeauHD
27 July 2026 at 19:00
YouTube Premium will include Peacock Premium at no extra charge beginning in early 2027. "The deal brings a slew of premium content to the [$15.99 per month] YouTube Premium subscription, including live sports like the NFL, NBA and MLB and entertainment like Law & Order, Saturday Night Live and Love Island," reports The Hollywood Reporter. "It also has the potential to dramatically scale Peacock, which remains smaller than many of its streaming competitors." From the report: Peacock has 48 million subscribers, while YouTube Premium and YouTube Music have a combined 125 million subscribers, though they don't break out how many each of those offerings have. The agreement, which expands on the deal the company inked with YouTube parent company Google last year, will also extend the entertainment company's programming deal with YouTube TV, while bringing some of YouTube's offerings to Comcast Xfinity and Xumo platforms. There's also a notable sports and production element to the deal, with NBC Sports agreeing to stream some live sporting events on its YouTube channels, and with NBC agreeing to serve as the production partner for select live events on YouTube. YouTube will also bundle some of the company's International streaming offerings like Universal+ and Hayu in select markets.

Read more of this story at Slashdot.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

18 June 2026 at 13:37

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Malicious streaming devices sold online that enroll the user's home Internet address in a residential proxy service. Image: Synthient. Pictured are 8 different TV boxes, including the X96 Mini Box, stick, and other no-name brands.

Malicious streaming devices sold online that enroll the user’s home Internet address in a residential proxy service. Image: HUMAN Security.

Popa is a massive botnet, but by all accounts it is unlike traditional botnets that enlist compromised systems in destructive activities, such as coordinating huge distributed denial-of-service attacks. Rather, Popa appears designed with a singular purpose: Implementing a persistent communications layer capable of registering a device, maintaining long-lived encrypted connections, and opening communication tunnels on demand.

Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes. These devices, which are marketed under thousands of brand names and model numbers and broadly available for purchase at top e-commerce destinations, all advertise the ability to stream hundreds of subscription video services for an up front one-time fee.

But as the FBI and security industry experts have warned repeatedly, these streaming boxes typically bundle or come pre-installed with software that turns the user’s TV into a “residential proxy” — allowing anyone to route their Internet traffic through that device for as long as it remains plugged into a wall socket and connected to a local network. More concerning, some of these proxy networks do little to stop malicious customers from communicating with and even compromising systems on the local network of the unsuspecting device owner.

The first clues about Popa’s origins came in a 2025 report from the Chinese security company XLAB, which flagged at least nine domain names that were used to register and direct the activities of compromised devices. In a report released today, the security firm Qurium described how it stumbled on some of those same domains while investigating a series of disruptive and expensive data scraping events targeting the company’s hosted organizations in May 2026, in which the scraping activity was scattered evenly across more than 1.4 million Internet addresses.

Qurium said it found several dozen domains used to control Popa that were all hosted in lockstep across multiple Internet addresses over time, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. Digging deeper, Qurium discovered gmslb[.]net was referenced in dozens of pirated or modded video content streaming apps, such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob and HD/OceanStreams.

Qurium’s report notes that most of the domains long used to control the Popa botnet were seized or dismantled in July 2025, after Google, HUMAN Security and Trend Micro teamed up to disrupt Badbox 2.0, a botnet that is closely associated with Vo1d. Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Ninjatech is a company founded by Moishi Kramer, whose LinkedIn profile says he is vice president of research and development at NetNut. That resume credits Kramer for helping NetNut to build from the “ground up,” “designing the architecture,” and “scaling the NetNut” before the company was acquired by Alarum Technologies. A self-created listing at the job board F6S references Kramer as the sole owner of the Ninjatech domain (a screen capture of it is pictured below).

Image: F6S.com.

Responding via email, Mr. Kramer said Ninjatech ceased operations approximately five years ago, when the company sold a software development kit (SDK) called Popa that was designed to use a small portion of a device’s bandwidth and to run only after the host application obtained user consent.

“That code was sold and licensed to third parties including resellers years ago,” Kramer said. “Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it.”

Kramer said neither he nor NetNut builds, operates or maintains the infrastructure being described as Popa, nor does he control the Ninjatech domain.

“I didn’t register the June 2025 domains you mention, and I don’t know who did,” he continued. “I have no control over, or visibility into, that infrastructure. I can only tell you it isn’t operated by me or by NetNut.”

But in a separate Popa research report released today, the proxy-tracking company Synthient said a recent analysis of the Popa SDK revealed outbound traffic clearly associated with NetNut.

“The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients,” Synthient wrote. “This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool.”

Synthient’s platform receiving outbound traffic from Popa. Image: Synthient.com.

Alarum Technologies, NetNut’s Tel Aviv-based parent company, said the reports by Synthient and Qurium contained “demonstrably inaccurate assertions and flawed deductions rather than verified facts.” Alarum shared a statement saying they reject the basic characterization of the SDKs and technologies discussed in the reports as a “botnet.”

“The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems or otherwise compromise the devices on which they operate,” the statement reads. “Netnut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services.”

Alarum said NetNut places “significant emphasis on appropriate notice and consent mechanisms, conducts customer due diligence, monitors for potential misuse, and takes steps intended to detect and mitigate suspicious or unauthorized activity.”

“This method of operation is supported both by internal procedures and policies, including performing KYC checks and additional due diligence of NetNut’s customers, as well as employing various technological measures, designed to assist in identifying and addressing suspected misuse of the network,” their statement continued.

However, in a report released on June 8, the proxy tracking service Spur asserted that NetNut does not require corporate verification or meaningful “know your customer” procedures before allowing customers to purchase proxy access.

“An individual can sign up, pay, and route traffic through partner address space, including space belonging to institutions whose users never opted in,” Spur wrote. “The ‘verified corporations only’ claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies.”

“Nor is NetNut the only front door,” Spur continued. “A number of downstream white labelers and resellers repackage the same ISP proxy pool under their own brands. These outlets typically perform no KYC at all, less scrutiny than NetNut itself, who at the very least might assign an account manager to potential users. Anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto.”

Synthient found that although the most recent builds of Popa (as of three months ago) have added the ability to ask the user for consent before installing proxy components, not all variants or previous versions of Popa contain this functionality.

“Of the over 20 genuine Popa publishers analyzed, none of them were observed asking for user consent,” Sythient wrote.

THE PREVALENCE OF POPA

Chris Formosa is senior lead information security engineer for Black Lotus Labs, a division of the Internet backbone carrier Lumen Technologies.

“What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing,” Formosa said, explaining that many other proxy services simply resell NetNut proxies rather than building out their own far-flung proxy networks. “So these Popa IPs appear in tons of different services all over the ecosystem, which makes it one of the most problematic and dangerous proxy botnets on the market currently.”

Formosa said the Popa botnet averages between 1.5 million to 2.5 million distinct IP addresses each day, relying on between 250 and 300 Internet addresses that are used to direct its activities.

“That’s why Popa is so dangerous,” Formosa said. “It may not be the largest botnet we have seen, but it is spread all over the industry, making its power very amplified.”

Formosa said while that makes Popa one of the larger botnets out there today, its numbers pale in comparison to those previously boasted by IPIDEA, a China-based proxy provider that until recently operated a daily pool of nearly 10 million devices that they resold as proxies to anyone. In January 2026, Synthient published research showing that multiple new large DDoS botnets had grown rapidly by tunneling through IPIDEA proxies into the local networks of unsuspecting TV box owners and infecting other Android-based devices behind the user’s firewall.

IPIDEA is based largely on SDKs used to view pirated streaming content on a vast number of TV box devices, but the service’s numbers have dwindled since January, when Google and industry partners took legal action to seize domain names that IPIDEA used to control devices and proxy traffic through them.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates. Meyer told KrebsOnSecurity that Nokia is monitoring 26 of at least 359 known relay nodes for the botnet, and estimates that each relay node handles between 35,000 and 60,000 clients simultaneously.

“On the relay node subset I am looking at (26 of them), 750,000 unique sources in 24 hours,” Meyer wrote in response to questions.

Nokia Deepfield released its own report today on RoboVPN, a VPN app tied to the Vo1d botnet’s Popa plugin that Qurium attributes to NetNut/Alarum Technologies.

THE SYMBIOSIS OF PROXIES AND DATA SCRAPING

Experts say many of the world’s largest proxy providers have updated their public-facing branding to highlight their utility for training AI platforms, implying it is a primary use case for their residential proxies. That’s because AI services tend to rely on constantly mass-scraping the Internet for new text, images and video content that can be used to train large language models (LLMs).

NetNut and other proxy services have recast themselves as critical infrastructure for the AI scraping economy. Image: Synthient.com.

“AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search,” reads a report this month from Include Security that examines the prevalence of proxy SDKs in smart TV apps. “But the modern web isn’t scrapeable from a datacenter. Cloudflare, DataDome, HUMAN, among others throttle or block requests from known cloud IPs. The workaround is residential proxies. A scraping job routed through a Comcast or T-Mobile subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer.”

This non-stop content scraping has spawned more than 70 copyright infringement lawsuits against major tech companies that have acknowledged large-scale data scraping as a major source of the “brains” behind their commercial AI offerings. Ironically, much of that scraping is being aided by proxy services that are intimately tied to unofficial Android TV boxes and associated SDKs whose stated purpose is streaming pirated content.

The scraping activity has become so aggressive that it often overwhelms the targeted websites, preventing them from being reachable by legitimate visitors. In many reported cases, nonprofit organizations, libraries and universities have complained of constantly battling to keep their services online in the face of relentless data-scraping firms hiding behind residential proxy services.

A survey conducted last year by the Confederation of Open Access Repositories (COAR) found while some content scraping bots are rather innocuous, “others are sufficiently aggressive that they are increasingly causing service disruptions in repositories and other scholarly communications infrastructures.” More than 90 percent of survey respondents indicated their repository is encountering aggressive bots, usually more than once a week, and often leading to slow downs and service outages.

“Automated web scraping is nothing new, and has been the key technology underlying search engines such as Google for over 30 years,” wrote Brendan O’Connell, platform manager at the Directory of Open Access Journals (DOAJ), a free, community-curated index of peer-reviewed academic journals. “However, the current investor-fueled AI startup craze means there are now thousands of well-funded companies developing and deploying their own scraping tools to train AI models, alongside existing major players like OpenAI and Google.”

DON’T TOUCH THAT DIAL!

Across the United States, local communities are pushing back against the proliferation of new data centers aimed primarily at improving the capabilities of AI. But security experts say the general public remains largely unaware that using one of these unsanctioned Android TV boxes means their “smart TV” is almost certainly using a significant amount of bandwidth each month to help train modern AI models.

Even households without these sketchy TV boxes can still have their smart TVs turned into residential proxy nodes, just by downloading one of thousands of apps made available on Samsung and LG smart TVs. Spur said it recently scraped the LG and Samsung app stores and found that each had approximately 3,000 apps available for download. Many of these apps are simple games or utilities that state in the fine print that the user’s Internet connection will be used to download data and that they can opt out at any time.

Spur said it found that more than 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found.

Image: Spur.us.

Experts say it’s questionable whether TV apps with proxy SDKs can obtain meaningful consent from users for installing an always-on proxy connection, particularly when anyone in a household — including children — can effectively opt the family TV into a residential proxy network just by installing a simple game or app.

“Privacy-policy disclosure is the wrong control surface for a TV,” Include Security wrote. “It is hard to scroll through a legal document navigated by arrow keys on a remote, and the in-app consent dialog doesn’t convey that a paying customer is about to route their scraping traffic through the user’s home internet.”

Spur’s head of research Sean Simmons told KrebsOnSecurity that most people do not have a working mental model for what it means to sell access to their residential IP address, no matter what device they are using.

“And on a TV, the gap is even wider,” Simmons said. “A one-time prompt navigated with a remote can disappear into the setup flow, while the app keeps monetizing the connection long after anyone remembers what they accepted.”

Simmons said LG and Samsung should follow the lead of other TV platforms that have already drawn a line against residential proxy providers, pointing to policies by Amazon that prohibit apps facilitating proxy services for third parties. Likewise the TV streaming device maker Roku reportedly now bars developers from using proxy SDKs and has removed apps that bundled them.

Piracy related apps pushing proxy SDKs onto unconsenting users. Image: Synthient.

Apps that turn one’s device into a residential proxy node are not limited to smart TVs and no-name streaming boxes, of course. As noted by the security firm Infoblox, mobile app developers can embed SDKs provided by the residential proxy networks into their products to monetize their software, allowing them to receive a small amount of money on each installation.

The result, Infoblox said, is that devices are frequently enrolled without the owner’s knowledge, typically through free applications such as VPNs, streaming apps, screensavers and “productivity” apps such as PDF viewers and break reminders.

All too often, these proxy services are beaconing out from employee devices brought into the workplace, Infoblox found. In a blog post earlier this month, Infoblox said it discovered that fully 65% of its customer base was querying one or more residential proxy related domains.

“We saw steady growth in these queries in 2025, with a 25% increase over the year to over 500 billion per month,” Infoblox wrote. “Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators. Perhaps even more concerning is that over 60% of government and banking customers have as well.”

Infoblox researchers Nick Sundvall and David Brunsdon warned that with residential proxies in the corporate environment, external access is granted to an organization’s IP space.

“If threat actors were to abuse the residential proxy to attack a third party, the third party’s incident response would, correctly, identify your residential proxy as the source,” they wrote. “Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation. The stunning prevalence of these services within customer environments warrants attention from both network defenders and policy makers who should consider how the risks posed by residential proxies could be impacting their security posture.”

AppleTV & nmap -sV

By: BHIS
11 October 2016 at 10:21

BBKing // So I’m working the other day, and my wife asks me why the TV is on. I don’t know. I didn’t turn it on. But it’s near my […]

The post AppleTV & nmap -sV appeared first on Black Hills Information Security, Inc..

❌
❌