Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
This was an unusually eventful week in cybersecurity. The FBI seized the NetNut residential proxy platform and associated Popa botnet infrastructure, marking one of the most significant takedowns of a proxy-based cybercrime enablement service. The operation targeted the Israeli company Alarum Technologies (NASDAQ: ALAR) and involved hundreds of seized domains, with Google also disabling accounts and apps tied to the malware. In the UK, two Scattered Spider members pleaded guilty on the first day of their trial to charges involving the 2024 Transport for London ransomware attack, with one also admitting to healthcare system intrusions. The group is alleged to have collected at least $115 million in ransom payments across 47 US entities. Britain announced plans for an autonomous AI-powered "Cyber Shield" to defend the nation, while simultaneously facing a leadership crisis that delayed the launch of the National Cyber Action Plan. A major medical device manufacturer notified nearly 4 million individuals of a data breach, and a critical Google Dialogflow CX flaw ("Rogue Agent") was disclosed and patched. On the mobile threat front, the RedWing Malware-as-a-Service emerged as a Telegram-rented Android banking trojan, and CISA issued urgent guidance on hardening Fortinet devices following credential exposure reports.
Incident Map
Defence 2 stories
Britain Plans Autonomous AI 'Cyber Shield' to Defend Nation
The UK government announced plans to develop an autonomous AI-driven "Cyber Shield" โ a defensive system designed to automatically detect and counter cyber threats to national infrastructure. The announcement comes amid a Labour leadership crisis that has delayed the broader National Cyber Action Plan.
CIA Chief Highlights Major Shifts in Agency's Tech Approach
The CIA director outlined significant changes to how the agency approaches technology, emphasizing cyber operations and AI adoption in intelligence gathering.
Financial Services 2 stories
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
A new Android malware operation called RedWing is being rented out on Telegram as a subscription-based bank-fraud service for as low as $300/month. It enables criminals to take over victims' phones, steal banking logins, and intercept one-time passcodes. Zimperium's zLabs identified it as a variant of the Oblivion malware, with a Telegram bot building custom malicious apps on demand.
Attackers Vote Themselves $20 Million in BONK Cryptocurrency
Attackers compromised a governance mechanism in the Solana-based BONK cryptocurrency and voted themselves approximately $20 million worth of tokens. The incident highlights ongoing security challenges with crypto governance protocols.
Government 7 stories
FBI Seizes NetNut Proxy Platform, Popa Botnet
The FBI seized hundreds of domains associated with NetNut, a residential proxy service operated by Israeli company Alarum Technologies (NASDAQ: ALAR). The action follows reports linking NetNut to the Popa botnet โ a network of at least 2 million compromised devices. Google confirmed it observed 316 distinct threat-actor clusters using NetNut exit nodes in a single week and has disabled related accounts and apps.
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Owen Flowers, 18, and Thalha Jubair, 20, pleaded guilty in the UK to charges related to the August 2024 Transport for London ransomware attack. Flowers also admitted to hacking US healthcare providers SSM Health Care and Sutter Health. The group's victims paid at least $115 million in ransoms across 47 US entities. Jubair is also wanted by US authorities under a New Jersey indictment.
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
CISA issued an alert urging organizations to harden Fortinet devices following reports of credential exposures. This adds to ongoing concerns about Fortinet appliances being targeted by threat actors.
Russian Intelligence Services Continue to Target Commercial Messaging Applications
A joint advisory warns that Russian intelligence services continue targeting commercial messaging apps, including Signal and WhatsApp, as part of espionage campaigns. The US has posted a $10 million reward related to this campaign.
Supreme Court Allows Texas App Law Requiring Age Verification to Take Effect
The US Supreme Court allowed a Texas law requiring app stores and platforms to implement age-verification measures to take effect, with implications for digital privacy and security regulation.
Launch of UK's National Cyber Action Plan Delayed Amid Labour Leadership Crisis
The UK's planned National Cyber Action Plan launch has been delayed due to an ongoing Labour Party leadership crisis, creating uncertainty around the country's cyber strategy timeline.
Canadian Spy Agency Reports Hacking Three Criminal Groups in 2025
Canada's signals intelligence agency (CSE) disclosed that it conducted offensive cyber operations against three criminal groups during 2025, a rare public acknowledgment of active cyber offense by a Five Eyes intelligence agency.
Healthcare 2 stories
Major Medical Device Manufacturer Notifies Nearly 4 Million of Breach
A major medical device manufacturer (identity undisclosed in reporting) sent breach notifications to nearly 4 million individuals, making this one of the largest healthcare sector data breaches of the year.
Scattered Spider Hackers Plead Guilty to Healthcare Hacks
As noted in the Government section, Owen Flowers admitted to hacking SSM Health Care Corporation and Sutter Health in September 2024, highlighting the healthcare sector's continued vulnerability to ransomware actors.
IT / Technology 4 stories
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
Security firm Varonis disclosed a critical vulnerability in Google's Dialogflow CX (named "Rogue Agent") that could allow attackers with edit rights on one agent to compromise all other agents in the same Google Cloud project. This could enable reading live conversations and stealing user data. Google has fixed the issue.
FBI Seizes NetNut Proxy Platform
(See Government section) โ The takedown of this residential proxy network has significant implications for the technology sector, as NetNut's SDKs were widely bundled in consumer applications, including smart TVs and streaming boxes.
Major Japanese Telco Says Cyberattack Exposed 12 Million Emails
A major Japanese telecommunications company disclosed a cyberattack that exposed approximately 12 million email addresses, one of the largest telco breaches in Japan's history.
UK Cyber Pledge Draws Only a Handful of Top Firms Despite Ministerial Appeal
A UK government cyber security pledge aimed at major corporations has seen limited uptake, with only a small number of top firms signing on despite ministerial appeals. This raises questions about private-sector commitment to national cyber resilience goals.
Media & Entertainment 2 stories
Ukrainian Media Outlets Now Among 'Priority Targets' for Russian Hackers
Ukrainian media organizations have been identified as "priority targets" for Russian state-aligned hacking groups, according to new threat intelligence. The targeting has intensified as part of broader information operations.
Japanese Teen Arrested Over Cyberattack That Disrupted Anime Streaming Service
A Japanese teenager was arrested in connection with a cyberattack that disrupted a major anime streaming service, highlighting the ongoing issue of young actors engaging in DDoS and other cyber offenses.
Energy & Utilities 1 story
Russian Intelligence Targeting of Messaging Apps Impacts Critical Infrastructure
(See Government section) โ The joint CISA advisory on Russian intelligence targeting messaging apps has particular relevance for the energy sector, where operational technology (OT) personnel often rely on messaging for coordination.
Cross-Sector / General 3 stories
Multiple KEV Updates โ CISA Adds Known Exploited Vulnerabilities to Catalog
CISA continued updating its Known Exploited Vulnerabilities (KEV) catalog with multiple additions, including at least 8 new entries across the week. Organizations across all sectors are urged to prioritize these patches.
Spyware Found on Phone of European Parliament Member Probing Spyware
Spyware was discovered on the phone of a European Parliament member who was actively involved in investigating spyware abuses, a deeply ironic and concerning development for democratic institutions.
US Racks Up About 400 Wins Over Illegal World Cup Streaming Sites
US authorities shut down approximately 400 illegal streaming websites related to World Cup broadcasts, demonstrating ongoing copyright enforcement through domain seizures.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |