Your $30 Streaming Box Is Moonlighting for Criminals
Thursday, June 25, 2026 · 5-minute read
Thalha Jubair, 20, and Owen Flowers, 18, admitted in a UK court this week to hacking Transport for London in August 2024 — the attack that knocked out services for millions of commuters. The pair are members of Scattered Spider, a group linked to over 120 breaches and at least $115 million in ransom payments from US companies alone. Flowers is also tied to the 2023 attacks on MGM Resorts and Caesars casinos in Las Vegas, and separately admitted hacking two US healthcare systems.
↗ Krebs on SecurityTata Electronics — part of one of India's largest conglomerates — confirmed it was the target of a cyberattack that damaged parts of its IT systems. Hackers have already begun leaking data stolen in the breach. The incident follows a pattern of attackers going after large manufacturers and supply-chain companies to maximize disruption and ransom leverage.
↗ BleepingComputerMicrosoft, Europol, and international law enforcement partners took down infrastructure supporting the StealC and Amadey botnets as part of Operation Endgame, an ongoing effort to dismantle cybercrime services. Both tools are widely rented out to other criminals to steal credentials and drop ransomware. Taking down this shared infrastructure makes life harder for dozens of criminal groups at once.
↗ BleepingComputerA campaign dubbed "FortiBleed" planted a custom packet sniffer on Fortinet FortiGate firewalls to vacuum up login credentials in real time. Attackers targeted the devices — which sit at the edge of corporate networks and are responsible for controlling who gets in — meaning stolen credentials could open doors to entire organizations. CISA has separately urged all organizations to harden their Fortinet devices after widespread reports of credential exposure.
A fake Microsoft Edge browser extension called "Edgecution" was used in a real ransomware attack. It escaped the browser's built-in security walls using a technique called Native Messaging, then dropped a Python-based backdoor onto the victim's machine. Most people assume browser extensions are low-risk — this attack shows a malicious one can be a full entry point for ransomware.
This flaw lets an authenticated attacker run commands as the most powerful user (root) on Cisco's SD-WAN devices. Cisco confirmed the bug was being actively exploited as a zero-day — meaning attackers were using it at least two months before Cisco publicly admitted it existed. Google's Mandiant team found that the attackers carefully covered their tracks by deleting and restoring system files to avoid detection.
Status: Patch now available. Apply Cisco's update immediately if your organization uses Catalyst SD-WAN.
CISA issued an emergency warning about a critical flaw in Lantronix EDS5000 serial-to-ethernet servers. These devices are common in industrial and government environments, and the vulnerability is being actively exploited right now. Federal agencies have until June 26, 2026 — tomorrow — to apply the fix.
Status: Patch available. Federal agencies must patch by June 26. If your organization uses Lantronix EDS5000 devices, treat this as urgent.
A second Cisco vulnerability, this one in Unified Communications Manager (the software that runs business phone systems), is now being actively exploited. The flaw is an SSRF vulnerability — attackers can trick the server into reaching out to internal systems it shouldn't be able to touch, potentially exposing sensitive internal resources.
Status: Patch available from Cisco. If your company uses Cisco Unified CM for office phones or video calls, apply the update now.
LastPass — the password manager that has had a rough few years — confirmed a new data breach. This time, attackers didn't go after LastPass directly. Instead, they compromised Klue, a third-party software vendor that LastPass uses, and used that access as a back door. This is called a supply chain attack, and it's increasingly the preferred method for reaching well-defended companies. The incident is a reminder that your security is only as strong as the weakest vendor in your software stack. If you use LastPass, watch for official communication about what data was affected and consider updating your master password.
You paid $30 for a no-name Android TV box online. It streams movies. It sits plugged in 24 hours a day. And according to new research, there's a good chance it's also quietly routing internet traffic for cybercriminals — without you ever knowing.
Researchers this week confirmed that a massive botnet called Popa — linked to a residential proxy provider called NetNut, operated by publicly-traded Israeli firm Alarum Technologies — has been running on millions of unofficial Android TV boxes worldwide for at least four years. These cheap streaming devices, sold under thousands of brand names on Amazon and similar sites, come pre-loaded with software that quietly enrolls your home internet address into a for-hire proxy network. That means anyone — including scammers, fraudsters, and hackers — can pay to make their internet traffic appear to come from your home address. Researchers at Qurium discovered the network while investigating a wave of data-scraping attacks that spread activity across more than 1.4 million IP addresses in a single month.
For regular people, the risk is real and underappreciated. Having your home IP address used for criminal activity could get you flagged by websites, put on blocklists, or — in serious cases — draw unwanted attention from law enforcement who see your address associated with suspicious activity. Worse, some of these proxy networks give paying customers the ability to probe and potentially compromise other devices on your home Wi-Fi network — your laptop, your phone, your smart home gadgets.
The simplest protection: avoid cheap, unofficial Android TV streaming boxes entirely. If you already own one, unplug it and replace it with a device from a known brand like Apple TV, Roku, or Amazon Fire TV. The FBI has previously warned about exactly these kinds of devices, and this week's research confirms the warning still stands. If a streaming box promises "free" access to every subscription service for a one-time low fee, the real cost is your home network.