Your Smart TV Was Secretly a Proxy-for-Hire — Plus a 9-Year-Old Linux Bug
Thursday, July 23, 2026 · 5-minute read
Security researchers at Group-IB stumbled onto an exposed cloud server in Singapore that belonged to a hacking group they call JadeProx — believed to be linked to China. The server's logs revealed active break-ins at a Vietnamese hospital's medical imaging system, Malaysia's Ministry of Foreign Affairs, and Hong Kong schools, plus a spear-phishing campaign aimed at Honduras's National Congress. The hackers got into the hospital through an exposed Java management interface and planted webshells to keep access open.
↗ The Hacker NewsSouth Korea disclosed that hackers quietly sat inside the National Diplomatic Academy's online learning system for ten full months before anyone noticed. Personal information belonging to current and former Ministry of Foreign Affairs employees — including diplomats stationed overseas — was stolen. Ten months of undetected access is a reminder that breaches often aren't discovered quickly, and the damage keeps growing the longer attackers stay hidden.
↗ BleepingComputerSwiss train maker Stadler Rail says the Everest ransomware gang broke into a file-sharing platform it shared with one of its suppliers and demanded about $12.3 million to stay quiet. Stadler rejected the demand. The attack highlights a growing trend: criminals don't always need to break into the main target directly — going through a supplier or partner can be just as effective.
↗ BleepingComputerThe Chaos ransomware gang has a new backdoor tool called msaRAT, and it's sneaky. Instead of communicating with its command-and-control server in an obvious way, it routes all its traffic through Chrome or Edge — the browsers already running on your computer. To security software watching your network, the malicious traffic looks like normal web browsing. Once installed, msaRAT gives attackers a persistent foothold on the machine to spy, steal data, or deploy ransomware.
Attackers are actively exploiting critical flaws in the wp2shell WordPress plugin to plant webshells on vulnerable websites. A webshell gives an attacker a permanent back door into a site — they can return any time, change content, steal visitor data, or use the site to attack others. If you run a WordPress site, any outdated or vulnerable plugin is a potential open door.
A nine-year-old bug hiding in the Linux kernel since 2017 was publicly disclosed yesterday. Any regular, non-admin user on an affected system can exploit a race condition in the XFS filesystem to overwrite protected files and give themselves full root — meaning total control — over the machine. The attack survives a reboot. Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are all affected in their default configurations.
Status: Patch available — the fix was merged on July 16. Linux vendors including Red Hat are shipping updated kernels now. Apply system updates as soon as possible.
Check Point, a major cybersecurity company, has patched a zero-day flaw in SmartConsole, the graphical admin panel used to manage Check Point security products. The flaw is already being exploited in real attacks. If your organization uses Check Point firewalls or security gateways managed through SmartConsole, this is urgent — attackers could potentially gain administrative access to your security infrastructure.
Status: Patch available — Check Point has issued a fix. Update SmartConsole immediately.
A zero-day flaw in Windows involving the legacy registry hive system has no official Microsoft patch yet, but free unofficial patches have been made available by third parties. An attacker who already has limited access to a Windows machine could use this flaw to raise their privileges — essentially promoting themselves from a regular user to an administrator. Microsoft has not yet issued an official fix.
Status: No official patch yet. Unofficial free patches are available. Watch for a Microsoft update and apply it as soon as it arrives.
Google announced a new way to get back into your account if you're ever locked out: a short selfie video. You set it up in advance by looking into your camera and making a few guided head movements, so Google can capture your face from multiple angles. If you're ever locked out later, you take a new selfie video and Google compares it to the one you recorded. It's designed as an extra recovery option on top of existing methods like backup email or phone number — not a replacement. The idea is to help people who lose access to both their recovery phone and email, though it does raise questions about how well the system handles photos or video spoofing attempts.
↗ The Hacker NewsOver 42% of apps available on LG smart TVs were quietly turning your television into a residential proxy node. That means strangers on the internet were routing their traffic through your TV — without your meaningful knowledge — while you watched Netflix. This week, LG said it's putting a stop to it.
Here's how it worked. App developers — everyone from game makers to screensaver creators — were paid by proxy SDK providers to bundle hidden software into their apps. When you downloaded a Pac-Man game or a file utility, you might have also downloaded code that quietly volunteered your TV's internet connection to paying customers worldwide. Security firm Spur found the same problem on Samsung's Tizen platform too, where more than a quarter of apps carried similar components. The TV sits on your home network 24 hours a day, often with no security software watching it, making it ideal for this kind of abuse.
Why does this matter to you? A residential proxy built from your device can be used to commit fraud, bypass geo-restrictions, conduct credential stuffing attacks against websites, or simply hide an attacker's real location. You likely agreed to something buried in an app's terms of service, but few people read those — and fewer still expected their television to become hired internet infrastructure. The fact that a simple Pac-Man clone could be doing this illustrates how the smart home ecosystem has grown faster than the security guardrails around it.
LG's response — threatening to suspend non-compliant apps — is a meaningful step, but watch to see whether Samsung takes similar action on its Tizen platform, and whether app store audits actually catch new SDK-bundled apps before they reach users. In the meantime, it's worth reviewing what apps are installed on your smart TV and deleting anything you don't actively use. The less software running on your TV, the smaller the chance something on it is working against you.