Your Streaming Box Is Moonlighting as a Fraud Machine
Monday, August 10, 2026 · 5-minute read
A hacking group called Head Mare has been breaking into unpatched TrueConf video-conferencing servers used by Russian companies — then quietly swapping out the real client installer for a poisoned one. Anyone who downloaded the software from an infected server got a backdoor called PhantomCore installed alongside it. The affected industries include energy, electronics, and transport.
↗ The Hacker NewsHackers broke into Switzerland's federal IT office by exploiting vulnerabilities in its SharePoint servers. About 200 employee accounts were compromised. It's a reminder that even well-resourced government IT departments can get caught out by unpatched software.
↗ BleepingComputerA cyberattack disrupted IT systems at three North Carolina ports — Wilmington, Morehead City, and Charlotte Inland Port. The attack slowed physical port operations, showing once again that digital attacks can have very real-world consequences on supply chains and trade.
↗ BleepingComputerTwo malicious extensions called "Solidity Pro" were published to a popular code-editor marketplace targeting software developers who work with cryptocurrency. Early versions quietly phoned home to retrieve hidden malicious code. Newer versions went further — stealing browser passwords, crypto wallet data, API keys, SSH keys, and even Telegram tokens. All stolen data was sent to attackers via a Telegram bot. The extensions have been removed from the marketplace but the GitHub code repository remains online.
A wave of cyberattacks is hitting hedge funds, private equity firms, and other financial organisations. The group behind it, called UNC6671, is linked to extortion gang BlackFile. These attackers break in, steal sensitive financial data, and then demand payment to keep it quiet — a particularly dangerous tactic for firms managing client money and confidential investment strategies.
Two flaws in TrueConf's video-conferencing server let attackers connect over a standard network port and run their own code on the server with full admin-level privileges. This is how the Head Mare group replaced legitimate software installers with malware-carrying fakes. Affected versions include TrueConf server 5.3.x through 5.5.5 and all earlier releases.
Status: Update to a patched version immediately. If you run TrueConf Server in your organisation, check your version number now — if it falls in the affected range, treat it as compromised until patched and audited.
CISA confirmed that hackers are actively exploiting a critical command injection vulnerability in Progress Kemp LoadMaster, a piece of software many organisations use to manage and balance web traffic. An attacker who exploits this can run arbitrary commands on the affected system — essentially taking it over.
Status: CISA has added this to its Known Exploited Vulnerabilities catalog. Apply the vendor patch immediately. If you're a federal agency, you're required to fix this under the CISA directive.
A zero-day SQL injection flaw in Metabase — a popular tool companies use to visualise and query their data — was actively exploited to steal customer data from real organisations, including Framework and Tally. Attackers used the flaw to pull data directly from connected databases.
Status: Patch available. If your organisation uses Metabase, update now and audit your database access logs for unusual queries.
OpenAI's upcoming AI model, codenamed Astra, scored high enough on cybersecurity capability tests that the company decided to pause some internal work on it until stronger safety guardrails are in place. This is a notable moment: a major AI lab voluntarily slowing down because its own model showed it could cause real harm. OpenAI is now building isolated test environments, restricting what the model can access on networks, encrypting model weights more aggressively, and adding universal monitoring for risky behaviour. It's an early example of AI safety controls being applied proactively — before a problem occurs in the real world — rather than after. Whether this sets a precedent other AI companies follow is worth watching closely.
Millions of people bought inexpensive Android TV streaming sticks — often sold for $30–$50 with promises of unlimited content — without realising the devices were secretly working for someone else. New research from security firm Bitsight has revealed just how deep that rabbit hole goes, and the findings are genuinely surprising.
Researcher Pedro Falé registered an expired domain name that had previously been used to coordinate one of these schemes. Once he had control of it, data from tens of thousands of H96 streaming devices started flowing in. Here's the strange part: almost every device was lying about what it was. Instead of identifying itself as a TV box, each device was telling websites it was a Samsung, Huawei, or Xiaomi smartphone. Why? Because the hidden apps on these boxes were clicking on ads — and the ad networks only paid out for mobile phone traffic. The boxes were impersonating phones to collect the money.
Bitsight traced the operation back to a Chinese company called Zhejiang Fengwo IoT Technology, which runs a network of AI-generated websites stuffed with fake articles about finance, health, food, and gaming. None of those sites show ads to normal visitors — only to devices running the Fengwo apps in disguise. The company had even filed patents describing exactly how this system works, hiding the scheme in plain sight in legal documents. The money flows through a web of shell companies in Hong Kong and Singapore before disappearing.
For everyday people, this matters for two reasons. First, your home internet connection and electricity are being used to commit fraud without your knowledge. Second, these same devices have full network access inside your home — meaning they could, in theory, be directed to do far worse things than click fake ads. If you own a budget Android TV box from an unfamiliar brand, treat it as untrusted hardware. Put it on a separate Wi-Fi network away from your phones and computers, or replace it with a device from a reputable manufacturer.