What happened
Security researchers have traced the Popa botnet — an Android-based network that has operated for at least four years across millions of consumer TV boxes — to NetNut, a residential proxy service run by the publicly traded Israeli company Ala. The botnet has been used to facilitate advertising fraud, credential-stuffing attacks, and large-scale data scraping by routing malicious traffic through compromised devices. Separately, F5 disclosed and patched two critical vulnerabilities in NGINX Open Source, both capable of enabling remote code execution. The more severe flaw, CVE-2026-42530 with a CVSS v4 score of 9.2, is a use-after-free bug in the HTTP/3 module that an unauthenticated remote attacker can trigger without any user interaction.
Why it matters for your business
The Popa botnet case highlights a broader risk: residential proxy networks can quietly enlist everyday devices — including hardware already inside corporate supply chains — as unwitting traffic relays, making fraud and scraping activity harder to detect and attribute. Organizations that rely on IP reputation signals for fraud prevention or bot mitigation should reassess how much trust they extend to residential IP ranges. On the NGINX front, any company running internet-facing infrastructure on unpatched versions of NGINX Open Source is exposed to a critical, no-authentication-required attack vector. CTOs and operations teams should audit their NGINX deployments immediately and apply F5's latest security updates, prioritizing any instances with HTTP/3 enabled.
What to watch next
Regulatory and legal scrutiny of the residential proxy industry is likely to intensify following the public linkage of Popa to a listed company, and similar investigations into peer providers are probable. On the NGINX side, proof-of-concept exploit code typically surfaces within days of high-profile CVE disclosures, compressing the window organizations have to patch before active exploitation begins.
