← All issues
cybersecurityCyberBubblesmart-tv-privacy

Your Smart TV Is Running a Proxy Side Hustle — Plus Two 10/10 Bugs to Patch Now

🌐  World Intel
Middle East & Africa: Iranian Hackers Turn Victims Into Spy Relays

An Iranian government-backed hacking group called Nimbus Manticore has been caught running a fresh wave of attacks across the Middle East, Africa, and South Asia. They deployed a new backdoor called NightLedger on Windows machines, which can take screenshots, run commands, and quietly map out the infected network. Alongside that, they installed two custom tools — ArcBridge and BridgeHead — that turn compromised machines into covert relay nodes, making the attackers' traffic much harder to trace.

Targets include government offices in Jordan, telecom companies in Ethiopia, aviation firms in Pakistan, and financial institutions in Burkina Faso. Kaspersky researchers published the findings today.

↗ The Hacker News
Russia: State Hackers Phishing Zimbra Email Users

CISA issued a formal advisory last week warning that Russian state-sponsored hackers are running a phishing campaign aimed at users of Zimbra Collaboration Suite, a popular email and calendar platform used widely by governments and businesses. The goal appears to be stealing login credentials to get inside targeted organizations. CISA's advisory (AA26-204A) urges Zimbra administrators to harden their setups and watch for suspicious login activity.

↗ CISA
Global: Dysphoria Botnet Hits 200,000 Devices Worldwide

A newly discovered botnet called Dysphoria has infected roughly 200,000 devices across the world. Attackers are using the network to launch DDoS attacks and route their own internet traffic through victims' machines to hide their tracks. BleepingComputer reported the story on Sunday, and the scale of the infection makes this one of the larger botnets seen so far this year.

↗ BleepingComputer
⚔️  Active Attacks
Network Gear Under Fire: Arista VeloCloud Orchestrator Being Actively Exploited

Attackers are actively exploiting a perfect-10 severity flaw in Arista VeloCloud Orchestrator, software that many businesses use to manage their SD-WAN networks. The bug is a command injection flaw — meaning an attacker can send specially crafted web requests to the server and make it run any command they want, without needing a password. A successful attack could give criminals full control of the orchestrator and every network it manages. Arista has patched hosted versions already, but on-premises installations need a manual update now.

CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on July 27, confirming real-world attacks are happening.

🛡 What to do: If your organization runs Arista VeloCloud Orchestrator on-premises, apply Arista's patch immediately. Contact your network vendor or IT team today — do not wait for a scheduled maintenance window.
Hotel Wi-Fi Hijack: Hackers Stealing Microsoft 365 Accounts at Hotels

Hackers are tampering with hotel Wi-Fi networks by hijacking their DNS settings. When guests connect and try to visit Microsoft 365 or other services, they get silently redirected to fake login pages that steal their username and password. The attack is stealthy — the hotel Wi-Fi appears to work normally, and the victim has no obvious sign anything went wrong. Business travelers logging into work email are the most likely targets.

🛡 What to do: Avoid logging into work accounts on hotel Wi-Fi. Use your phone's mobile data or a trusted VPN instead. Enable multi-factor authentication on all important accounts so a stolen password alone isn't enough to break in.
🔓  New Vulnerabilities
CVE-2026-16812 Arista VeloCloud Orchestrator CRITICAL 10.0

A maximum-severity command injection bug in Arista's VeloCloud Orchestrator. An attacker anywhere on the internet can send crafted requests to the server, bypass all authentication, and run any command they like on the underlying machine. That means full takeover of the device and the networks it manages. Active exploitation confirmed in the wild.

Status: Patch available. Hosted versions already updated by Arista. On-premises customers must update manually — check Arista's advisory for affected versions (VCO 5.2.x and related branches).

CVE-2026-63077 JetBrains TeamCity On-Premises CRITICAL 9.8

JetBrains TeamCity is a popular build and deployment tool used by software development teams. This flaw lets an attacker who isn't logged in at all send requests over HTTP/HTTPS that trick the server into skipping its login checks entirely — then run any operating system command they want with the same permissions the server itself has. Discovered July 10 and patched quickly, but all on-premises versions are affected until updated.

Status: Patch available in versions 2025.11.7 and 2026.1.3. TeamCity Cloud was already updated automatically.

CVE-2026-53264 Linux Kernel (CentOS Stream 9) HIGH 7.8

A researcher used AI to help find and exploit a use-after-free flaw in the Linux kernel's network traffic-control code. On a vulnerable system, a regular local user could escalate their privileges all the way to root — full administrator control. The full exploit code is now public, lowering the bar for copycats. Importantly, this requires the attacker to already have a local account on the machine, so it is not remotely exploitable on its own.

Status: Upstream fix landed June 1, 2026, and has been backported to several stable kernel branches. Update your Linux kernel packages via your distribution's package manager.

🛠  New Tech
Microsoft MDASH Gets Its First Purpose-Built Cybersecurity AI Model

Microsoft has added a new AI model called MAI-Cyber-1-Flash to its MDASH platform — a system designed to automatically find and help fix security vulnerabilities in software. Paired with GPT-5.4, the combination scored 95.95% on a standard security benchmark called CyberGym, which tests whether an AI can reproduce known software vulnerabilities from their descriptions. Microsoft claims this setup costs 50% less than its previous best configuration. The idea is that MAI-Cyber-1-Flash handles the routine 90% of tasks cheaply and quickly, while the more powerful GPT-5.4 steps in only for the hardest problems. The model is not available to the public — it runs exclusively inside MDASH for approved customers through a private Azure preview.

GitHub and PyPI Add Time-Based Defenses Against Supply Chain Attacks

GitHub and PyPI — the main repository where Python software packages live — have introduced a new time-based protection inside the Dependabot dependency management tool. The mechanism puts guardrails around how quickly a newly published or altered package can be automatically pulled into projects, giving security teams a window to catch suspicious changes before they spread. Supply chain attacks — where attackers sneak malicious code into trusted developer tools — have caused some of the biggest breaches of recent years. This is a practical, low-friction step toward making that much harder to pull off at scale.

💡  Deep Dive
Your Smart TV May Be Running a Secret Internet Business — And LG Is Finally Cracking Down

Imagine renting out your home's front door to strangers without knowing it. That's roughly what has been happening to millions of LG smart TV owners — and the company just announced it's putting a stop to it.

Security researchers at Spur discovered that more than 42% of apps available on LG's webOS app store include hidden SDKs that quietly enroll your TV into a residential proxy network. In plain terms: your TV's internet connection gets rented out to third parties — businesses, researchers, or potentially bad actors — who use it to browse the web as if they were sitting in your living room. Samsung's Tizen platform had a similar problem, with over a quarter of its apps carrying the same hidden software. The apps doing this ranged from a Pac-Man game to screensavers to file utilities. Many gave users a choice between watching ads or "consenting" to proxy enrollment — but the consent was buried in terms most people never read.

Why does this matter? A residential proxy that runs through your home IP address can be used to bypass geographic restrictions, scrape websites, commit ad fraud, or make malicious traffic harder to trace back to the real perpetrators. Your internet connection gets the blame, not theirs. For most households the practical risk is slow streaming or a flagged IP address, but the principle — that an app on your TV can silently monetize your bandwidth without meaningful consent — is a serious one.

LG's Senior Vice President John Taylor told Krebs on Security that apps failing to remove the proxy option will be suspended from the webOS store, and that the review process is already underway. It's a meaningful response, but the broader lesson is this: smart TVs are full computers running third-party code, and the app stores governing them have historically had far weaker security reviews than your phone's app store. Worth checking what's installed on yours.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →