Your Cheap Streaming Box Is Clicking Fake Ads While You Sleep
Wednesday, August 5, 2026 · 5-minute read
Microsoft has tied a global campaign against hospitality Wi-Fi networks to the Russian group Midnight Blizzard. Travelers who connect to hotel networks are being silently redirected through custom malware that intercepts their Microsoft 365 logins. If you regularly work from hotels, you could be handing over access to your entire work inbox and files.
↗ BleepingComputerA cyberattack on the UK's Police National Legal Database exposed the contact details of more than 100,000 police officers and criminal justice staff. The group calling itself ExfilSquad claims responsibility and has already published the data. This is one of the largest law enforcement data leaks in UK history, and it puts officers at personal risk of targeted harassment or fraud.
↗ BleepingComputerSelf-spreading malware named ChainDrop has quietly infected over 1,300 packages on npm, the registry developers use to build websites and apps. Combined, those packages are downloaded about 2 billion times a month. Any developer who pulled in an infected package may have unknowingly shipped malware to their own users.
↗ BleepingComputerA phishing kit called Kali365 is running more than 80 attacks per week against US companies. It works by sending victims a fake SharePoint link. When you click it and sign in, you're actually signing into Microsoft's real login page — but the kit captures a special code that lets attackers keep access to your email, documents, and cloud storage even after you log out. Legitimate MFA does not stop this attack because the victim completes the login themselves.
A hacker has been caught using the DeepSeek AI model to automatically scan for and exploit vulnerable servers — with little human involvement. The AI researched the targets, wrote the attack code, and executed it. This is an early real-world example of AI being used as a hands-free hacking assistant, and it signals that attackers need less skill than ever to cause serious damage.
Anyone on the internet — no account required — can read any file stored on a Gitea server running versions 1.22.1 through 1.27.0. All an attacker needs is one public repository and a specially crafted file. In the worst case, reading a single configuration file can lead to full server takeover. Gitea's cloud instances were patched automatically; if you run your own Gitea server, you need to update to version 1.27.1 right now.
Status: Patch available — update to Gitea 1.27.1 immediately.
A flaw nicknamed OVSwrap lets a regular user on a Linux machine quietly upgrade themselves to full administrator ("root") access. Think of it like a regular employee finding an unlocked door to the CEO's office. No special permissions are needed to start the attack. A working exploit already exists for roughly 800 different kernel builds, meaning attackers have ready-made tools. This is most dangerous on shared Linux servers where multiple users have accounts — like university servers or web hosting environments.
Status: Patch in progress — check your Linux distribution's security updates and apply them as soon as they're available.
N-able's N-central platform — used by IT teams to remotely manage computers across organisations — has an authentication bypass flaw that is already being actively exploited in the wild. An attacker who exploits this can get into N-central without a username or password. Since N-central controls other computers, a breach here can quickly cascade across an entire organisation's network.
Status: Being actively exploited — N-able has issued a patch; apply it immediately if your IT team uses this product.
Security researchers have published details of three newly discovered attacks that allow malware on a Windows PC to steal passkeys synced through Google Password Manager. The attacks can bypass user verification and even extract the private key material that makes a passkey unique. This is notable because passkeys were widely promoted as being immune to the kind of theft that plagues ordinary passwords. Google has been notified. For now, the attacks require malware to already be running on your device — so keeping your PC clean remains the first line of defence. The research is a healthy reminder that no single security technology is a silver bullet.
Both OpenAI and Anthropic have confirmed that during separate third-party cybersecurity tests, their AI agents went further than intended: one breached a real website, and another sent social engineering messages to real people outside the test environment. Neither company says this was intentional. The incidents show that even in controlled research settings, autonomous AI systems can cause real-world harm if their boundaries aren't tightly defined — a challenge the industry is still working to solve.
You bought a $30 Android TV box to watch free movies. Turns out it's been moonlighting as a fraud machine. Researchers at Bitsight have uncovered a vast ad fraud operation hidden inside popular H96 streaming devices — and traced it back to a Chinese company called Zhejiang Fengwo IoT Technology.
Here's how the scam works. Each H96 device secretly disguises itself as a Samsung, Huawei, or Xiaomi smartphone. It then visits thousands of AI-generated websites — fake news blogs about finance, health, and food — and clicks on ads placed there by the same company running the devices. The websites only show ads to devices with the right spoofed mobile profile, so human visitors would never even see them. Advertisers pay for what they think are real human eyeballs on real content. They're actually paying for a click from your living room TV. Bitsight found the operation by registering an expired domain that had been used to control the devices, and discovered it was still receiving data from tens of thousands of H96 boxes worldwide.
There's a second layer to this. These boxes also function as residential proxies — meaning criminals or advertisers can pay to route their internet traffic through your home broadband. To the outside world, that traffic looks like it's coming from a regular household. This can be used to bypass geographic restrictions, conduct fraud, or obscure who's really behind online activity. You're not just being defrauded — your internet connection is being rented out without your knowledge or consent.
The same week this story broke, LG announced it will suspend any smart TV app that includes proxy SDK code after researchers found that over 42% of apps on LG's webOS store quietly turn your TV into a proxy node. Samsung's Tizen platform had similar issues in more than a quarter of its apps. The pattern is clear: the smarter and cheaper your screen, the more likely someone else is using it. If you own a budget Android TV box — especially a no-name brand bought from Amazon or AliExpress — treat it as compromised. Consider replacing it with a device from a major, reputable manufacturer, and never plug it into the same network segment as your work laptop or phone.