What happened
Researchers at Calif.io disclosed a heap over-read vulnerability in the Squid web proxy, dubbed Squidbleed, that can expose one user's cleartext HTTP request — including credentials and session tokens — to another user sharing the same proxy. The flaw originates in a code change made in 1997 to handle FTP parsing and remains active in Squid's default configuration today. Separately, security researchers across multiple firms have attributed the Popa botnet — an Android-based operation running for at least four years — to NetNut, a residential proxy service operated by a publicly traded Israeli company. Popa is estimated to have compromised millions of consumer TV boxes, using them to route traffic tied to advertising fraud, account takeover campaigns, and large-scale data scraping.
Why it matters for your business
Any organization routing internal or customer traffic through Squid — a widely deployed open-source proxy — should treat Squidbleed as an active credential-exposure risk, not a theoretical one. Shared proxy environments are particularly vulnerable because a single malicious or compromised session could harvest authentication tokens from unrelated users on the same instance. The Popa findings carry a different but equally serious implication: residential proxy networks marketed as legitimate infrastructure may be built on compromised consumer devices without those device owners' knowledge, meaning enterprises that use such services for data collection or ad verification could inadvertently be complicit in fraud. Operations and security teams should audit proxy vendors for transparency around node sourcing and review contractual liability clauses accordingly.
What to watch next
A patch for Squidbleed had not been confirmed as fully deployed at time of disclosure, so administrators should monitor the official Squid project repository and apply fixes as they become available while considering interim controls such as traffic isolation. The attribution of Popa to a publicly traded firm raises the prospect of regulatory and legal scrutiny — investors and enterprise customers of NetNut should watch for official responses and potential action from securities or data-protection authorities. Broader questions about the residential proxy industry's device-consent practices are likely to draw increased attention from regulators in the EU and US.
