← All issues
cybersecurityCyberBubblebotnet

Your Smart TV Was a Crime Tool: FBI Takes Down NetNut's 2M-Device Botnet

🌐  World Intel
North Korea: 108 Fake Code Packages Caught Stealing Developer Secrets

North Korean hackers published 108 malicious packages across popular developer platforms including npm, Go, and even the Chrome extension store. The campaign — dubbed PolinRider — is an extension of a long-running North Korean operation that targets software developers, often posing as job recruiters. Researchers warn that new poisoned packages keep appearing because the attackers are hijacking legitimate developer accounts to publish infected code — making the bad stuff harder to spot.

↗ The Hacker News
UK: Two Scattered Spider Members Plead Guilty Over Transport for London Hack

Two young British men — Owen Flowers, 18, and Thalha Jubair, 20 — pleaded guilty on the first day of their trial for hacking Transport for London in August 2024. They are members of Scattered Spider, a group also linked to the 2023 MGM Resorts casino attack and breaches of UK retailers Marks & Spencer and Harrods. Jubair is also wanted in the US, where prosecutors allege Scattered Spider extorted at least $115 million in ransom payments from 47 American organizations.

↗ Krebs on Security
USA: FBI Seizes NetNut Proxy Network Tied to 2 Million Hacked Home Devices

The FBI, with help from Google and other partners, seized hundreds of domains belonging to NetNut — a commercial proxy service run by Israeli company Alarum Technologies. Security firms found that NetNut secretly turned millions of home smart TVs and streaming boxes into proxy nodes, renting their internet connections to cybercriminals for fraud, scraping, and account takeovers. In a single week in June, Google spotted 316 separate criminal groups using NetNut exit nodes to hide their tracks.

↗ Krebs on Security
⚔️  Active Attacks
Avalon Malware: One Email Opens the Door to Ransomware, Credential Theft, and a Backdoor

A newly discovered malware framework called Avalon arrives as a fake legal document email. The email points victims to a password-protected archive on Proton Drive. Inside is an ISO image containing a disguised shortcut file. Clicking it quietly installs a multi-stage attack tool that can steal passwords, spread through a company network, block recovery, and finally deploy ransomware called CrownX. The ISO packaging is intentional — it slips past most email security scanners without triggering any alerts.

🛡 What to do: Never open password-protected archives sent by email, even if the sender looks official. Legitimate legal and business documents don't arrive this way. If in doubt, call the sender directly to verify.
FortiBleed Credential Theft Now Fueling Lynx and INC Ransomware Attacks

The FortiBleed campaign — which scooped up login credentials from Fortinet networking devices — has been directly linked to two active ransomware-as-a-service operations: Lynx and INC. Attackers used the stolen credentials to quietly log in to company networks through legitimate accounts, making their access very hard to detect. Organizations that use Fortinet devices and haven't rotated passwords since the FortiBleed disclosure are at serious risk right now.

🛡 What to do: If your workplace uses Fortinet firewalls or VPNs, ask your IT team to confirm that all admin passwords were changed after the FortiBleed disclosure in June. Don't assume it's been done.
🔓  New Vulnerabilities
CVE-2026-46242 Linux Kernel / Android — "Bad Epoll" CRITICAL

A flaw in the Linux kernel lets any normal user — no special privileges needed — take full control of a computer as the all-powerful "root" administrator. It affects Linux desktops, servers, and Android phones. The bug is in a feature called Epoll, which almost every program uses to handle multiple tasks at once, so you can't simply disable it. A working attack has already been demonstrated by the researcher who found it.

Status: Patch available — apply Linux kernel updates and Android security patches now. Check your phone manufacturer's update channel for Android fixes.

Multiple CVEs FatFs Library — Embedded Devices (cameras, drones, ATMs, USB devices) CRITICAL

Seven vulnerabilities were found in FatFs, a tiny piece of code built into the firmware of millions of embedded devices — security cameras, drones, industrial controllers, hardware crypto wallets, and more. An attacker with brief physical access can plug in a booby-trapped USB drive or SD card and take complete control of the device. Public kiosks, ATMs, voting machines, and any camera with a card slot could all be affected. Many of these devices have no memory protection to slow attackers down.

Status: No universal patch yet — fixes depend on individual device manufacturers updating their firmware. Check for firmware updates on any devices you own that have USB or SD card slots.

Unassigned CVE Microsoft SharePoint — Remote Code Execution HIGH

CISA confirmed that attackers are now actively exploiting a remote code execution flaw in Microsoft SharePoint, the popular document-sharing platform used by many businesses. Microsoft patched the vulnerability in May, but organizations that haven't applied the update are now being targeted. Once exploited, an attacker can run whatever code they like on the SharePoint server.

Status: Patch available since May — if your organization runs SharePoint on-premises, confirm with IT that the May 2026 security update has been applied.

🛠  New Tech
Opera's "Paste Protect" Takes Aim at ClickFix Scams

Opera has rolled out a new browser feature called Paste Protect, built specifically to stop ClickFix attacks. These attacks trick users into copying a malicious command and pasting it into Windows' Run dialog or terminal, which silently installs malware. Paste Protect watches what lands on your clipboard and warns you before you paste something that looks dangerous. ClickFix attacks have surged in popularity with cybercriminals because they bypass almost all traditional security tools — the victim does the dirty work themselves, so nothing looks suspicious to the computer. It's a simple, smart addition that addresses a very real and growing threat.

Microsoft Rolls Out Smarter Bot Protection for Teams Meetings

Microsoft has added improved bot detection to Microsoft Teams meetings, making it harder for automated accounts to join calls uninvited. This matters because Teams meeting links are routinely shared broadly, and attackers have used fake bot participants to eavesdrop, drop malicious links in chats, or disrupt calls. The update uses smarter behavioral checks to tell real humans from automated intruders at the point of joining. For organizations running sensitive meetings over Teams, this is a welcome layer of protection that requires no action from users.

💡  Deep Dive
Your Smart TV Was a Cybercrime Tool — And You Had No Idea: The NetNut Takedown Explained

Imagine lending your home internet connection to criminals every hour of the day without knowing it. That's what happened to at least two million people whose smart TVs and streaming boxes were quietly hijacked by a network called NetNut — until the FBI pulled the plug this week.

Here's how it worked. NetNut, run by a publicly traded Israeli company called Alarum Technologies, built a business around selling "residential proxy" services. Companies and individuals pay for these services to make their internet traffic appear to come from a real home — not a data center. That has some legitimate uses, but it's also a goldmine for criminals who want to hide their tracks. The problem: NetNut populated its network by secretly installing software on people's devices through apps they willingly downloaded. Your streaming box runs an app, that app bundles NetNut's code, and suddenly your home IP address is for rent. You never agreed to that. In a single week in June, Google spotted 316 distinct criminal groups using NetNut exit nodes to do things like spray stolen passwords at accounts, scrape websites, and commit advertising fraud. Some were espionage groups.

This matters for regular people in two ways. First, if criminal traffic routes through your home internet address, that address could end up on blocklists, get flagged by banks or streaming services, or — in a worst case — attract law enforcement attention that rightfully belongs elsewhere. Second, the researchers noted that once your device becomes an exit node, attackers routing traffic through it can potentially reach other devices on your home network, like your laptop or phone. Your smart TV becomes a door into your house.

The FBI seizure is significant, but it won't be the last story like this. Dozens of other residential proxy services operate on similar models. The practical takeaway: be selective about what apps you install on smart TVs and streaming boxes, keep their firmware updated, and if a streaming app asks for unusual permissions, that's a red flag. The convenience of a free app sometimes comes with a hidden cost you never agreed to pay.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →