Back to news

FatFs Vulnerabilities Expose Embedded Devices; FBI Seizes NetNut Proxy Network

Seven unpatched flaws in a ubiquitous firmware library and an FBI takedown of a botnet-linked proxy service mark a turbulent week for hardware and network security.

FatFs Vulnerabilities Expose Embedded Devices; FBI Seizes NetNut Proxy Network

What happened

Researchers at runZero publicly disclosed seven unpatched vulnerabilities in FatFs, a lightweight filesystem library embedded in the firmware of security cameras, industrial controllers, drones, and hardware crypto wallets — potentially affecting millions of devices worldwide. Separately, the FBI, working alongside industry partners, seized hundreds of domains tied to NetNut, a residential proxy platform operated by Nasdaq-listed Israeli firm Alarum Technologies. The law enforcement action followed reporting by Krebs on Security that linked NetNut's infrastructure to the Popa botnet, which routes malicious traffic through compromised consumer devices.

Why it matters for your business

The FatFs findings are particularly consequential because the library is rarely updated in deployed hardware — firmware supply chains are notoriously slow to patch, meaning devices already in the field may remain vulnerable indefinitely. Organizations relying on embedded systems for operations, access control, or data storage should audit their device inventories and request firmware update timelines from vendors. The NetNut seizure signals that authorities are scrutinizing residential proxy services with renewed intensity, which carries compliance implications for any business that uses third-party proxy networks for web scraping, ad verification, or anonymized data collection. Procurement and security teams should verify that proxy providers are not inadvertently routing traffic through botnet-compromised endpoints.

What to watch next

runZero has indicated the FatFs vulnerabilities remain unpatched, so coordinated disclosure timelines and any vendor responses will be critical to follow in the coming weeks. On the law enforcement front, Alarum Technologies faces potential regulatory and investor scrutiny given its public listing, and further government actions against proxy-as-a-service platforms are widely anticipated. Businesses dependent on either embedded IoT infrastructure or third-party proxy networks should treat both developments as near-term risk signals requiring immediate vendor engagement.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp