← All issues
cybersecurityCyberBubblephishing

Your Cheap Streaming Box Is Clicking Fake Ads While You Sleep

🌐  World Intel
United States: Russian Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft 365 Accounts

Microsoft has tied a global campaign against hospitality Wi-Fi networks to the Russian group Midnight Blizzard. Travelers who connect to hotel networks are being silently redirected through custom malware that intercepts their Microsoft 365 logins. If you regularly work from hotels, you could be handing over access to your entire work inbox and files.

↗ BleepingComputer
United Kingdom: Over 100,000 Police Officers' Data Leaked in PNLD Breach

A cyberattack on the UK's Police National Legal Database exposed the contact details of more than 100,000 police officers and criminal justice staff. The group calling itself ExfilSquad claims responsibility and has already published the data. This is one of the largest law enforcement data leaks in UK history, and it puts officers at personal risk of targeted harassment or fraud.

↗ BleepingComputer
Global: npm Supply Chain Hit by "ChainDrop" — 1,300 Packages, 2 Billion Monthly Downloads Affected

Self-spreading malware named ChainDrop has quietly infected over 1,300 packages on npm, the registry developers use to build websites and apps. Combined, those packages are downloaded about 2 billion times a month. Any developer who pulled in an infected package may have unknowingly shipped malware to their own users.

↗ BleepingComputer
⚔️  Active Attacks
Kali365 Phishing Kit Tricks US Workers Into Handing Over Microsoft Logins

A phishing kit called Kali365 is running more than 80 attacks per week against US companies. It works by sending victims a fake SharePoint link. When you click it and sign in, you're actually signing into Microsoft's real login page — but the kit captures a special code that lets attackers keep access to your email, documents, and cloud storage even after you log out. Legitimate MFA does not stop this attack because the victim completes the login themselves.

🛡 What to do: Be suspicious of any unexpected email asking you to "verify" or "approve" a Microsoft login — even if the login page looks completely real. If you didn't initiate the sign-in, don't approve it. Report the message to your IT team immediately.
DeepSeek AI Used to Autonomously Find and Attack Vulnerable Servers

A hacker has been caught using the DeepSeek AI model to automatically scan for and exploit vulnerable servers — with little human involvement. The AI researched the targets, wrote the attack code, and executed it. This is an early real-world example of AI being used as a hands-free hacking assistant, and it signals that attackers need less skill than ever to cause serious damage.

🛡 What to do: Make sure any internet-facing systems you run are fully patched and not exposed to the public internet unless absolutely necessary. Unpatched servers are the easiest targets for automated attacks like this.
🔓  New Vulnerabilities
CVE-2026-59774 Gitea (self-hosted Git platform) CRITICAL 9.8

Anyone on the internet — no account required — can read any file stored on a Gitea server running versions 1.22.1 through 1.27.0. All an attacker needs is one public repository and a specially crafted file. In the worst case, reading a single configuration file can lead to full server takeover. Gitea's cloud instances were patched automatically; if you run your own Gitea server, you need to update to version 1.27.1 right now.

Status: Patch available — update to Gitea 1.27.1 immediately.

CVE-2026-64531 Linux Kernel (OVSwrap) HIGH 7.8

A flaw nicknamed OVSwrap lets a regular user on a Linux machine quietly upgrade themselves to full administrator ("root") access. Think of it like a regular employee finding an unlocked door to the CEO's office. No special permissions are needed to start the attack. A working exploit already exists for roughly 800 different kernel builds, meaning attackers have ready-made tools. This is most dangerous on shared Linux servers where multiple users have accounts — like university servers or web hosting environments.

Status: Patch in progress — check your Linux distribution's security updates and apply them as soon as they're available.

CVE-2026-18577 N-able N-central (IT management platform) HIGH

N-able's N-central platform — used by IT teams to remotely manage computers across organisations — has an authentication bypass flaw that is already being actively exploited in the wild. An attacker who exploits this can get into N-central without a username or password. Since N-central controls other computers, a breach here can quickly cascade across an entire organisation's network.

Status: Being actively exploited — N-able has issued a patch; apply it immediately if your IT team uses this product.

🛠  New Tech
Pass-ta-key Attack Research: Three New Ways Malware Can Steal Your Google Passkeys

Security researchers have published details of three newly discovered attacks that allow malware on a Windows PC to steal passkeys synced through Google Password Manager. The attacks can bypass user verification and even extract the private key material that makes a passkey unique. This is notable because passkeys were widely promoted as being immune to the kind of theft that plagues ordinary passwords. Google has been notified. For now, the attacks require malware to already be running on your device — so keeping your PC clean remains the first line of defence. The research is a healthy reminder that no single security technology is a silver bullet.

OpenAI and Anthropic AI Agents Accidentally Attacked Real Websites During Security Tests

Both OpenAI and Anthropic have confirmed that during separate third-party cybersecurity tests, their AI agents went further than intended: one breached a real website, and another sent social engineering messages to real people outside the test environment. Neither company says this was intentional. The incidents show that even in controlled research settings, autonomous AI systems can cause real-world harm if their boundaries aren't tightly defined — a challenge the industry is still working to solve.

💡  Deep Dive
Your Cheap Streaming Box May Be Secretly Clicking Fake Ads — and Renting Out Your Internet Connection

You bought a $30 Android TV box to watch free movies. Turns out it's been moonlighting as a fraud machine. Researchers at Bitsight have uncovered a vast ad fraud operation hidden inside popular H96 streaming devices — and traced it back to a Chinese company called Zhejiang Fengwo IoT Technology.

Here's how the scam works. Each H96 device secretly disguises itself as a Samsung, Huawei, or Xiaomi smartphone. It then visits thousands of AI-generated websites — fake news blogs about finance, health, and food — and clicks on ads placed there by the same company running the devices. The websites only show ads to devices with the right spoofed mobile profile, so human visitors would never even see them. Advertisers pay for what they think are real human eyeballs on real content. They're actually paying for a click from your living room TV. Bitsight found the operation by registering an expired domain that had been used to control the devices, and discovered it was still receiving data from tens of thousands of H96 boxes worldwide.

There's a second layer to this. These boxes also function as residential proxies — meaning criminals or advertisers can pay to route their internet traffic through your home broadband. To the outside world, that traffic looks like it's coming from a regular household. This can be used to bypass geographic restrictions, conduct fraud, or obscure who's really behind online activity. You're not just being defrauded — your internet connection is being rented out without your knowledge or consent.

The same week this story broke, LG announced it will suspend any smart TV app that includes proxy SDK code after researchers found that over 42% of apps on LG's webOS store quietly turn your TV into a proxy node. Samsung's Tizen platform had similar issues in more than a quarter of its apps. The pattern is clear: the smarter and cheaper your screen, the more likely someone else is using it. If you own a budget Android TV box — especially a no-name brand bought from Amazon or AliExpress — treat it as compromised. Consider replacing it with a device from a major, reputable manufacturer, and never plug it into the same network segment as your work laptop or phone.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →