← All issues
cybersecurityCyberBubbleransomware

Your Streaming Box Is Running a Fraud Empire (Plus: North Korean Fake Hires)

🌐  World Intel
Poland: Hackers Shut Down a Power Plant Turbine Via a Cellular Data Network

Attackers broke into a Polish CHP plant in December 2025 and shut off a steam turbine along with the water treatment system — affecting heat supply to around 50,000 people. They got in through a private APN — essentially a private cellular data lane used by the grid operator — after first compromising a nearby wind farm on the same network. CERT Polska only disclosed the incident this week after a three-month investigation. Fortunately, no customers lost heat or electricity during the attack.

↗ BleepingComputer
Global: Gunra Ransomware Hits Hospitals, Banks, and Government Agencies

The U.S. and South Korea jointly warned that a ransomware group called Gunra is actively targeting hospitals, financial services, and government agencies worldwide. Gunra breaks in by exploiting known security holes in Fortinet FortiOS and Schneider Electric industrial equipment, then steals and encrypts data — threatening to publish everything unless victims pay within five to seven days. CISA issued a full advisory on August 10th.

↗ The Hacker News
Canada: Snowflake Hacker Pleads Guilty — 165 Companies, 100M AT&T Records Stolen

Connor Riley Moucka, a 26-year-old from Ontario, pleaded guilty to hacking and extorting more than 165 organizations that used the cloud data platform Snowflake. He and his group stole over 100 million AT&T customer records plus data from TicketMaster, Neiman Marcus, and others — all because those accounts had no multi-factor authentication enabled. The group pocketed over $2.5 million in ransom payments before Moucka was arrested in October 2024.

↗ Krebs on Security
⚔️  Active Attacks
Gunra Ransomware: Critical Infrastructure Under Active Attack

Gunra ransomware operators are scanning the internet for unpatched Fortinet and Schneider Electric devices right now. Once inside a network, they steal sensitive data first, then lock everything with encryption — a double extortion playbook. Targets include healthcare providers, government offices, and financial firms across the U.S. and internationally. Victims who refuse to pay face having their stolen data published publicly.

🛡 What to do: If your organization uses Fortinet FortiOS, FortiProxy, or Schneider Electric PowerLogic P5 devices, apply the latest security patches immediately and check CISA's advisory AA26-222A for specific guidance.
North Korean Fake IT Workers Are Getting Hired at Real Companies

Security researchers set up a fake crypto startup, posted developer jobs, and hired three people they believe were North Korean IT operatives. Each applicant submitted mismatched ID documents — wrong state licenses, bank accounts from different states, and in one case an ID photo with a hidden SynthID watermark proving the image was AI-generated. A successful hire hands the operative real access to company systems and source code. A U.S. government joint alert from July 31st confirmed this threat is ongoing.

🛡 What to do: During hiring, flag mismatched ID documents — a California license with a New York bank account is a red flag. Video-verify candidates live, and check whether submitted photos contain AI-editing artifacts or stripped GPS data.
🔓  New Vulnerabilities
CVE-2025-24472 Fortinet FortiOS & FortiProxy CRITICAL

This flaw lets an attacker gain administrator-level access to Fortinet network security devices without needing a valid password. Gunra ransomware operators are actively using it right now to break into company networks. If your organization uses a Fortinet firewall or web proxy and hasn't patched recently, this is urgent.

Status: Patch available — update FortiOS and FortiProxy to the latest version immediately.

CVE-2024-5559 Schneider Electric PowerLogic P5 CRITICAL

A security hole in Schneider Electric's PowerLogic P5 power monitoring units lets attackers gain unauthorized access from the internet. Gunra ransomware groups used this flaw as one of their entry points into critical infrastructure networks. These devices are common in hospitals, utilities, and industrial sites.

Status: Patch available from Schneider Electric — prioritize if your facility uses PowerLogic P5 hardware.

No CVE yet Windows 11 Plug and Play (PnP) HIGH

Researchers at DEF CON 34 showed they could take full control of a fully updated Windows 11 machine by tricking its Plug and Play system into fetching and running a malicious software installer — no physical USB device required. The same trick works over a remote desktop session under certain conditions. Microsoft says the riskiest configuration isn't enabled by default, but the technique still applies to many real-world setups.

Status: No patch yet. Microsoft is aware. Disable USB redirection in Remote Desktop settings if you don't need it.

🛠  New Tech
OpenAI Releases GPT 5.6 Cyber — An AI Built for Security Work

OpenAI has released a specialized AI model called GPT 5.6 Cyber, designed specifically for cybersecurity tasks like finding software vulnerabilities, running penetration tests, responding to incidents, and suggesting fixes. It's currently limited to approved users only — meaning security teams and researchers who apply for access, not the general public. The move signals a broader push by AI companies to build tools tailored for the security profession rather than adapting general-purpose models. It also raises questions about what happens if similar capabilities end up in the wrong hands.

Researchers Expose AI Coding Assistants' Hidden Weak Spot: Split Instructions

The ASSET Research Group demonstrated a new attack against AI coding assistants that use the Model Context Protocol (MCP). A malicious tool server can steal SSH keys, source code, and secrets without ever sending one obviously suspicious command — it just splits the harmful instruction into innocent-looking fragments across different channels, and the AI stitches them together on its own. The research, published today, shows that simply refusing blunt theft requests isn't enough protection. Developers using AI coding tools connected to external servers should treat those connections with the same suspicion they'd give a third-party app.

💡  Deep Dive
Your Smart TV Streaming Box May Be Secretly Running an Ad Fraud Empire

Those cheap Android TV boxes that promise unlimited streaming for a one-time fee? Researchers just confirmed what security experts have suspected for years: many of them are quietly running fraud operations in the background — and the scale of what they found is remarkable.

Security researcher Pedro Falé at Bitsight stumbled onto the operation by registering an expired domain name that had been used to coordinate activity across tens of thousands of H96 streaming devices. When data started flowing in, something immediately seemed wrong: nearly every TV box was reporting itself as a Samsung, Vivo, Huawei, or Xiaomi smartphone — not a TV device at all. Further digging revealed why. All the devices had two apps in common, both made by a Chinese company called Zhejiang Fengwo IoT Technology. Those apps quietly spoofed the devices as mobile phones, then used them to click on ads at a network of AI-generated content sites operated by the same company. Crucially, those sites only showed ads when the visiting device matched the spoofed mobile profile — making the fraud harder to detect.

This matters for regular people in two ways. First, if you own one of these devices, your home internet connection is being rented out to commit fraud without your knowledge or consent. That can slow your connection, expose your IP address to bad actors, and potentially implicate your household in illegal activity. Second, this kind of ad fraud costs businesses billions of dollars a year — costs that eventually get passed along to consumers through higher prices everywhere.

The safest move is to avoid cheap, unbranded streaming boxes entirely. Stick to devices from established manufacturers — Apple TV, Roku, Amazon Fire TV, Google Chromecast — where the supply chain is easier to trust. If you already own an H96 or similar device, consider replacing it. There's no user-level fix for firmware that's been compromised at the factory.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →