← All issues
cybersecurityCyberBubbleprivacy

Your Smart TV Was Renting Out Your Internet. The FBI Just Shut It Down.

🌐  World Intel
USA: FBI Seizes NetNut — a Proxy Network Running on 2 Million Hacked Home Devices

The FBI seized hundreds of domains tied to NetNut, a service run by Israeli company Alarum Technologies that was secretly turning smart TVs and streaming boxes into proxy nodes. Security firms had linked NetNut to the Popa botnet — at least two million compromised home devices whose internet connections were being rented out to cybercriminals for fraud, scraping, and account takeover attacks. Google reported that in a single week in June 2026, 316 separate groups of bad actors were spotted using NetNut exit nodes — including both criminal gangs and espionage groups.

↗ Krebs on Security
Global: Police Arrest 5,800 Suspects in Worldwide Fraud Crackdown

Law enforcement agencies across 97 countries arrested 5,811 suspects and seized $293 million in stolen assets as part of a coordinated anti-fraud operation. The sweep targeted online scams, money laundering, and fraud networks operating across borders. It's one of the largest single coordinated cybercrime enforcement actions on record.

↗ BleepingComputer
USA: Sketchy "Zero-Day Broker" Linked to Convicted Felons Jack Burkman and Jacob Wohl

A cybersecurity startup called IRIS C2 — which claims to pay up to $7 million for zero-day exploits — turns out to be run by Jack Burkman and Jacob Wohl, a pair of convicted felons best known for running disinformation campaigns and fake intelligence companies. The company, registered as Calvexa Group LLC in Virginia, has been actively recruiting vulnerability researchers on X/Twitter and LinkedIn. Security researchers are warning people in the industry to be cautious about engaging with the firm.

↗ Krebs on Security
⚔️  Active Attacks
Voice Phishing Scam Tricks Workers Into Handing Over Microsoft 365 Access

A criminal group tracked as O-UNC-066 is calling employees on the phone, pretending to be IT or security staff, and telling them they need to register a new passkey for their Microsoft 365 account. The call directs them to a fake website that looks exactly like Microsoft's real passkey setup page. Once the victim enrolls there, the attackers gain full access to the account and use it to steal data. Industries targeted so far include healthcare, food and beverage, technology, automotive, construction, and aviation.

🛡 What to do: If you get an unexpected call asking you to visit a website and register a passkey or security device, hang up and call your IT department back on a number you already know. Legitimate IT teams don't cold-call you about urgent security enrollments.
WP-SHELLSTORM: Hackers Quietly Broke Into Over a Million WordPress Sites for Resale

A hacking crew accidentally left their own server exposed to the internet for three weeks — and researchers used that window to map the entire operation. The group, now called WP-SHELLSTORM, was breaking into WordPress and Joomla sites at scale by targeting outdated plugins, planting hidden backdoors called webshells, and selling that access to other criminals. Their target list named 1.4 million websites; the Breeze caching plugin for WordPress and the JCE editor plugin for Joomla were the two most-exploited entry points.

🛡 What to do: If you run a WordPress or Joomla site, log in today and update every plugin — especially Breeze (WordPress) and JCE Editor (Joomla). Delete any plugins you're not actively using. Your hosting provider may also offer a malware scan tool worth running.
🔓  New Vulnerabilities
NO CVE YET XQUIC / Tengine (Alibaba) — XRING Flaw CRITICAL — No Patch

A researcher at FoxIO found a bug in XQUIC — Alibaba's open-source library for running HTTP/3 servers — that lets anyone crash a server with just 260 bytes of completely normal-looking traffic. No login needed, no suspicious packets — just a tiny burst of ordinary data hits a single bad line of code and the server process dies. Because XQUIC is open-source, any company that has built it into their own server software is also exposed. Alibaba's own Tengine web server — which powers Taobao and Alipay — is affected. Every version through v1.9.4 (the latest) is vulnerable.

Status: No patch available as of July 10, 2026. Operators can disable QPACK dynamic tables as a workaround, or turn off HTTP/3 entirely until a fix ships.

NO CVE LISTED Ubiquiti UniFi OS CRITICAL — Max Severity

Ubiquiti has warned customers of a maximum-severity vulnerability in UniFi OS, the software that runs its popular networking gear — routers, access points, and network controllers used in homes and small businesses. A critical flaw at max severity in this type of device means an attacker could potentially take full control of your network hardware remotely. Ubiquiti has urged customers to patch immediately.

Status: Patch available — update your UniFi OS devices now through the UniFi Network app or console dashboard.

NO CVE LISTED Adobe ColdFusion CRITICAL — Actively Exploited

CISA — the US government's cybersecurity agency — ordered all federal agencies to patch a critical flaw in Adobe ColdFusion, a web application server still used across many government and enterprise systems, by today (Friday, July 10). The flaw is serious enough that CISA added it to its Known Exploited Vulnerabilities catalog, meaning real attackers are already using it in the wild.

Status: Patch available from Adobe. If your organization runs ColdFusion, treat this as urgent.

🛠  New Tech
MVPNalyzer: The Tool That Tested 281 Free VPN Apps — and Found Most Fail at Their One Job

Researchers at the University of Michigan, University of New Mexico, and IIT Delhi built an automated testing system called MVPNalyzer and ran it against 281 of the most popular free VPN apps on the Google Play Store. The results were grim: 29 apps let traffic leak outside the encrypted tunnel — including DNS queries that reveal every site you visit. Another 61 apps sent some data in completely plain text, readable by anyone on the same Wi-Fi network. Five apps even sent their configuration files unencrypted, letting a nearby attacker redirect your connection to a server they control. The apps flagged with at least one problem have a combined 2.4 billion installs. The research was presented at the NDSS security conference in February 2026 and is a major wake-up call: free VPNs are often worse than using no VPN at all.

💡  Deep Dive
The Proxy Scam in Your Living Room: How NetNut Turned Smart TVs Into a Criminal Network

Imagine hiring a locksmith, only to find out they've been quietly making copies of your house key and renting them to strangers while you sleep. That's essentially what NetNut — a service run by publicly traded Israeli company Alarum Technologies — was doing to millions of households around the world. And this week, the FBI finally kicked the door in.

Here's how it worked. NetNut operated what's called a residential proxy network. Companies and individuals pay for access to these networks when they want their internet traffic to look like it's coming from ordinary homes rather than data centers — useful for ad verification, market research, and unfortunately, also for cybercrime. NetNut populated its network by distributing software through apps commonly installed on smart TVs and streaming devices. Once installed, the software quietly turned those devices into always-on relay points. Your TV or streaming box was routing strangers' internet traffic — potentially including fraud, account takeovers, and password spray attacks — without you ever knowing.

Google's threat intelligence team found that in a single week in June 2026, 316 separate groups of bad actors were spotted using NetNut exit nodes, including both organized crime groups and state-sponsored espionage operations. That's not a niche problem. When your home device becomes an exit node for this kind of traffic, there's an added risk: unauthorized traffic passing through your device could also expose other gadgets on your home network — your laptop, your phone, your security cameras — to internet-based attacks.

The FBI, working with Google, Lumen Technologies, and the Shadowserver Foundation, seized hundreds of NetNut's domains this week. Alarum Technologies saw its Nasdaq-listed stock take a hit. But the bigger takeaway isn't about one company — it's about the whole category. Residential proxy networks are a booming, semi-legal industry, and many operate in the same grey zone NetNut did. If you have apps on your smart TV or streaming stick you don't recognize or no longer use, now is a good time to do a clean sweep. And if you're shopping for a VPN or privacy tool, stick to well-reviewed paid services — the free ones, as today's MVPNalyzer story shows, are often the product.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →