Search/akamai technologies
Vendor

akamai technologies

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
client
Connections
9 relationships
WAFを89%すり抜ける事例も──AIが休みなく仕掛けるWeb攻撃、予防策はあるか
「見えないWeb攻撃」──情報漏えい対策の盲点 WAFを89%すり抜ける事例も──AIが休みなく仕掛けるWeb攻撃、予防策はあるか(1/4 ページ) 米Anthropicや米OpenAIなどが開発するフロンティアAIの登場による、脆弱性探索能力の飛躍的な向上が、サイバーセキュリティの攻防を否応なく次のステージに押し上げようとしている。 エージェント型AIによる“マシンスピード”での攻撃が、WebやAPIに具体的にどのようなリスクをもたらすのか。実際に観測されているAIによるWeb攻撃の特徴を分析し、防御側の備えとして何が必要になるかを具体的に探っていこう。 AIでサイバーリスクはどう変わる? フロンティアAIが攻撃に使われることで、何が変わるのだろうか? まず、OSやシステム、プログラムなどの未知の脆弱性が大量に発見できるようになる。Anthropicの「Claude Mythos」の先行利用権を得て自社のサービスの脆弱性を検証した企業は、(AIも組み込まれた)既存の脆弱性検査ツールと比べ、発見される数量も検知の精度もまさに桁違いだとレポートしている。 こうしたモデルは、発見した脆弱性を悪用して攻撃を仕掛けるためのプログラム(エクスプロイトコード)を瞬時に生成する能力も備えている。人力では数日から数週間を要するが、生成AIの能力があれば、わずか数分に短縮される。 AIは、単体では深刻とまではいえない脆弱性を組み合わせ、実システムに対して攻撃を繰り返すことで、防御をすり抜ける道筋を割り出す能力にも長けている。これら一連の手順を、AIが“マシンスピード”で試行し続ける点が最大の脅威となっている。 その一方で、多くの企業や開発ベンダーはアプリケーションの開発に生成AIを用いる「バイブコーディング」を取り入れようとしている。開発の高速化を見込む動きではあるが、一方でセキュリティ面が十分でないコードが量産される恐れもあり、多くの脆弱性を生むリスクが高まっている。 最新AIがWAF防御をすり抜ける? Web攻撃の変化 こうした状況変化の結果、WebサイトやWebアプリケーション、スマートフォンアプリ・サービスで用いられるWeb APIはとあるリスクに直面している。攻撃者が操るAIから、WAF (Web Application Firewall)の検知ルールをすり抜けられるパターンの探索を、絶え間なく受けるリスクが高まっているのだ。 WAFのすりぬけには「難読化」という手法がよく用いられる。Webへの侵害では、Webサーバの背後で動作しているプログラムやデータベースなどの不正な操作を引き起こす命令文を送る。その命令文の途中に特殊な文字を混ぜるなどして、WAFルールで設定された照合用文字列との一致による検知の回避を試みるのが難読化の手口だ。 つまり、AIは「WAFの検知は回避できるが、標的にしたアプリケーションには意図した命令が通る」すり抜けパターンを大量に生成し、自動で試そうとする。 AIが難読化したリクエストが、実際WAFの検知ルールを突破してしまうことは、研究者により検証されている。例えばAIが生成した、SQLインジェクションの派生パターンによる攻撃の試行では、オープンソースのWAFである「ModSecurity」で89%、「AWS WAF」では約41%の攻撃が、それぞれのWAFルールによる検知を回避して突破。同様にクロスサイトスクリプティングでも、80%がModSecurityの検知を突破している。 実際に、クラウド型WAFを企業向けに提供しているAkamai Technologiesでは、攻撃側のAIが生成したと考えられる難読化された攻撃の試行をすでにとらえている。 Copyright © ITmedia, Inc. All Rights Reserved. 「見えないWeb攻撃」──情報漏えい対策の盲点 さまざまなWebサービスが、巧妙に隠された「見えないWeb攻撃」に狙われている。個人情報漏えいや犯罪行為を引き起こしている攻撃の実態を、独自のデータを交えて分析する。
itmedia.co.jpAug 2, 2026extracted
なぜいま「DNS」の見直しが必要? 攻撃者が狙う“6つの設定ミス”
NIST����������DNS�K�C�h���C������ɁAAkamai�͍U���҂��W�I�Ƃ���6�̎�v��DNS�ݒ�E�^�p��̖��ɂ��ĉ�������B�l�b�g���[�N�Z�L�����e�B�ɂ�����DNS�̏d�v���ƁA�U���҂ɑ_���₷���_�Ƃ́B �@CDN�i�R���e���c�f���o���[�l�b�g���[�N�j�x���_�[Akamai Technologies��2026�N6��18���i�č����ԁj�A�č������W���Z�p�������iNIST�j��3���Ɍ��J����DNS�iDomain Name System�j�K�C�h���C�������ŁuSP 800-81r3�v�ɂ��ĉ�������u���O�L�������J�����B �@DNS��Web�A�N�Z�X��N���E�h�T�[�r�X���p�A���[�����M�ȂǁA��Ƃɂ�����l�b�g���[�N�����̋N�_�ƂȂ�B���ꂾ���ɓK�ɊǗ�����Ȃ�����X�N�������\�������邪�ADNS�̌��S���Ǘ��͌�ɂ���Ă���ƃu���O�L���͎w�E����B �@NIST�̐V�K�C�h���C���ł́ADNS�͒P�Ȃ閼�O�����̎d�g�݂Ƃ��������A�l�b�g���[�N�Z�L�����e�B���x���鐧���ՂƂ��Ĉʒu�t�����Ă���BAkamai�͂���܂��A�U���҂ɑ_���₷��DNS�ݒ�~�X�Ƃ���6�̖���������Ă���B �@DNS�͖{���A�l�Ԃ��ǂ݂₷���h���C������IP�A�h���X�ɕϊ�����u���O�����v�̂��߂̎d�g�݂��B������NIST�͍ŐV�ł�DNS�K�C�h���C���ŁADNS���[���g���X�g�⑽�w�h����x����l�b�g���[�N�Z�L�����e�B�̊�ՂƂ��Ĉʒu�t���ADNS���|���V�[�K�p�⋺�Ќ��m���s���d�v�Ȑ���|�C���g�Ƃ��Ċ��p���邱�Ƃ𐄏����Ă���B NIST�͎��̂悤�ȑ�𐄏����Ă���B �@Akamai�ɂ��ƁAAI bot�̃g���t�B�b�N��2025�N��300�����������B��������bot��DNS�̐ݒ�~�X��ϋɓI�ɒT�����Ă���Ƃ����B�����X�L���i�[�́A���u���ꂽCNAME���R�[�h�̌��o����J���\�[�X���R�[�h�̎��W�A������ƂȂ���DNS�ϔC�̏�����Ȃǂ��A�l��ł͒ǂ��t���Ȃ����x�Ŏ��s����B �@AI�G�[�W�F���g�̕��y�ɔ����ADNS�̐M�����͂���ɏd�v�ɂȂ�B1�̃^�X�N��5�10��̐��_���N�G�X�g�����s����AI�G�[�W�F���g�ł́A�]�[���h���t�g�iDNS�ݒ�̕s�����j�ɂ��x����T�u�h���C��������̃��X�N�͋��e�ł��Ȃ��BDNS�ϔC�̐ݒ�~�X�́A���[�U�[�̗����Ȃ������łȂ��A���������ꂽ���[�N�t���[�S�̂��C�t���Ȃ������ɒ�~�����鋰�ꂪ����B �@NIST��DNS�K�C�h���C���́ADNS�����Ǘ����錠��DNS�T�[�o�▼�O�������s����ċA���]���o�A�N���C�A���g���̖��O�����@�\�i�X�^�u���]���o�j�ȂǁADNS�V�X�e���S�̂�Ώۂɂ��Ėԗ��I�ɋ��Ђ��J�^���O�����Ă���B����������_��̂��̂ł͂Ȃ��A��Ƃ����ۂɒ��ʂ��Ă���U���܂������̂��B�ȉ��́AAkamai�����ɒ��ӂ��ׂ��Ƃ���6��DNS�ݒ�E�^�p��̖�肾�B �@DNS���R�[�h�ł���CNAME���R�[�h���A�g�D�����ɊǗ����Ă��Ȃ��e�h���C�����w���Ă���ꍇ�A�U���҂����̃]�[����o�^���ADNS���������g�̃C���t���փ��_�C���N�g�ł���B���K�h���C���̐M���ƕ]�������̂܂܈����p����ɂȂ邽�߁A�U���ɋC�t���ɂ����B �@���C���f���Q�[�V�����ilame delegation�j�́A�T�u�h���C����DNS�z�X�e�B���O�v���o�C�_�[�ɈϔC����Ă���ɂ�������炸�A���̃T�[�r�X�_�ϔC���c�����܂��������ۂɔ�������B�U���҂͓����v���o�C�_�[�ƌ_�Ă��̃T�u�h���C�����z�X�g���邱�ƂŁA�������N�G�X�g�̐��䌠���ɓ�����B �@�U���҂͕W�I�g�D�ɂȂ肷�܂����߂ɁA�ގ��h���C����h���C�����̃~�X�^�C�v��_�����^�C�|�X�N���b�e�B���O�h���C����o�^����B�����ȕ����̒u�������A���ە����̌n����̓��`�ّ̎��A���K�h���C���ƌ��ԈႦ�₷���ώ�Ȃǂ�����Ƃ��Ďg����BNIST�́A�p�~���ꂽ�ϔC���O�҂��o�^���邱�ƂŌÂ������N��u�b�N�}�[�N���[�U�[��U�����郊�X�N���w�E���Ă���B �@SOA�iStart of Authority�j���R�[�h�ɐݒ肷��]�[�����̍X�V�Ԋu�iRefresh�j��A�X�V���s���̍Ď��s�Ԋu�iRetry�j���K�łȂ��ƁA�v���C�}���[�ƃZ�J���_���[�̃l�[���T�[�o�Ԃœ����������B�l�����߂���ƌÂ��s���m�ȃf�[�^���c��]�[���h���t�g���N���A��߂���Ɖߏ�ȓ]���ɂ���ăT�[�r�X������]�[���X���b�V������������B �@DNS�̃��\�[�X���R�[�h�ł���HINFO�iHost Information�j�ARP�iResponsible Person�j�ALOC�iLocation�j�A�ݒ�~�X�̂���TXT�G���g���Ȃǂ̃��R�[�h�́A�U���҂�bot��OS��Ǝ�i�������Ⴍ�j�������T�[�r�X���܂ޓ����C���t���̏ڍׂȏ�����Ă��܂��BNIST�͂����̃��R�[�h�^�C�v���C���^�[�l�b�g�����]�[�����犮�S�ɏ��O���邱�Ƃ𐄏����Ă���B �@DNSSEC�́A�L���b�V���|�C�Y�j���O�A�����X�v�[�t�B���O�A���ԎҍU���iMITM�U���j����DNS�f�[�^���Í��I�ɕی삷��B�Í���DNS�v���g�R���ł���uDoT�v�iDNS over TLS�j�A�uDoH�v�iDNS over HTTPS�j�A�uDoQ�v�iDNS over QUIC�j�͖₢���킹�Ɖ����̃v���C�o�V�[�Ɗ��S���i�f�[�^�����m�ʼn�����Ă��Ȃ����Ɓj��ی삷��BNIST�͈Í����̍X�V���ւ��̍ۂ̕s�K��DNSSEC�Ǘ���DNS�T�[�r�X��Q�̌����ɂȂ�ƌx�����Ă���B �@�����̃��X�N�ɋ��ʂ���̂́ADNS�ݒ��^�p���p���I�ɔc���E�Ǘ��ł��Ă��Ȃ����w�i�ɂ��邱�Ƃ��BNIST��DNS�K�C�h���C���́ADNS���l�b�g���[�N�Z�L�����e�B���x����d�v�Ȑ����ՂƂ��Ĉʒu�t���A�K�Ȑݒ�ƌp���I�ȉ^�p�E�ێ�̏d�v���������Ă���B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpJul 30, 2026extracted
Hush Security Raises $30 Million for AI Agent Governance
Cybersecurity startup Hush Security today announced raising $30 million in a Series A funding round that brings the total raised by the company to $41 million. The fresh investment came from Akamai Technologies and previous backers Battery Ventures and YL Ventures. Founded in 2024, Tel Aviv-based Hush Security emerged from stealth in September 2025 with a machine access platform that enables organizations to securely control enterprise AI agents and their underlying infrastructure. With every agent enrolled in a central registry, the solution provides scoped just-in-time (JIT) permissions at runtime, eliminating credentials, logging every action, and offering a centralized kill switch. Hush’s platform allows organizations to identify agents running in their environments and map the MCPs, tools, and resources they reach and use. It also enables them to register, control, and secure all agents from a single, central panel, map their permissions, and enforce policies for each action. Additionally, it maintains a complete audit trail for each AI agent interaction to support investigations, compliance, and governance. Hush will use the fresh investment to hire new talent across its engineering and sales teams, accelerate IAM and agentic ecosystem support, and expand corporate partnerships. “Every company already knows how to manage identity for its people and its applications. But now software acts autonomously, on its own initiative, inside your most sensitive systems. AI agents need strict identity, not just API keys. We solved that for non-human identities, and now we’re extending governance to AI agents,” said Hush Security co-founder and CEO Micha Rave. Related: Beelzebub Raises $3.4 Million for Hacker-Trapping Platform Related: Palo Alto Networks to Acquire Observability Platform Provider Embrace Related: StrongestLayer Raises $4.1 Million in Seed Funding Extension Related: Empirical Security Raises $25 Million in Series A Funding
securityweek.comJul 28, 2026extracted
OpenAI’s Daybreak uses Codex Security to identify risky attack paths
OpenAI’s Daybreak uses Codex Security to identify risky attack paths OpenAI Daybreak is the company’s cybersecurity initiative focused on building AI-assisted software defense into the development process from the start. It combines OpenAI models, Codex Security, and cyber-focused GPT-5.5 variants to help organizations identify, validate, and prioritize software vulnerabilities. How Daybreak identifies exploitable vulnerabilities Daybreak builds editable threat models from a company’s code repository, analyzes realistic attack paths, validates likely vulnerabilities in isolated environments, and helps teams focus on exploitable issues instead of noisy alerts. “Daybreak combines the intelligence of OpenAI models, the extensibility of Codex as an agentic harness, and our partners across the security flywheel to help make the world safer for everyone. Defenders can bring secure code review, threat modeling, patch validation, dependency risk analysis, detection, and remediation guidance into the everyday development loop so software becomes more resilient from the start,” the company said. Organizations can request a Daybreak assessment from OpenAI that includes a vulnerability scan. Pricing details have not been disclosed. OpenAI offers three levels of access. Default GPT-5.5 for general-purpose, developer, and knowledge work, GPT-5.5 with Trusted Access for Cyber for verified defensive work in authorized environments, and GPT-5.5-Cyber for specialized authorized workflows with stronger verification and account-level controls. OpenAI prepares rollout of cyber-capable AI models The company said it is working with industry and government partners while preparing to deploy more cyber-capable models as part of an iterative deployment approach. “We are excited to partner with OpenAI to gain access to the Trusted Access for Cyber program. Frontier models are fundamentally changing vulnerability management, and early access enables us to adapt proactively. The adoption of these capabilities will be critical for enterprise security teams,” said Boaz Gelbord, chief security officer at Akamai Technologies.
helpnetsecurity.comMay 12, 2026extracted
バイブコーディングが“脆弱性の温床”に? APIへの攻撃が113%増――AI時代の攻撃実態
Akamai�̃��|�[�g�u�C���^�[�l�b�g�̌���v�iSOTI�j�ɂ��ƁAAI�̕��y���T�C�o�[�U����ς�����BAPI����v�ȍU���ΏۂƂȂ�A�o�C�u�R�[�f�B���O���V���ȃ��X�N���������˂Ȃ��Ƃ����B���̎��ԂƂ́B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@�Z�L�����e�B�����CDN�i�R���e���c�f���o���[�l�b�g���[�N�j�x���_�[Akamai Technologies��2026�N3��17���i�č����ԁj�A�Z�L�����e�B���|�[�g�uApps, APIs, and DDoS 2026�v�i2026�N�̃A�v���AAPI�A�����DDoS�j�����J�����B�����|�[�g�́A���Ђ��W�J����Z�L�����e�B���|�[�g�V���[�Y�uThe State of the Internet�v�iSOTI�F�C���^�[�l�b�g�̌���j�̈���B �@�T�C�o�[�U���͂������N�ŋ}���ɐi�����Ă���ƁAAkamai�̒����`�[���͎w�E����B��̓I�ɂ�API�i�A�v���P�[�V�����v���O���~���O�C���^�t�F�[�X�j�̈��p��Web�A�v���P�[�V�����U���A���C���[7��DDoS�i���U�^�T�[�r�X���ہj�U����g�ݍ��킹���u�����^�L�����y�[���v�Ɉڍs������Ƃ����B �@�g�D��AI�i�l�H�m�\�j�̓��������������钆�ŁAAPI����v�ȃA�^�b�N�T�[�t�F�X�i�U���ʁj�ɂȂ����Ƃ����̂��AAkamai�̌������B�����|�[�g�ɂ��ƁA2025�N���ɒ����Ώۑg�D��87����API�֘A�̃Z�L�����e�B�C���V�f���g���o���������A2024�N����2025�N�ɂ�����1���������API�U���̕��ό�����113�����������B �@�����|�[�g�ɂ��ƁA�g�D�̓A�v���P�[�V�����̃Z�L�����e�B��API�̃Z�L�����e�B���ˑR�Ƃ��ĕʂ̉ۑ�Ƃ��đ����A�ʂɊǗ����Ă���B���������ł͑g�D���S�̂̏�c�����ɂ����Ȃ�A�U���҂ɃA�v���P�[�V������API����̂̍U���o�H�Ƃ��Ĉ��p����郊�X�N�����܂�Ƃ����B �@�u�g�D�̊Ԃ�AI�������i�ޒ��A������x����API���U���҂̎�ȕW�I�ɂȂ��Ă���v�BAkamai�̃Z�L�����e�B�헪�S��CTO�i�ō��Z�p�ӔC�ҁj�ł���p�g���b�N�E�T���o�����́A�����w�E����B �@�T���o�����ɂ��ƁA�U���҂͕W�I�g�D�ɂ�����V�X�e���̃p�t�H�[�}���X�ቺ��IT�C���t���R�X�g�㏸��_���̂ɉ����āAAI�����p������K�͂Ȏ������ɏd�_��u���悤�ɂȂ��Ă���B�U���҂�AI�̊��p�ɂ��A�I���ȃL�����y�[�����R�X�g���v���ɌJ��Ԃ����s�ł���悤�ɂȂ����Ƃ����B �@AI�Ƀ\�[�X�R�[�h��������u�o�C�u�R�[�f�B���O�v�ŊJ�������A�v���P�[�V�����ł́A�Ǝ�i�������Ⴍ�j����ݒ�~�X�����荞�ރ��X�N������Ɠ����|�[�g�͎w�E����B���������A�v���P�[�V�������\���ȃe�X�g���o�Ȃ��܂ܖ{�Ԋ��ɓ��������ƁA�Z�L�����e�B���X�N�̑���ɂȂ���Ɠ����|�[�g�͌x����炷�B �@�����|�[�g�ɂ��ƁA2023�N����2025�N�ɂ�����Web�A�v���P�[�V�����U����73���������A���C���[7��DDoS�U����104�����������B�w�i�ɂ́uDDoS as a Service�v�iDDoSaaS�j�Ȃǂ�DDoS�U���T�[�r�X�̕��y�ɂ���āAbot�l�b�g��e�Ղɓ���ł���悤�ɂȂ������Ƃɉ����āAAI�����p�����U���X�N���v�g�̐Z��������Ƃ����B �@bot�l�b�g�\�z�}���E�F�A�uMirai�v����ɂ����A�uAisuru�v�uKimwolf�v�Ƃ�������K��bot�l�b�g���o�ꂵ�Ă���A������DDoSaaS��IT�C���t���Ƃ��Ďg���Ă���Ɠ����|�[�g�͎w�E����BDDoSaaS�́A�T�C�o�[�ƍߎ҂�n�N�e�B�r�X�g�i�Љ�I�E�����I�咣��ړI�Ƃ���U���ҁj�Ȃǂɗ��p����Ă���B �@�����|�[�g�ɂ��ƁA�n�N�e�B�r�X�g�哱��DDoS�U���͈��������������Ă���B�w�i�ɂ͍��ۏ�ْ̋�����^���^bot�l�b�g�̗��p�g�傪����A�n�N�e�B�r�X�g�͂��������ω��ɔ����Ċ����������������Ă���Ƃ����B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpApr 21, 2026extracted
The Kimwolf Botnet is Stalking Your Local Network
The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. The vulnerability at issue has been exploited for months already, and it’s time for a broader awareness of the threat. The short version is that everything you thought you knew about the security of the internal network behind your Internet router probably is now dangerously out of date. The past few months have witnessed the explosive growth of a new botnet dubbed Kimwolf, which experts say has infected more than 2 million devices globally. The Kimwolf malware forces compromised systems to relay malicious and abusive Internet traffic — such as ad fraud, account takeover attempts and mass content scraping — and participate in crippling distributed denial-of-service (DDoS) attacks capable of knocking nearly any website offline for days at a time. More important than Kimwolf’s staggering size, however, is the diabolical method it uses to spread so quickly: By effectively tunneling back through various “residential proxy” networks and into the local networks of the proxy endpoints, and by further infecting devices that are hidden behind the assumed protection of the user’s firewall and Internet router. Residential proxy networks are sold as a way for customers to anonymize and localize their Web traffic to a specific region, and the biggest of these services allow customers to route their traffic through devices in virtually any country or city around the globe. The malware that turns an end-user’s Internet connection into a proxy node is often bundled with dodgy mobile apps and games. These residential proxy programs also are commonly installed via unofficial Android TV boxes sold by third-party merchants on popular e-commerce sites like Amazon, BestBuy, Newegg, and Walmart. These TV boxes range in price from $40 to $400, are marketed under a dizzying range of no-name brands and model numbers, and frequently are advertised as a way to stream certain types of subscription video content for free. But there’s a hidden cost to this transaction: As we’ll explore in a moment, these TV boxes make up a considerable chunk of the estimated two million systems currently infected with Kimwolf. Kimwolf also is quite good at infecting a range of Internet-connected digital photo frames that likewise are abundant at major e-commerce websites. In November 2025, researchers from Quokka published a report (PDF) detailing serious security issues in Android-based digital picture frames running the Uhale app — including Amazon’s bestselling digital frame as of March 2025. There are two major security problems with these photo frames and unofficial Android TV boxes. The first is that a considerable percentage of them come with malware pre-installed, or else require the user to download an unofficial Android App Store and malware in order to use the device for its stated purpose (video content piracy). The most typical of these uninvited guests are small programs that turn the device into a residential proxy node that is resold to others. The second big security nightmare with these photo frames and unsanctioned Android TV boxes is that they rely on a handful of Internet-connected microcomputer boards that have no discernible security or authentication requirements built-in. In other words, if you are on the same network as one or more of these devices, you can likely compromise them simultaneously by issuing a single command across the network. THERE’S NO PLACE LIKE 127.0.0.1 The combination of these two security realities came to the fore in October 2025, when an undergraduate computer science student at the Rochester Institute of Technology began closely tracking Kimwolf’s growth, and interacting directly with its apparent creators on a daily basis. Benjamin Brundage is the 22-year-old founder of the security firm Synthient, a startup that helps companies detect proxy networks and learn how those networks are being abused. Conducting much of his research into Kimwolf while studying for final exams, Brundage told KrebsOnSecurity in late October 2025 he suspected Kimwolf was a new Android-based variant of Aisuru, a botnet that was incorrectly blamed for a number of record-smashing DDoS attacks last fall. Brundage says Kimwolf grew rapidly by abusing a glaring vulnerability in many of the world’s largest residential proxy services. The crux of the weakness, he explained, was that these proxy services weren’t doing enough to prevent their customers from forwarding requests to internal servers of the individual proxy endpoints. Most proxy services take basic steps to prevent their paying customers from “going upstream” into the local network of proxy endpoints, by explicitly denying requests for local addresses specified in RFC-1918, including the well-known Network Address Translation (NAT) ranges 10.0.0.0/8, 192.168.0.0/16, and 172.16.0.0/12. These ranges allow multiple devices in a private network to access the Internet using a single public IP address, and if you run any kind of home or office network, your internal address space operates within one or more of these NAT ranges. However, Brundage discovered that the people operating Kimwolf had figured out how to talk directly to devices on the internal networks of millions of residential proxy endpoints, simply by changing their Domain Name System (DNS) settings to match those in the RFC-1918 address ranges. “It is possible to circumvent existing domain restrictions by using DNS records that point to 192.168.0.1 or 0.0.0.0,” Brundage wrote in a first-of-its-kind security advisory sent to nearly a dozen residential proxy providers in mid-December 2025. “This grants an attacker the ability to send carefully crafted requests to the current device or a device on the local network. This is actively being exploited, with attackers leveraging this functionality to drop malware.” As with the digital photo frames mentioned above, many of these residential proxy services run solely on mobile devices that are running some game, VPN or other app with a hidden component that turns the user’s mobile phone into a residential proxy — often without any meaningful consent. In a report published today, Synthient said key actors involved in Kimwolf were observed monetizing the botnet through app installs, selling residential proxy bandwidth, and selling its DDoS functionality. “Synthient expects to observe a growing interest among threat actors in gaining unrestricted access to proxy networks to infect devices, obtain network access, or access sensitive information,” the report observed. “Kimwolf highlights the risks posed by unsecured proxy networks and their viability as an attack vector.” ANDROID DEBUG BRIDGE After purchasing a number of unofficial Android TV box models that were most heavily represented in the Kimwolf botnet, Brundage further discovered the proxy service vulnerability was only part of the reason for Kimwolf’s rapid rise: He also found virtually all of the devices he tested were shipped from the factory with a powerful feature called Android Debug Bridge (ADB) mode enabled by default. ADB is a diagnostic tool intended for use solely during the manufacturing and testing processes, because it allows the devices to be remotely configured and even updated with new (and potentially malicious) firmware. However, shipping these devices with ADB turned on creates a security nightmare because in this state they constantly listen for and accept unauthenticated connection requests. For example, opening a command prompt and typing “adb connect” along with a vulnerable device’s (local) IP address followed immediately by “:5555” will very quickly offer unrestricted “super user” administrative access. Brundage said by early December, he’d identified a one-to-one overlap between new Kimwolf infections and proxy IP addresses offered for rent by China-based IPIDEA, currently the world’s largest residential proxy network by all accounts. “Kimwolf has almost doubled in size this past week, just by exploiting IPIDEA’s proxy pool,” Brundage told KrebsOnSecurity in early December as he was preparing to notify IPIDEA and 10 other proxy providers about his research. Brundage said Synthient first confirmed on December 1, 2025 that the Kimwolf botnet operators were tunneling back through IPIDEA’s proxy network and into the local networks of systems running IPIDEA’s proxy software. The attackers dropped the malware payload by directing infected systems to visit a specific Internet address and to call out the pass phrase “krebsfiveheadindustries” in order to unlock the malicious download. On December 30, Synthient said it was tracking roughly 2 million IPIDEA addresses exploited by Kimwolf in the previous week. Brundage said he has witnessed Kimwolf rebuilding itself after one recent takedown effort targeting its control servers — from almost nothing to two million infected systems just by tunneling through proxy endpoints on IPIDEA for a couple of days. Brundage said IPIDEA has a seemingly inexhaustible supply of new proxies, advertising access to more than 100 million residential proxy endpoints around the globe in the past week alone. Analyzing the exposed devices that were part of IPIDEA’s proxy pool, Synthient said it found more than two-thirds were Android devices that could be compromised with no authentication needed. SECURITY NOTIFICATION AND RESPONSE After charting a tight overlap in Kimwolf-infected IP addresses and those sold by IPIDEA, Brundage was eager to make his findings public: The vulnerability had clearly been exploited for several months, although it appeared that only a handful of cybercrime actors were aware of the capability. But he also knew that going public without giving vulnerable proxy providers an opportunity to understand and patch it would only lead to more mass abuse of these services by additional cybercriminal groups. On December 17, Brundage sent a security notification to all 11 of the apparently affected proxy providers, hoping to give each at least a few weeks to acknowledge and address the core problems identified in his report before he went public. Many proxy providers who received the notification were resellers of IPIDEA that white-labeled the company’s service. KrebsOnSecurity first sought comment from IPIDEA in October 2025, in reporting on a story about how the proxy network appeared to have benefitted from the rise of the Aisuru botnet, whose administrators appeared to shift from using the botnet primarily for DDoS attacks to simply installing IPIDEA’s proxy program, among others. On December 25, KrebsOnSecurity received an email from an IPIDEA employee identified only as “Oliver,” who said allegations that IPIDEA had benefitted from Aisuru’s rise were baseless. “After comprehensively verifying IP traceability records and supplier cooperation agreements, we found no association between any of our IP resources and the Aisuru botnet, nor have we received any notifications from authoritative institutions regarding our IPs being involved in malicious activities,” Oliver wrote. “In addition, for external cooperation, we implement a three-level review mechanism for suppliers, covering qualification verification, resource legality authentication and continuous dynamic monitoring, to ensure no compliance risks throughout the entire cooperation process.” “IPIDEA firmly opposes all forms of unfair competition and malicious smearing in the industry, always participates in market competition with compliant operation and honest cooperation, and also calls on the entire industry to jointly abandon irregular and unethical behaviors and build a clean and fair market ecosystem,” Oliver continued. Meanwhile, the same day that Oliver’s email arrived, Brundage shared a response he’d just received from IPIDEA’s security officer, who identified himself only by the first name Byron. The security officer said IPIDEA had made a number of important security changes to its residential proxy service to address the vulnerability identified in Brundage’s report. “By design, the proxy service does not allow access to any internal or local address space,” Byron explained. “This issue was traced to a legacy module used solely for testing and debugging purposes, which did not fully inherit the internal network access restrictions. Under specific conditions, this module could be abused to reach internal resources. The affected paths have now been fully blocked and the module has been taken offline.” Byron told Brundage IPIDEA also instituted multiple mitigations for blocking DNS resolution to internal (NAT) IP ranges, and that it was now blocking proxy endpoints from forwarding traffic on “high-risk” ports “to prevent abuse of the service for scanning, lateral movement, or access to internal services.” Brundage said IPIDEA appears to have successfully patched the vulnerabilities he identified. He also noted he never observed the Kimwolf actors targeting proxy services other than IPIDEA, which has not responded to requests for comment. Riley Kilmer is founder of Spur.us, a technology firm that helps companies identify and filter out proxy traffic. Kilmer said Spur has tested Brundage’s findings and confirmed that IPIDEA and all of its affiliate resellers indeed allowed full and unfiltered access to the local LAN. Kilmer said one model of unsanctioned Android TV boxes that is especially popular — the Superbox, which we profiled in November’s Is Your Android TV Streaming Box Part of a Botnet? — leaves Android Debug Mode running on localhost:5555. “And since Superbox turns the IP into an IPIDEA proxy, a bad actor just has to use the proxy to localhost on that port and install whatever bad SDKs [software development kits] they want,” Kilmer told KrebsOnSecurity. ECHOES FROM THE PAST Both Brundage and Kilmer say IPIDEA appears to be the second or third reincarnation of a residential proxy network formerly known as 911S5 Proxy, a service that operated between 2014 and 2022 and was wildly popular on cybercrime forums. 911S5 Proxy imploded a week after KrebsOnSecurity published a deep dive on the service’s sketchy origins and leadership in China. In that 2022 profile, we cited work by researchers at the University of Sherbrooke in Canada who were studying the threat 911S5 could pose to internal corporate networks. The researchers noted that “the infection of a node enables the 911S5 user to access shared resources on the network such as local intranet portals or other services.” “It also enables the end user to probe the LAN network of the infected node,” the researchers explained. “Using the internal router, it would be possible to poison the DNS cache of the LAN router of the infected node, enabling further attacks.” 911S5 initially responded to our reporting in 2022 by claiming it was conducting a top-down security review of the service. But the proxy service abruptly closed up shop just one week later, saying a malicious hacker had destroyed all of the company’s customer and payment records. In July 2024, The U.S. Department of the Treasury sanctioned the alleged creators of 911S5, and the U.S. Department of Justice arrested the Chinese national named in my 2022 profile of the proxy service. Kilmer said IPIDEA also operates a sister service called 922 Proxy, which the company has pitched from Day One as a seamless alternative to 911S5 Proxy. “You cannot tell me they don’t want the 911 customers by calling it that,” Kilmer said. Among the recipients of Synthient’s notification was the proxy giant Oxylabs. Brundage shared an email he received from Oxylabs’ security team on December 31, which acknowledged Oxylabs had started rolling out security modifications to address the vulnerabilities described in Synthient’s report. Reached for comment, Oxylabs confirmed they “have implemented changes that now eliminate the ability to bypass the blocklist and forward requests to private network addresses using a controlled domain.” But it said there is no evidence that Kimwolf or other other attackers exploited its network. “In parallel, we reviewed the domains identified in the reported exploitation activity and did not observe traffic associated with them,” the Oxylabs statement continued. “Based on this review, there is no indication that our residential network was impacted by these activities.” PRACTICAL IMPLICATIONS Consider the following scenario, in which the mere act of allowing someone to use your Wi-Fi network could lead to a Kimwolf botnet infection. In this example, a friend or family member comes to stay with you for a few days, and you grant them access to your Wi-Fi without knowing that their mobile phone is infected with an app that turns the device into a residential proxy node. At that point, your home’s public IP address will show up for rent at the website of some residential proxy provider. Miscreants like those behind Kimwolf then use residential proxy services online to access that proxy node on your IP, tunnel back through it and into your local area network (LAN), and automatically scan the internal network for devices with Android Debug Bridge mode turned on. By the time your guest has packed up their things, said their goodbyes and disconnected from your Wi-Fi, you now have two devices on your local network — a digital photo frame and an unsanctioned Android TV box — that are infected with Kimwolf. You may have never intended for these devices to be exposed to the larger Internet, and yet there you are. Here’s another possible nightmare scenario: Attackers use their access to proxy networks to modify your Internet router’s settings so that it relies on malicious DNS servers controlled by the attackers — allowing them to control where your Web browser goes when it requests a website. Think that’s far-fetched? Recall the DNSChanger malware from 2012 that infected more than a half-million routers with search-hijacking malware, and ultimately spawned an entire security industry working group focused on containing and eradicating it. XLAB Much of what is published so far on Kimwolf has come from the Chinese security firm XLab, which was the first to chronicle the rise of the Aisuru botnet in late 2024. In its latest blog post, XLab said it began tracking Kimwolf on October 24, when the botnet’s control servers were swamping Cloudflare’s DNS servers with lookups for the distinctive domain 14emeliaterracewestroxburyma02132[.]su. This domain and others connected to early Kimwolf variants spent several weeks topping Cloudflare’s chart of the Internet’s most sought-after domains, edging out Google.com and Apple.com of their rightful spots in the top 5 most-requested domains. That’s because during that time Kimwolf was asking its millions of bots to check in frequently using Cloudflare’s DNS servers. It is clear from reading the XLab report that KrebsOnSecurity (and security experts) probably erred in misattributing some of Kimwolf’s early activities to the Aisuru botnet, which appears to be operated by a different group entirely. IPDEA may have been truthful when it said it had no affiliation with the Aisuru botnet, but Brundage’s data left no doubt that its proxy service clearly was being massively abused by Aisuru’s Android variant, Kimwolf. XLab said Kimwolf has infected at least 1.8 million devices, and has shown it is able to rebuild itself quickly from scratch. “Analysis indicates that Kimwolf’s primary infection targets are TV boxes deployed in residential network environments,” XLab researchers wrote. “Since residential networks usually adopt dynamic IP allocation mechanisms, the public IPs of devices change over time, so the true scale of infected devices cannot be accurately measured solely by the quantity of IPs. In other words, the cumulative observation of 2.7 million IP addresses does not equate to 2.7 million infected devices.” XLab said measuring Kimwolf’s size also is difficult because infected devices are distributed across multiple global time zones. “Affected by time zone differences and usage habits (e.g., turning off devices at night, not using TV boxes during holidays, etc.), these devices are not online simultaneously, further increasing the difficulty of comprehensive observation through a single time window,” the blog post observed. XLab noted that the Kimwolf author shows an almost ‘obsessive’ fixation” on Yours Truly, apparently leaving “easter eggs” related to my name in multiple places through the botnet’s code and communications: ANALYSIS AND ADVICE One frustrating aspect of threats like Kimwolf is that in most cases it is not easy for the average user to determine if there are any devices on their internal network which may be vulnerable to threats like Kimwolf and/or already infected with residential proxy malware. Let’s assume that through years of security training or some dark magic you can successfully identify that residential proxy activity on your internal network was linked to a specific mobile device inside your house: From there, you’d still need to isolate and remove the app or unwanted component that is turning the device into a residential proxy. Also, the tooling and knowledge needed to achieve this kind of visibility just isn’t there from an average consumer standpoint. The work that it takes to configure your network so you can see and interpret logs of all traffic coming in and out is largely beyond the skillset of most Internet users (and, I’d wager, many security experts). But it’s a topic worth exploring in an upcoming story. Happily, Synthient has erected a page on its website that will state whether a visitor’s public Internet address was seen among those of Kimwolf-infected systems. Brundage also has compiled a list of the unofficial Android TV boxes that are most highly represented in the Kimwolf botnet. If you own a TV box that matches one of these model names and/or numbers, please just rip it out of your network. If you encounter one of these devices on the network of a family member or friend, send them a link to this story and explain that it’s not worth the potential hassle and harm created by keeping them plugged in. Chad Seaman is a principal security researcher with Akamai Technologies. Seaman said he wants more consumers to be wary of these pseudo Android TV boxes to the point where they avoid them altogether. “I want the consumer to be paranoid of these crappy devices and of these residential proxy schemes,” he said. “We need to highlight why they’re dangerous to everyone and to the individual. The whole security model where people think their LAN (Local Internal Network) is safe, that there aren’t any bad guys on the LAN so it can’t be that dangerous is just really outdated now.” “The idea that an app can enable this type of abuse on my network and other networks, that should really give you pause,” about which devices to allow onto your local network, Seaman said. “And it’s not just Android devices here. Some of these proxy services have SDKs for Mac and Windows, and the iPhone. It could be running something that inadvertently cracks open your network and lets countless random people inside.” In July 2025, Google filed a “John Doe” lawsuit (PDF) against 25 unidentified defendants collectively dubbed the “BadBox 2.0 Enterprise,” which Google described as a botnet of over ten million unsanctioned Android streaming devices engaged in advertising fraud. Google said the BADBOX 2.0 botnet, in addition to compromising multiple types of devices prior to purchase, also can infect devices by requiring the download of malicious apps from unofficial marketplaces. Google’s lawsuit came on the heels of a June 2025 advisory from the Federal Bureau of Investigation (FBI), which warned that cyber criminals were gaining unauthorized access to home networks by either configuring the products with malware prior to the user’s purchase, or infecting the device as it downloads required applications that contain backdoors — usually during the set-up process. The FBI said BADBOX 2.0 was discovered after the original BADBOX campaign was disrupted in 2024. The original BADBOX was identified in 2023, and primarily consisted of Android operating system devices that were compromised with backdoor malware prior to purchase. Lindsay Kaye is vice president of threat intelligence at HUMAN Security, a company that worked closely on the BADBOX investigations. Kaye said the BADBOX botnets and the residential proxy networks that rode on top of compromised devices were detected because they enabled a ridiculous amount of advertising fraud, as well as ticket scalping, retail fraud, account takeovers and content scraping. Kaye said consumers should stick to known brands when it comes to purchasing things that require a wired or wireless connection. “If people are asking what they can do to avoid being victimized by proxies, it’s safest to stick with name brands,” Kaye said. “Anything promising something for free or low-cost, or giving you something for nothing just isn’t worth it. And be careful about what apps you allow on your phone.” Many wireless routers these days make it relatively easy to deploy a “Guest” wireless network on-the-fly. Doing so allows your guests to browse the Internet just fine but it blocks their device from being able to talk to other devices on the local network — such as shared folders, printers and drives. If someone — a friend, family member, or contractor — requests access to your network, give them the guest Wi-Fi network credentials if you have that option. There is a small but vocal pro-piracy camp that is almost condescendingly dismissive of the security threats posed by these unsanctioned Android TV boxes. These tech purists positively chafe at the idea of people wholesale discarding one of these TV boxes. A common refrain from this camp is that Internet-connected devices are not inherently bad or good, and that even factory-infected boxes can be flashed with new firmware or custom ROMs that contain no known dodgy software. However, it’s important to point out that the majority of people buying these devices are not security or hardware experts; the devices are sought out because they dangle something of value for “free.” Most buyers have no idea of the bargain they’re making when plugging one of these dodgy TV boxes into their network. It is somewhat remarkable that we haven’t yet seen the entertainment industry applying more visible pressure on the major e-commerce vendors to stop peddling this insecure and actively malicious hardware that is largely made and marketed for video piracy. These TV boxes are a public nuisance for bundling malicious software while having no apparent security or authentication built-in, and these two qualities make them an attractive nuisance for cybercriminals. Further reading:
krebsonsecurity.comJan 2, 2026extracted
Tenzai Raises $75 Million in Seed Funding to Build AI-Powered Pentesting Platform
Cybersecurity startup Tenzai has emerged from stealth with $75 million in seed funding, one of the largest early-stage rounds reported in the sector. Tel Aviv, Israel based Tenzai has developed an AI-driven platform for penetration testing, which it says can continuously identify and address software vulnerabilities. The company aims to automate a process that has traditionally been manual and infrequent, a gap that has grown as software development accelerates with the use of AI-generated code and frequent production updates. The company was founded by a group of cybersecurity veterans: Pavel Gurvich, Ariel Zeitlin, Ofri Ziv, Itamar Tal, and Aner Mazur. Gurvich and Zeitlin previously co-founded Guardicore, which was acquired by Akamai Technologies in 2021 for $600 million. Mazur was formerly chief product officer at developer security firm Snyk. Tenzai says it is already piloting its platform with large organizations in the financial services, healthcare, and technology industries. “Pentesting hasn’t changed much since I was a pentester in high school some 25 years ago,” said Gurvich. “Back then the work was episodic and manual. Today, AI allows us to bring elite, nation-grade offensive capabilities at a scale and speed that were previously impossible. In large enterprises with hundreds of applications that change daily, providing real security assurance is only possible with autonomous AI that can find and fix vulnerabilities at enterprise scale. The funding was led by Greylock Partners, Battery Ventures, and Lux Capital, with additional participation from Swish Ventures and several individual investors. The additional cash will be used to expand its research and security teams and to support growth in North America and Europe.
securityweek.comNov 11, 2025extracted