← All issues
cybersecurityCyberBubbleransomware

Your $30 Streaming Box Is Moonlighting for Criminals

🌐  World Intel
UK: Two Scattered Spider Members Plead Guilty Over Transport for London Hack

Thalha Jubair, 20, and Owen Flowers, 18, admitted in a UK court this week to hacking Transport for London in August 2024 — the attack that knocked out services for millions of commuters. The pair are members of Scattered Spider, a group linked to over 120 breaches and at least $115 million in ransom payments from US companies alone. Flowers is also tied to the 2023 attacks on MGM Resorts and Caesars casinos in Las Vegas, and separately admitted hacking two US healthcare systems.

↗ Krebs on Security
India: Tata Electronics Hit by Cyberattack, Customer Data Leaked

Tata Electronics — part of one of India's largest conglomerates — confirmed it was the target of a cyberattack that damaged parts of its IT systems. Hackers have already begun leaking data stolen in the breach. The incident follows a pattern of attackers going after large manufacturers and supply-chain companies to maximize disruption and ransom leverage.

↗ BleepingComputer
Global: Amadey and StealC Malware Networks Disrupted in Operation Endgame

Microsoft, Europol, and international law enforcement partners took down infrastructure supporting the StealC and Amadey botnets as part of Operation Endgame, an ongoing effort to dismantle cybercrime services. Both tools are widely rented out to other criminals to steal credentials and drop ransomware. Taking down this shared infrastructure makes life harder for dozens of criminal groups at once.

↗ BleepingComputer
⚔️  Active Attacks
FortiBleed: Hackers Used a Custom Tool to Silently Steal Firewall Credentials

A campaign dubbed "FortiBleed" planted a custom packet sniffer on Fortinet FortiGate firewalls to vacuum up login credentials in real time. Attackers targeted the devices — which sit at the edge of corporate networks and are responsible for controlling who gets in — meaning stolen credentials could open doors to entire organizations. CISA has separately urged all organizations to harden their Fortinet devices after widespread reports of credential exposure.

🛡 What to do: If your organization uses Fortinet firewalls, follow CISA's June 18 hardening guidance immediately, rotate any credentials that may have touched those devices, and check for unauthorized configuration changes.
Malicious Browser Extension "Edgecution" Breaks Out of the Browser to Deploy Malware

A fake Microsoft Edge browser extension called "Edgecution" was used in a real ransomware attack. It escaped the browser's built-in security walls using a technique called Native Messaging, then dropped a Python-based backdoor onto the victim's machine. Most people assume browser extensions are low-risk — this attack shows a malicious one can be a full entry point for ransomware.

🛡 What to do: Review the extensions installed in your browser and remove any you don't recognize or no longer use. Only install extensions from official stores, and check their reviews and publisher before installing.
🔓  New Vulnerabilities
CVE-2026-20245 Cisco Catalyst SD-WAN HIGH 7.8

This flaw lets an authenticated attacker run commands as the most powerful user (root) on Cisco's SD-WAN devices. Cisco confirmed the bug was being actively exploited as a zero-day — meaning attackers were using it at least two months before Cisco publicly admitted it existed. Google's Mandiant team found that the attackers carefully covered their tracks by deleting and restoring system files to avoid detection.

Status: Patch now available. Apply Cisco's update immediately if your organization uses Catalyst SD-WAN.

CVE-2026-LANT Lantronix EDS5000 Series CRITICAL

CISA issued an emergency warning about a critical flaw in Lantronix EDS5000 serial-to-ethernet servers. These devices are common in industrial and government environments, and the vulnerability is being actively exploited right now. Federal agencies have until June 26, 2026 — tomorrow — to apply the fix.

Status: Patch available. Federal agencies must patch by June 26. If your organization uses Lantronix EDS5000 devices, treat this as urgent.

CVE-2026-20230 Cisco Unified Communications Manager HIGH

A second Cisco vulnerability, this one in Unified Communications Manager (the software that runs business phone systems), is now being actively exploited. The flaw is an SSRF vulnerability — attackers can trick the server into reaching out to internal systems it shouldn't be able to touch, potentially exposing sensitive internal resources.

Status: Patch available from Cisco. If your company uses Cisco Unified CM for office phones or video calls, apply the update now.

🛠  New Tech
LastPass Breach Traced Back to a Supply Chain Attack on Klue

LastPass — the password manager that has had a rough few years — confirmed a new data breach. This time, attackers didn't go after LastPass directly. Instead, they compromised Klue, a third-party software vendor that LastPass uses, and used that access as a back door. This is called a supply chain attack, and it's increasingly the preferred method for reaching well-defended companies. The incident is a reminder that your security is only as strong as the weakest vendor in your software stack. If you use LastPass, watch for official communication about what data was affected and consider updating your master password.

💡  Deep Dive
Your Cheap Streaming Box Might Be Working a Second Job — For Criminals

You paid $30 for a no-name Android TV box online. It streams movies. It sits plugged in 24 hours a day. And according to new research, there's a good chance it's also quietly routing internet traffic for cybercriminals — without you ever knowing.

Researchers this week confirmed that a massive botnet called Popa — linked to a residential proxy provider called NetNut, operated by publicly-traded Israeli firm Alarum Technologies — has been running on millions of unofficial Android TV boxes worldwide for at least four years. These cheap streaming devices, sold under thousands of brand names on Amazon and similar sites, come pre-loaded with software that quietly enrolls your home internet address into a for-hire proxy network. That means anyone — including scammers, fraudsters, and hackers — can pay to make their internet traffic appear to come from your home address. Researchers at Qurium discovered the network while investigating a wave of data-scraping attacks that spread activity across more than 1.4 million IP addresses in a single month.

For regular people, the risk is real and underappreciated. Having your home IP address used for criminal activity could get you flagged by websites, put on blocklists, or — in serious cases — draw unwanted attention from law enforcement who see your address associated with suspicious activity. Worse, some of these proxy networks give paying customers the ability to probe and potentially compromise other devices on your home Wi-Fi network — your laptop, your phone, your smart home gadgets.

The simplest protection: avoid cheap, unofficial Android TV streaming boxes entirely. If you already own one, unplug it and replace it with a device from a known brand like Apple TV, Roku, or Amazon Fire TV. The FBI has previously warned about exactly these kinds of devices, and this week's research confirms the warning still stands. If a streaming box promises "free" access to every subscription service for a one-time low fee, the real cost is your home network.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →