← All issues
cybersecurityCyberBubbleransomware

Your Smart TV Was a Criminal's Disguise — Plus AI Ransomware Runs Solo

🌐  World Intel
India: China-Linked Hackers Target Tax Season With Fake Government Emails

A hacking group with suspected ties to China has been sending spear-phishing emails to Indian taxpayers, accountants, and corporate finance teams. The emails impersonate India's Income Tax Department and arrive timed to the annual tax filing season — not a coincidence. The goal is to install a remote access trojan called DcRAT to steal financial data. Researchers at Seqrite Labs named the campaign Operation DragonReturn and say the lures are unusually polished, with real legal citations and bilingual content, signalling a well-funded, deliberate operation.

↗ The Hacker News
UK: Two Scattered Spider Members Plead Guilty Over Transport for London Hack

Thalha Jubair, 20, and Owen Flowers, 18, admitted in a UK court to hacking Transport for London in August 2024, the attack that disrupted the city's public transit network. Flowers separately admitted to hacking two US healthcare providers. The pair were key members of Scattered Spider, a gang linked to at least 120 network intrusions across 47 US companies and $115 million in ransom payments. Their guilty pleas came on the very first day of what was expected to be a six-week trial.

↗ Krebs on Security
US/Global: FBI and Google Dismantle NetNut Proxy Botnet, 2 Million Devices Cut Off

The FBI, Google, and several security partners seized hundreds of domains belonging to NetNut, a residential proxy botnet run by Israeli company Alarum Technologies. NetNut had quietly infected roughly two million home devices — smart TVs, streaming boxes — turning them into traffic relays rented out to cybercriminals for fraud, scraping, and account takeover attacks. In a single week in June, Google spotted 316 separate criminal groups using NetNut exit nodes. The FBI replaced the NetNut homepage with a seizure banner; the company says it's cooperating.

↗ Krebs on Security
⚔️  Active Attacks
AI-Powered Ransomware: JadePuffer Ran an Entire Attack Without a Human

Researchers say JadePuffer is the first documented ransomware operation run entirely by an AI agent. A large language model handled every phase of the attack — finding a target, breaking in, moving through the network, encrypting files, and even drafting the ransom note — with no human operator needed. This matters because it removes the main bottleneck in ransomware attacks: the skilled criminal's time. Attacks like this could scale rapidly and run around the clock.

🛡 What to do: Make sure your most important files are backed up somewhere offline or in a separate account — a backup the attacker can't reach is your best protection if ransomware ever hits.
Microsoft SharePoint Flaw Now Actively Exploited in the Wild

CISA confirmed that a remote code execution vulnerability in Microsoft SharePoint is being actively used in real attacks right now. SharePoint is widely used by businesses to share documents and manage internal websites, making it a high-value target. If your organisation runs SharePoint on its own servers rather than via Microsoft's cloud, you need to act immediately.

🛡 What to do: If your company runs SharePoint on-premises, tell your IT team today — Microsoft has released a patch and it should be applied as soon as possible.
🔓  New Vulnerabilities
CVE-2026-48282 Adobe ColdFusion CRITICAL

Adobe ColdFusion — software many organisations use to run web applications — has a maximum-severity flaw that attackers are already exploiting. A successful attack lets someone run any code they want on the server, which could mean stealing data, installing malware, or taking the site fully offline. The Canadian Centre for Cyber Security confirmed live exploitation this week.

Status: Patch available from Adobe — apply immediately if your organisation runs ColdFusion.

CVE-TBA Microsoft SharePoint HIGH · Actively Exploited

This vulnerability in Microsoft SharePoint lets an attacker run malicious code on a server just by sending a specially crafted request. No login required in some configurations. CISA has added it to its Known Exploited Vulnerabilities catalog, meaning real attackers are using it today.

Status: Patch available — CISA urges immediate patching for all on-premises SharePoint deployments.

CVE-TBA Fortinet Network Devices HIGH · Credential Exposure

CISA issued an alert urging organisations to harden their Fortinet devices after reports of credential exposure. Fortinet gear is common in business and government networks. If attackers get valid login credentials, they can bypass security controls entirely, as if they work there.

Status: No single patch — CISA recommends reviewing device configurations and rotating credentials immediately.

🛠  New Tech
TrojPix: Researchers Demo Data Theft Via Invisible Pixel Flickers on Your Monitor

Researchers at Shandong University built a technique called TrojPix that can pull data off a computer that has no internet connection at all — what security people call an air-gapped system. It works by making tiny, invisible changes to on-screen pixels, which causes the video cable to emit faint radio signals. A receiver nearby can decode those signals and reconstruct the stolen data. TrojPix achieved speeds up to 8.1 Mbps — fast enough to steal a 100 MB file in under two minutes — and worked at distances up to 208 metres in controlled tests. The catch: malware must already be on the machine to trigger the pixel changes, so this is an escape route for data, not a way to break in. Real-world walls and interference would reduce the range significantly, but the research shows that "air-gapped" does not mean "untouchable."

QuimaRAT: A Rent-by-Month Hacking Tool That Runs on Windows, Mac, and Linux

Security researchers at LevelBlue flagged QuimaRAT, a new malware-as-a-service remote access trojan written in Java. Because it's Java-based, the same tool works on Windows, Mac, and Linux machines — a rare and dangerous combination. Subscriptions start at $150 per month and go up to $1,200 for lifetime access, making it accessible to low-skill criminals. It uses encrypted plugins that can be swapped in and out remotely, so its capabilities can be upgraded even after it's already on a victim's device.

💡  Deep Dive
Your Streaming Box Was a Criminal's Internet Disguise — The NetNut Takedown Explained

Imagine lending your home address to a stranger so they can send threatening letters — except you never agreed to it, and you had no idea it was happening. That is essentially what the NetNut residential proxy network was doing to roughly two million people's smart TVs, streaming boxes, and Android devices around the world.

NetNut was operated by Alarum Technologies, a publicly traded Israeli company. Its software — bundled inside seemingly harmless apps — quietly turned infected home devices into internet relay points. Cybercriminals paid to route their traffic through these devices, so that when they attacked a website or tried to break into accounts, the traffic appeared to come from ordinary household internet connections rather than suspicious servers. In a single week in June 2026, Google counted 316 distinct criminal groups using NetNut exit nodes, including both fraud rings and state-linked espionage groups.

On July 3, the FBI seized hundreds of NetNut domains and replaced its homepage with a federal seizure notice. Google disabled accounts and apps tied to the network and worked with partners including Lumen and Shadowserver to cut off the infrastructure. For the two million people whose devices were unknowingly enrolled, this also means their home networks were being used to attack others — and in some cases, criminals with access to an exit node could potentially reach other devices on the same home Wi-Fi network.

The bigger lesson here is about where trust breaks down. NetNut's software got onto devices through legitimate-looking apps — the kind you'd install without a second thought. Until regulators and app stores enforce stricter rules about what SDKs are allowed to do inside apps, takedowns like this will keep being reactive. Watch for whether Alarum Technologies faces financial penalties — that outcome will signal how seriously regulators intend to treat companies that profit from botnets, even when incorporated into a legal business model.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →