Your Smart TV Was a Criminal Relay — Plus Pegasus Spied on a Spy Hunter
Friday, July 3, 2026 · 5-minute read
A former Member of the European Parliament, Stelios Kouloglou, was repeatedly hacked with Pegasus spyware while he was sitting on the very committee investigating Pegasus abuse. Researchers at Citizen Lab found the infections through forensic analysis of his device and confirmed that attackers could have read confidential committee documents. No government has been officially blamed, though investigators noted overlap with a separate campaign targeting Russian and Belarusian exiled journalists and activists.
↗ The Hacker NewsThalha Jubair, 20, and Owen Flowers, 18, pleaded guilty in a UK court this week to hacking Transport for London in August 2024 — on the very first day of what was expected to be a six-week trial. The pair are members of Scattered Spider, a group linked to attacks on MGM Resorts, Caesars Entertainment, Marks & Spencer, and dozens of US healthcare providers. US prosecutors allege the wider group extorted at least $115 million in ransom payments from 47 American organizations.
↗ Krebs on SecurityThe FBI, working with Google, Lumen, and Shadowserver, seized hundreds of domains tied to NetNut, a residential proxy network operated by Israeli company Alarum Technologies. NetNut quietly installed software on smart TVs and streaming boxes, turning them into relays that cybercriminals rented to hide their tracks. Google's researchers saw 316 separate criminal and espionage groups using NetNut exit nodes in a single week in June 2026.
↗ Krebs on SecurityThe Anubis ransomware-as-a-service group is actively exploiting a critical flaw in Citrix networking equipment — dubbed Citrix Bleed 2 (CVE-2025-5777) — to get their foot in the door at victim organizations. Once inside, they blend in by using legitimate IT tools like ScreenConnect and Zoho Assist that look like normal helpdesk activity. The group then moves through the network quietly before locking files and demanding payment.
A new piece of Mac malware called PamStealer is spreading through a convincing fake website — maccyapp[.]com — that pretends to be a popular clipboard manager called Maccy. If you download and run the fake app, it asks for your Mac login password using what looks like a normal system prompt, then verifies the password is real before stealing it along with saved browser data. A second hidden component written in Rust then digs in deeper, persisting on your machine and sending your data to attackers.
This flaw lets attackers break into Citrix networking equipment — the kind businesses use to let employees connect remotely — without needing a valid username or password. Once in, they can move freely through a company's internal network. The Anubis ransomware group is already actively exploiting it.
Status: Patch available from Citrix. Apply immediately if you haven't already.
CISA confirmed this week that ransomware gangs are actively exploiting a Windows flaw nicknamed BlueHammer. The bug lets attackers run their own code on a victim's machine — meaning they can install ransomware, steal files, or take full control — without the user doing anything wrong. It affects Windows systems that haven't been recently updated.
Status: Patch available via Windows Update. Install all pending Windows updates now.
CISA warned this week that attackers have started exploiting a remote code execution bug in Microsoft SharePoint — the document collaboration platform used by millions of businesses. An attacker who reaches your SharePoint server can run commands on it as if they were sitting at the keyboard. Microsoft patched this in May, but attackers are now actively targeting unpatched servers.
Status: Patch available since May 2026. Check with your IT team that your SharePoint installation is up to date.
Opera browser just rolled out a feature called Paste Protect, designed to stop a growing type of scam called a ClickFix attack. In a ClickFix attack, a malicious website shows a fake error and tells you to copy a command and paste it into your computer's terminal or run box — which then installs malware silently. Paste Protect watches your clipboard for suspicious commands and warns you before you can accidentally run them. It's a simple but meaningful defense against a trick that's caught out even technically savvy users. No action needed — the feature rolls out automatically to Opera users.
Microsoft has added enhanced bot detection to Teams meetings, making it harder for automated accounts to join calls uninvited and scrape conversation data. The update uses behavioral signals — patterns in how a participant joins and interacts — to flag non-human attendees in real time. For businesses using Teams for sensitive discussions, this is a quiet but useful upgrade that requires no configuration changes from users.
The FBI seized a service this week that had quietly turned at least two million home devices — including smart TVs and streaming boxes — into a criminal highway. If your device was part of it, strangers were routing their internet traffic through your home connection, and your address was taking the blame for whatever they did.
The service was called NetNut, run by an Israeli company called Alarum Technologies that traded on the Nasdaq stock exchange. On the surface, NetNut marketed itself as a legitimate "residential proxy" business — a way for companies to test websites from real home IP addresses. But security researchers at Google, Lumen, and Krebs on Security connected NetNut to a botnet called Popa. Popa grew by bundling hidden software into apps, which then silently recruited devices into the network. The owners of those devices had no idea any of this was happening.
Why does this matter beyond the obvious privacy invasion? When criminals route traffic through your home connection, your IP address appears in the logs of whatever they do — fraud, account takeover attempts, credential stuffing, ad fraud. You could find your internet service flagged, blocked, or even investigated, through no fault of your own. Google's researchers found 316 distinct criminal and espionage groups using NetNut exit nodes in a single week. Some of those were nation-state spies. Others were ransomware crews. All of them were hiding behind real families' home internet addresses.
The FBI and IRS Criminal Investigation seized the domains and Google killed associated accounts and apps that bundled the NetNut software. But this takedown is a reminder that smart home devices — TVs, routers, streaming sticks — are computers running software, and they can be compromised just like a laptop. Check your router's connected device list periodically, keep your TV's firmware updated, and if a streaming app asks for unusual permissions, think twice before hitting accept.