Your Streaming Box Is Running a Fraud Empire (Plus: North Korean Fake Hires)
Tuesday, August 11, 2026 · 5-minute read
Attackers broke into a Polish CHP plant in December 2025 and shut off a steam turbine along with the water treatment system — affecting heat supply to around 50,000 people. They got in through a private APN — essentially a private cellular data lane used by the grid operator — after first compromising a nearby wind farm on the same network. CERT Polska only disclosed the incident this week after a three-month investigation. Fortunately, no customers lost heat or electricity during the attack.
↗ BleepingComputerThe U.S. and South Korea jointly warned that a ransomware group called Gunra is actively targeting hospitals, financial services, and government agencies worldwide. Gunra breaks in by exploiting known security holes in Fortinet FortiOS and Schneider Electric industrial equipment, then steals and encrypts data — threatening to publish everything unless victims pay within five to seven days. CISA issued a full advisory on August 10th.
↗ The Hacker NewsConnor Riley Moucka, a 26-year-old from Ontario, pleaded guilty to hacking and extorting more than 165 organizations that used the cloud data platform Snowflake. He and his group stole over 100 million AT&T customer records plus data from TicketMaster, Neiman Marcus, and others — all because those accounts had no multi-factor authentication enabled. The group pocketed over $2.5 million in ransom payments before Moucka was arrested in October 2024.
↗ Krebs on SecurityGunra ransomware operators are scanning the internet for unpatched Fortinet and Schneider Electric devices right now. Once inside a network, they steal sensitive data first, then lock everything with encryption — a double extortion playbook. Targets include healthcare providers, government offices, and financial firms across the U.S. and internationally. Victims who refuse to pay face having their stolen data published publicly.
Security researchers set up a fake crypto startup, posted developer jobs, and hired three people they believe were North Korean IT operatives. Each applicant submitted mismatched ID documents — wrong state licenses, bank accounts from different states, and in one case an ID photo with a hidden SynthID watermark proving the image was AI-generated. A successful hire hands the operative real access to company systems and source code. A U.S. government joint alert from July 31st confirmed this threat is ongoing.
This flaw lets an attacker gain administrator-level access to Fortinet network security devices without needing a valid password. Gunra ransomware operators are actively using it right now to break into company networks. If your organization uses a Fortinet firewall or web proxy and hasn't patched recently, this is urgent.
Status: Patch available — update FortiOS and FortiProxy to the latest version immediately.
A security hole in Schneider Electric's PowerLogic P5 power monitoring units lets attackers gain unauthorized access from the internet. Gunra ransomware groups used this flaw as one of their entry points into critical infrastructure networks. These devices are common in hospitals, utilities, and industrial sites.
Status: Patch available from Schneider Electric — prioritize if your facility uses PowerLogic P5 hardware.
Researchers at DEF CON 34 showed they could take full control of a fully updated Windows 11 machine by tricking its Plug and Play system into fetching and running a malicious software installer — no physical USB device required. The same trick works over a remote desktop session under certain conditions. Microsoft says the riskiest configuration isn't enabled by default, but the technique still applies to many real-world setups.
Status: No patch yet. Microsoft is aware. Disable USB redirection in Remote Desktop settings if you don't need it.
OpenAI has released a specialized AI model called GPT 5.6 Cyber, designed specifically for cybersecurity tasks like finding software vulnerabilities, running penetration tests, responding to incidents, and suggesting fixes. It's currently limited to approved users only — meaning security teams and researchers who apply for access, not the general public. The move signals a broader push by AI companies to build tools tailored for the security profession rather than adapting general-purpose models. It also raises questions about what happens if similar capabilities end up in the wrong hands.
The ASSET Research Group demonstrated a new attack against AI coding assistants that use the Model Context Protocol (MCP). A malicious tool server can steal SSH keys, source code, and secrets without ever sending one obviously suspicious command — it just splits the harmful instruction into innocent-looking fragments across different channels, and the AI stitches them together on its own. The research, published today, shows that simply refusing blunt theft requests isn't enough protection. Developers using AI coding tools connected to external servers should treat those connections with the same suspicion they'd give a third-party app.
Those cheap Android TV boxes that promise unlimited streaming for a one-time fee? Researchers just confirmed what security experts have suspected for years: many of them are quietly running fraud operations in the background — and the scale of what they found is remarkable.
Security researcher Pedro Falé at Bitsight stumbled onto the operation by registering an expired domain name that had been used to coordinate activity across tens of thousands of H96 streaming devices. When data started flowing in, something immediately seemed wrong: nearly every TV box was reporting itself as a Samsung, Vivo, Huawei, or Xiaomi smartphone — not a TV device at all. Further digging revealed why. All the devices had two apps in common, both made by a Chinese company called Zhejiang Fengwo IoT Technology. Those apps quietly spoofed the devices as mobile phones, then used them to click on ads at a network of AI-generated content sites operated by the same company. Crucially, those sites only showed ads when the visiting device matched the spoofed mobile profile — making the fraud harder to detect.
This matters for regular people in two ways. First, if you own one of these devices, your home internet connection is being rented out to commit fraud without your knowledge or consent. That can slow your connection, expose your IP address to bad actors, and potentially implicate your household in illegal activity. Second, this kind of ad fraud costs businesses billions of dollars a year — costs that eventually get passed along to consumers through higher prices everywhere.
The safest move is to avoid cheap, unbranded streaming boxes entirely. Stick to devices from established manufacturers — Apple TV, Roku, Amazon Fire TV, Google Chromecast — where the supply chain is easier to trust. If you already own an H96 or similar device, consider replacing it. There's no user-level fix for firmware that's been compromised at the factory.