Modalità di lettura

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.

The NetNut homepage today was replaced by this seizure banner from the FBI.

On June 19, three different security firms issued similar findings: That NetNut is a residential proxy network which populates a botnet called Popa, and distributes software for devices commonly found in homes, such as smart TVs and streaming boxes. NetNut’s software turns those systems into always-on residential proxy nodes that are rented to others, who predominantly use them to relay abusive and intrusive Internet traffic, such as mass content scraping, advertising fraud, and account takeover activity.

Earlier today, NetNut’s homepage was replaced with a seizure notice from the FBI and the Internal Revenue Service Criminal Investigation division. The seizure notice thanked Google, Lumen, Shadowserver and other industry partners for their help in dismantling hundreds of domains tied to the Popa botnet, which experts say has long been synonymous with NetNut’s residential proxy infrastructure.

In a blog post published today, the Google Threat Intelligence Group (GTIG) said NetNut’s proxy network is widely resold and white-labeled by a number of third-party proxy providers, and that its services are heavily sought out by cybercriminals seeking to obfuscate the source of their malicious traffic. The GTIG said that in a single week during June 2026, they observed 316 distinct clusters of threat actors using suspected NetNut exit nodes, including cybercriminal and espionage groups.

“These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks,” Google’s GTIG wrote. “Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats.”

Google said it disabled Google accounts and services used by NetNut for malware command and control, and that it shared technical intelligence on NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement and research firms. The company also disabled apps known to bundle NetNut’s various SDKs.

Omer Weiss, legal counsel for NetNut parent Alarum Technologies, said the company was aware of the FBI seizure and cooperating with investigators.

“Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account,” Weiss said in a written statement.

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies. Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

Brundage said NetNut’s apparent demise is likely to be a great disadvantage for the cybercrime community, which was already reeling from legal actions by Google earlier this year that seized infrastructure for NetNut’s biggest competitor — IPIDEA.

“I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown,” he said. “Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it.”

NetNut’s infrastructure, in a nutshell. Image: Black Lotus Labs, Lumen.

The NetNut and Popa botnet takedown may have another added benefit, Brundage said: Lessening the impact of large distributed denial-of-service botnets that have been built on the backs of poorly configured residential proxy services. In January, Synthient revealed how cybercriminals had built the world’s largest DDoS botnet (Kimwolf) by tunneling through IPIDEA proxy connections into the local networks of TV box owners, and infecting other Android-based devices behind the victim’s firewall.

While many of the bigger proxy providers took steps to block this activity, resellers of the major proxy networks have been far slower to respond to the threat, Brundage said.

“In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there,” he said.

For its part, Google reckons today’s actions have caused “significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions.” But the company warns that proxy networks can rebuild themselves by effectively reselling other proxy services, as IPIDEA has done over the past few months.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes. “While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers.”

As KrebsOnSecurity has warned repeatedly, most of the no-name TV streaming boxes for sale on the major e-commerce websites either come pre-installed with residential proxy software, or require the installation of proxy SDKs in order to use the device for its stated purpose (streaming pirated movies, sporting events and TV shows). Google’s advice here is sound: When it comes to TV boxes, stick to name brands from reputable manufacturers, and then be sparing and judicious with any apps you choose to install.

The sketchy TV boxes that are being commandeered by the Popa botnet and other threats all come with or require the user to install unofficial Android operating systems that do not operate within the confines of Google’s Official Play Protect store. Google says consumers can confirm whether or not a device is built with the official Android TV OS and Play Protect certification by following these instructions.

Even people without TV streaming boxes can find their smart TVs enrolled in residential proxy networks, just by installing one of thousands of apps available for download on Samsung and LG smart TVs. In a report released last month, the proxy tracking company Spur found 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found.

Image: Spur.us.

Update, 4:24 p.m. ET: Included a statement shared post-publication from an attorney representing NetNut parent Alarum Technologies.

Update, July 8, 2:34 p.m. ET: The website for Alarum Technologies — alarum[.]io — now also features a seizure notice from the FBI. The company’s stock has taken a beating since the FBI action, and is currently trading at $2.62 a share, a roughly 67 percent decline over the past week.

  •  

BAD DRIVERS OF ITALY dashcam compilation 7.2 - INC---TO

💾

Trova la tua prossima DASHCAM https://sicurisullastrada.it/dashcam/
Dubbi o domande? Trovi qui le RISPOSTE https://sicurisullastrada.it/dashcam-5-minuti-per-sapere-tutto/
Vuoi inviarci le clip della TUA DASHCAM? Guarda come fare su https://bit.ly/inviavideo
Seguici sui canali BDOI per essere AGGIORNATO e vedere le MIGLIORI CLIP https://bit.ly/canalibdoi
Hai domande o curiosità? COMMENTA sotto al video oppure CONTATTACI https://bit.ly/contattabdoi
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
This video shows DANGEROUS behaviors not to imitate! Always drive carefully!
Do you want to send us the clips of YOUR DASHCAM? See how on https://bit.ly/inviavideo
Follow us on BDOI channels to be UPDATED and see the BEST CLIPS https://bit.ly/canalibdoi
Do you have any questions or curiosities? COMMENT below the video or CONTACT US https://bit.ly/contattabdoi

#baddriversofitaly #dashcam #compilation
  •  

Good Morning, Earth!

A bright orange sunburst illuminates Earth's atmosphere during an orbital sunrise in this photograph from the International Space Station as it orbited 264 miles above the Caucasus Mountains.

  •  

Piaggio : la chiamano responsabilità. Noi la chiamiamo resa.

Dal 1° luglio Piaggio aprirà l'ennesima procedura di solidarietà. Ancora una volta saranno gli operai a pagare il prezzo delle scelte aziendali, con meno salario e meno prospettive. Ma la situazione è ancora più grave.
Da domani iniziano le fermate delle linee in diversi reparti. Alcune produzioni termineranno già a metà luglio. Il lavoro manca. E non manca per una fatalità o per una crisi improvvisa. Manca perché da anni è assente una vera strategia industriale. Gli investimenti vengono rinviati, i nuovi progetti non arrivano e lo stabilimento viene lasciato vivere alla giornata, senza una prospettiva di rilancio.
Solo poche settimane fa si celebravano gli ottant'anni della Vespa. Discorsi, fotografie, autorità e applausi raccontavano l'eccellenza italiana e un marchio simbolo nel mondo. Finita la propaganda, però, resta la realtà: fermate produttive, solidarietà, salari che diminuiscono e un futuro sempre più incerto. È questa la distanza tra la narrazione e ciò che gli operai vivono ogni giorno.

Piaggio continua a utilizzare gli ammortizzatori sociali come uno strumento ordinario di gestione, trasferendo sui lavoratori e sulla collettività il costo delle proprie scelte. È inaccettabile che si continui a ricorrere alla solidarietà senza assumersi la responsabilità di rilanciare davvero il sito di Pontedera.
Per USB la solidarietà non può tradursi in un taglio dello stipendio. Se l'azienda sceglie questa strada, deve garantire l'integrazione salariale. Gli operai non possono diventare il bancomat a cui attingere ogni volta che vengono meno programmazione, investimenti e visione industriale.
Anche questa volta tutto viene deciso all'ultimo momento. I lavoratori vengono convocati quando le decisioni sono già state prese, senza un confronto reale e senza una trattativa vera. Si chiede soltanto di ratificare un accordo già scritto.

Negli anni questo metodo è stato presentato come responsabilità. In realtà ha finito per trasformare la responsabilità in semplice accettazione delle decisioni aziendali. Ogni sacrificio viene descritto come inevitabile, ogni arretramento come necessario, ogni accordo come il migliore possibile.
Ma il compito di un delegato sindacale non è accompagnare i lavoratori ad accettare nuovi sacrifici. È rappresentarli, difenderne il salario, contrastare le scelte sbagliate e pretendere investimenti e prospettive. Quando invece si firma tutto, si giustifica tutto e si invita sempre e soltanto ad avere pazienza, si smette di rappresentare gli operai e si finisce per assecondare un modello che punta a una fabbrica senza conflitto e a lavoratori sempre più ricattabili.


Gli accordi al ribasso non hanno salvato il futuro dello stabilimento. Lo hanno progressivamente indebolito. Ogni firma che ha ridotto diritti e tutele è stata giustificata in nome del domani.
Quel domani oggi è sotto gli occhi di tutti: esuberi, fermate produttive, solidarietà e assenza di una prospettiva industriale.
Anche la politica porta una responsabilità enorme. Quando c'è da inaugurare una mostra sulla Vespa o partecipare a una celebrazione, le istituzioni sono sempre presenti. Quando invece occorre pretendere investimenti, difendere l'occupazione e chiedere conto delle scelte industriali della proprietà, prevalgono il silenzio e l'inerzia. Da anni Comune, Regione e Governo assistono senza intervenire al progressivo indebolimento dello stabilimento. Si evita di mettere in discussione la proprietà e di aprire un confronto serio sul futuro industriale di Pontedera. Eppure è compito delle istituzioni pretendere un piano industriale credibile, vincolare gli incentivi pubblici agli investimenti e garantire un confronto permanente sul futuro produttivo del territorio. Il lavoro si difende con gli atti, non con le fotografie.
Per questo non possiamo accettare che gli ammortizzatori sociali diventino una componente strutturale del modello Piaggio, né che siano sempre gli operai a pagare il prezzo delle scelte aziendali. Allo stesso modo, il sindacato non può ridursi a certificare decisioni già prese. Serve rompere un equilibrio costruito sul silenzio, sulla rassegnazione e sulla continua ricerca della pace sociale.

La storia del movimento operaio insegna una cosa semplice: nessun diritto è stato regalato. Tutto è stato conquistato attraverso il conflitto. Chi rinuncia al conflitto finisce inevitabilmente per accettare l'arretramento dei diritti e le decisioni dell'azienda. Ed è proprio questa scelta a rendere sempre più evidente da quale parte si decide di stare. Chi oggi invita ad abbassare la testa non sta difendendo il lavoro. Sta soltanto rendendo più semplice il compito di chi vuole continuare a ridurre salari, diritti e occupazione.
Per questo il primo passo è ricostruire partecipazione, consapevolezza e organizzazione. È il momento di scegliere da che parte stare. Noi, come sempre, stiamo dalla parte degli operai.

CHI FIRMA LA RESA È PARTE DEL PROBLEMA.
I DIRITTI NON SI FIRMANO. SI CONQUISTANO CON LA LOTTA.

RSU USB PIAGGIO

  •  

Comunicato congiunto: Sottomarini da guerra nel nostro porto? Ferma opposizione anche durante l’incontro con il presidente dell’Autorità di Sistema Portuale

Nella giornata di ieri una delegazione dei collettivi, sindacati e partiti che da anni lottano contro la militarizzazione del nostro porto e la complicità della nostra città con le guerre americane e israeliane ha incontrato il presidente dell’Autorità di Sistema Davide Gariglio e il dirigente demanio portuale Marilli. Incontro richiesto durante la recente manifestazione di protesta davanti a Palazzo Rosciano.
Abbiamo nuovamente espresso la nostra forte opposizione rispetto alla possibilità che l’azienda Drass, che dovrà produrre sottomarini da guerra per il governo indonesiano, possa ricevere in concessione spazi del nostro porto per i test di questi sottomarini.
Sappiamo inoltre che le concessioni per gli spazi che si stanno liberando in porto verranno rilasciate per periodi che raggiungono anche i dieci anni, motivo di ulteriore preoccupazione qualora aziende impegnate nella filiera bellica dovessero appropriarsene, rendendo di fatto il nostro porto luogo di produzione e test di mezzi destinati alla guerra.
Le ragioni che sono state espresse, a sostegno della nostra posizione, non hanno solo un carattere etico e politico. Basterebbero quelle. Ma anche economiche ed occupazionali. I traffici e le attività civili, ormai è ampiamente noto, hanno un’incidenza occupazionale ben maggiore. Inoltre, vi sono anche ragioni legate alla sicurezza dei lavoratori portuali e non solo.
Al netto di quali saranno le decisioni dell’Autorità e i bandi di assegnazione che usciranno siamo pronte e pronti a dare battaglia come tante altre volte, ricordando sempre che la guerra non è fatta solo di bombe e proiettili, ma anche e soprattutto di logistica, mezzi di trasporto e demolizione, come i caterpillar israeliani che fermammo a settembre al molo Italia.

 
Potere al Popolo
Attac Livorno
USB Livorno

 

  •  

Jurassic World a Milano: unica tappa italiana


C’è un nuovo motivo per fare un salto a Milano Sesto quest’estate.
Ha aperto Jurassic World: The Experience, la grande esperienza immersiva ufficiale dedicata alla celebre saga cinematografica che trasporta i visitatori nel mondo di Isla Nublar, tra dinosauri a grandezza naturale, scenografie spettacolari e ambientazioni ispirate ai film.

Dopo aver conquistato città come Londra, Madrid e Bangkok, l’esperienza arriva per la prima volta in Italia e sceglie MilanoSesto, a Sesto San Giovanni, come unica tappa italiana. L’evento sarà visitabile fino al 10 gennaio 2027.

Un viaggio nel mondo di Jurassic World
Non si tratta di una semplice mostra. Jurassic World: The Experience è un percorso immersivo che permette di entrare nelle ambientazioni iconiche della saga cinematografica, incontrando dinosauri animatronici a grandezza naturale e ricostruzioni fedeli dei laboratori e delle aree del parco.

Durante la visita si attraversano alcune delle location più famose del film. Tra queste ci sono gli iconici cancelli di Jurassic World, il laboratorio di creazione dei dinosauri e la valle popolata da gigantesche creature preistoriche. Inoltre, non mancano effetti speciali, suoni e scenografie che rendono l’esperienza ancora più coinvolgente.

Un’esperienza per grandi e piccoli
L’attrazione è pensata per tutta la famiglia. I bambini potranno osservare da vicino dinosauri come il Triceratopo, il Velociraptor e il maestoso Tyrannosaurus Rex, mentre gli adulti ritroveranno le atmosfere della saga cinematografica iniziata con Jurassic Park.

Grazie agli animatronici, agli effetti sonori e alle installazioni interattive, la visita permette di vivere un’avventura che va oltre la classica esposizione museale. Per questo motivo è una delle esperienze più attese dell’estate nell’area milanese.

Dove si trova e quando visitarla
Jurassic World: The Experience è allestita nell’area MilanoSesto, in viale Italia 576 a Sesto San Giovanni.

Per prenotare è possibile consultare il sito ufficiale dell’esperienza:
https://jurassicworldexperience.com/it/

Credits Photo
sito Jurassicworldexperience.com

Info Milano

L'articolo Jurassic World a Milano: unica tappa italiana proviene da InfoMilano.news.

  •  

Installare Mailman3 in un server con qmail e vpopmail

Mailman è un software libero per la gestione delle discussioni via mail e le liste di distribuzione. Mailman è integrato con il web, al fine di semplificare agli utenti la gestione degli account e agli ai proprietari (owners) l'amministrazione delle liste. Mailman comprende come parte integrante il sistema di archiviazione, il processamento automatico dei rimbalzi (bounce), il filtro dei contenuti, la spedizione dei digest, filtri anti spam, e altro.

Mailman è un software libero distribuitosotto la GNU General Public License, e scritto nel linguaggio di programmazione Python.

Indice

  •  
❌