← All issues
cybersecurityCyberBubbleransomware

Your Smart TV Was a Hacker's Proxy — And a Nasdaq Firm Ran the Botnet

🌐  World Intel
Global: 5,800 Fraud Suspects Arrested in 97-Country Sweep

Law enforcement agencies around the world arrested 5,811 suspects and seized $293 million in stolen money as part of a coordinated anti-fraud operation. The crackdown spanned 97 countries, making it one of the largest international fraud takedowns on record. If you've ever wondered whether global cybercrime enforcement has teeth — this week, it did.

↗ BleepingComputer
Japan: KDDI Data Breach Hits 12 Million Customers

Japanese telecom giant KDDI confirmed that attackers broke into an email platform shared by five internet service providers, exposing email addresses and passwords for over 12 million people. If you use a Japanese ISP or have a KDDI-connected email account, change your password now and check for any suspicious login activity. This is a reminder that even infrastructure-level email platforms — the pipes behind the scenes — are attractive targets.

↗ BleepingComputer
Canada: Mount Royal University Hit by Hackers Who Stole and Deleted Data

Mount Royal University in Calgary confirmed that hackers broke into its network, stole files from its storage systems, and then deleted them — a double blow that leaves victims without their own data. The attack follows a pattern increasingly used against schools and universities, which often have valuable personal records but lean security budgets. Students and staff at the university should watch for targeted phishing attempts using their stolen information.

↗ BleepingComputer
⚔️  Active Attacks
GodDamn Ransomware Kills Your Antivirus Before Striking

A new ransomware family called GodDamn has been spotted in the wild, and it comes with a nasty trick up its sleeve. Before encrypting your files, it uses a malicious software component called the PoisonX kernel driver to shut down your security software. With your antivirus blind, the ransomware then moves freely. Researchers at Symantec say the group behind it also used the remote desktop tool AnyDesk to get inside victim networks, then harvested browser-saved passwords before unleashing the ransomware. The attackers are believed to be the same crew behind older ransomware strains called Beast and Monster.

🛡 What to do: Don't rely on antivirus alone — make sure you have offline or cloud backups of critical files that can't be deleted or encrypted by ransomware, and audit which remote access tools like AnyDesk are active on your network.
China-Linked Hackers Spy on University Researchers via Roundcube Email Flaw

A hacking group tied to China has been exploiting a security flaw in Roundcube webmail servers to spy on academic researchers at U.S. and Canadian universities. Once inside, attackers steal login credentials and plant backdoor malware for long-term access. Researchers and academics who use university email systems — especially Roundcube — should be on alert, as this campaign is actively targeting higher education.

🛡 What to do: If your university IT team manages a Roundcube server, make sure it's patched immediately. As a user, report any unexpected login prompts or strange email behavior to your IT department right away.
🔓  New Vulnerabilities
CVE-2026-50656 Microsoft Defender (Malware Protection Engine) HIGH 7.8

This flaw, nicknamed RoguePlanet, lives inside the engine that powers Microsoft Defender — the built-in antivirus on Windows. A researcher found that a race condition bug lets an attacker trick Defender into giving them SYSTEM-level control — the highest level of access on a Windows computer. With that access, they can run any code they want. The flaw affects fully up-to-date Windows systems, which makes it especially serious.

Status: Patch now available — Microsoft has released a fix in Malware Protection Engine version 1.1.26060.3008. Windows Defender updates automatically, but check that your system is current.

CVE — Max Severity Ubiquiti UniFi OS CRITICAL 10.0

Ubiquiti — a popular brand for home and small-business networking gear — has patched seven serious flaws in its UniFi OS. The worst one scores a perfect 10 out of 10 for severity. It allows command injection, meaning an attacker could take complete control of your router or network equipment remotely. If you use Ubiquiti gear at home or in your office, this needs your attention today.

Status: Patches available — log into your UniFi controller and apply the latest firmware update immediately.

CVE — Max Severity Adobe ColdFusion CRITICAL

CISA — the U.S. government's cybersecurity agency — has ordered all federal agencies to patch a maximum-severity flaw in Adobe ColdFusion by this Friday. The flaw is already being actively exploited in the wild, meaning real attackers are using it right now. ColdFusion powers a lot of government and enterprise web applications, so the stakes here are high.

Status: Patch required — CISA deadline is Friday, July 11. If your organization runs ColdFusion, treat this as urgent.

🛠  New Tech
DuckDuckGo Browser Now Blocks YouTube Ads — Including Mid-Video Ones

The privacy-focused DuckDuckGo browser has added the ability to block most video ads on YouTube, including the ones that interrupt you mid-video. This works inside the DuckDuckGo browser itself — no extra extensions needed. For anyone exhausted by unskippable ads or skeptical of ad-based tracking, this is a meaningful upgrade. It's also a sign that privacy-first browsers are pushing harder into territory that mainstream browsers like Chrome have been slow to touch, largely because Google's business model depends on those very ads.

↗ BleepingComputer
Meta's Muse Image AI Uses Your Public Instagram Photos — By Default

Meta has launched a new AI image tool called Muse Image that lets anyone use public Instagram photos to generate new AI-created images. It's turned on by default for all public accounts. You can tag an Instagram username in Meta AI, and it will pull in that person's public posts to build a custom image. This raises real questions about consent — your public photos were shared to be seen, not necessarily to train or fuel someone else's AI creations. If you want to limit this, check your Instagram privacy settings and consider switching your account to private.

↗ The Hacker News
💡  Deep Dive
The FBI Just Seized a Botnet Hidden Inside Millions of Smart TVs — And a Nasdaq-Listed Company Was Running It

The FBI this week seized hundreds of domains tied to NetNut, a residential proxy service run by publicly traded Israeli company Alarum Technologies. The reason? Security researchers had linked NetNut to something called the Popa botnet: a collection of at least two million compromised devices, many of them smart TVs and streaming boxes sitting in people's living rooms.

Here's how the scheme worked. NetNut's software got installed on consumer devices — often without meaningful consent — and quietly turned them into "exit nodes." That means whenever a paying customer of NetNut's service wanted to hide their internet activity, their traffic was routed through your smart TV. To the rest of the internet, the traffic looked like it came from an innocent home in Des Moines or Manchester. In a single week in June 2026, Google's threat researchers spotted 316 different groups of hackers using NetNut's network to mask their attacks — including groups conducting password spray attacks and espionage operations.

The scariest part for regular people: when your device becomes an exit node, it doesn't just route outside traffic. It potentially exposes every other device on your home network — your laptop, your phone, your baby monitor — to whatever is flowing through it. The FBI worked with Google, Lumen, and Shadowserver to dismantle the infrastructure. Alarum Technologies, which trades on the Nasdaq stock exchange, saw its homepage replaced with an FBI seizure notice.

This story matters beyond NetNut. It's a sharp reminder that "free" or cheap apps on smart TVs and streaming devices often come with hidden costs. Your device's internet connection is valuable to bad actors, and some companies have built entire business models around harvesting it. Going forward, watch for what permissions smart TV apps request, keep your devices updated with the latest firmware, and if a streaming app seems oddly eager to run in the background — that's a red flag worth investigating.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →