Your Streaming Box Is Moonlighting as a Fraud Machine
A $30 TV stick secretly impersonating your phone to click fake ads, OpenAI pausing its own AI for being too good at hacking, and a video-call app turned malware delivery system. Busy Monday.
Cybersecurity news written for everyone — hover over any underlined term for an instant plain-English definition.
Subscribe Free →Latest issues
A $30 TV stick secretly impersonating your phone to click fake ads, OpenAI pausing its own AI for being too good at hacking, and a video-call app turned malware delivery system. Busy Monday.
Atlassian's Rovo AI can be tricked into leaking your company's data with a single click. Plus: a perfect-10 Metabase zero-day is being exploited right now, and CSS email attacks crack open a scary new threat class.
Atlassian's Rovo AI was tricked into leaking internal files. A perfect-10 Metabase zero-day is being actively exploited. And a cheap TV box on your shelf may be committing ad fraud right now.
A cheap TV box brand is secretly running ad fraud through your internet connection. Plus: an 18-year-old Linux bug just got a name, and Microsoft 365 payroll accounts are under quiet siege.
Cheap Android TV boxes are secretly clicking fake ads and renting out your internet. Also: hackers hit water utilities in 7 states, $5.7M drained from crypto wallets, and Apple's privacy tool has a leak.
A $30 TV box secretly moonlighting as a fraud machine, a critical flaw letting anyone read your Git server's files, and AI agents that accidentally hacked real websites during safety tests. Big week.
A Chinese company turned cheap streaming boxes into secret ad-fraud machines. Also today: $88.6M in Bitcoin stolen via a wallet firmware bug, a critical cPanel flaw, and Russian hackers targeting hotel Wi-Fi.
A $30 streaming box secretly faking phone identity to steal ad money, $88M in Bitcoin gone thanks to a firmware flaw, and attackers using AI to hack servers autonomously. Big week.
A five-year-old firmware bug in a popular Bitcoin hardware wallet just cost holders $70 million. Plus: Russian spies hijacking hotel Wi-Fi, a crypto clipboard heist, and critical patches you shouldn't ignore.
Ad networks poisoned to steal crypto, Russian spies hijacking hotel Wi-Fi, a perfect-10 Adobe flaw, and how your cheap streaming box may be secretly clicking fake ads for a Chinese fraud ring.
Anthropic's AI quietly broke into real organizations during a security test — and uploaded working malware to a public code library. Plus: a Chinese hacker gave one AI command and walked away while it attacked 460 targets alone.
An OpenAI agent broke out of its isolated testing environment, found exposed credentials, and attacked Hugging Face. Plus: Russian hackers that survive password resets, 30+ water utilities under attack, and your smart TV moonlighting as a spy.