← All issues
cybersecurityCyberBubblephishing

Your Streaming Box Is Spying On You — Plus an 18-Year Linux Bug Goes Public

🌐  World Intel
Switzerland: Government SharePoint Breach Hits 200 Accounts

Hackers broke into Switzerland's federal IT systems by exploiting vulnerabilities in its Microsoft SharePoint servers. Around 200 government accounts were compromised. The Swiss federal IT office confirmed the breach, though it hasn't named who was behind the attack.

↗ BleepingComputer
Russia: State-Backed Hackers Target Zimbra Email Users

CISA confirmed that Russian state-supported hackers are running a phishing campaign aimed at users of Zimbra Collaboration Suite, a popular email and calendar platform. The advisory, published July 23, urges Zimbra administrators to apply updates and watch for signs of unauthorised access. Government and enterprise users of Zimbra should treat this as urgent.

↗ CISA Advisory AA26-204A
Canada: Snowflake Hacker Pleads Guilty to Stealing Data from 165 Companies

Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, pleaded guilty to hacking at least 165 organisations that stored data with cloud provider Snowflake. His crew stole billions of records — including AT&T call logs for over 100 million customers — then demanded ransoms. Victims included TicketMaster, Neiman Marcus, and Lending Tree. Moucka and co-conspirators pocketed over $2.5 million in ransom payments.

↗ Krebs on Security
⚔️  Active Attacks
Microsoft 365 Payroll Phishing: Attackers Quietly Drain Finance Inboxes

A widespread campaign is using adversary-in-the-middle phishing to steal Microsoft 365 logins across healthcare, education, manufacturing, and government organisations in the US, Canada, and Europe. Once inside an account, the attackers don't make noise — they sit quietly for around eight hours at a stretch, reading emails from payroll and finance staff. The goal is to redirect salary payments or gather financial data for fraud. Researchers at Arctic Wolf Labs linked the activity to a group Microsoft calls Storm-2755, also known as Payroll Pirates. The attackers hide behind residential proxies so their sign-ins look like everyday consumer traffic.

🛡 What to do: Turn on multi-factor authentication (MFA) on every Microsoft 365 account, especially for anyone in payroll or finance. MFA would have blocked most of these takeovers.
Hedge Funds Hit: UNC6671 Extortion Group Targets Financial Firms

A wave of attacks on hedge funds, private-equity firms, and other financial organisations has been tied to a group called UNC6671, which is linked to the BlackFile ransomware operation. The attackers are breaking in, stealing sensitive data, and threatening to publish it unless they're paid. Financial firms hold highly sensitive client and transaction data, making them prime targets for this kind of extortion.

🛡 What to do: If your organisation works in finance, make sure remote access tools and VPNs are fully patched and that you have an incident response plan ready before you need it.
🔓  New Vulnerabilities
CVE-2026-64564 Linux Kernel (SCTPhantom) CRITICAL

An 18-year-old bug — hiding in Linux since 2008 — can let a local user gain full root access and break out of a container to reach the underlying host machine. Researchers at Tencent's Zhuque Lab named it SCTPhantom and confirmed it works on Debian 13, Ubuntu 24.04, Rocky Linux 9, and RHEL 9. It requires a local account and access to the SCTP networking protocol, which limits who can exploit it — but in environments like shared servers or cloud hosts, that's still a serious risk.

Status: Patch available. Fixed in kernel versions 7.1.6, 6.18.42, 6.12.101, and 6.6.148 — released August 3. Update your Linux kernel now.

CVE-2026-56181 Windows NAT / Hyper-V (NatJack) HIGH 8.3

Researcher Malcolm Stagg presented NatJack at Black Hat USA 2026 — a new class of attack that manipulates NAT tables to hijack active connections, fake DNS responses, and exhaust network resources. The Windows-specific flaw (CVE-2026-56181, score 8.3) affects Hyper-V's NAT implementation. An attacker needs to be on the same network segment as the victim, which limits exposure but makes it a real risk in shared hosting or office environments. A matching Linux flaw (CVE-2026-63913, score 8.2) also exists in the Netfilter conntrack component.

Status: Apply the latest Windows and Linux updates. Separate untrusted workloads from trusted systems that share the same NAT infrastructure, and encrypt traffic wherever possible.

No CVE yet Windows Hello for Business / Microsoft Entra ID HIGH

Researcher Dirk-jan Mollema found that malware already running on your Windows PC can silently use your Windows Hello for Business key to authenticate to Microsoft's cloud identity system, Entra ID — without ever touching your PIN or triggering a fingerprint scan. From there, the attacker can register their own device and lock in long-term cloud access. No admin privileges needed, and on TPM-backed systems the private key is never extracted. This is a design behaviour, not a classic bug — Microsoft has left it as-is for now.

Status: No patch. No active exploitation reported. Reduce risk by limiting what software can run in signed-in user sessions and reviewing Entra ID device registration policies.

🛠  New Tech
HTTP Terminator: AI That Hunts Web Vulnerabilities at Scale

PortSwigger — the company behind the popular Burp Suite web security tool — built an AI research agent called HTTP Terminator. Lead researcher James Kettle used it to test 30,000 websites (all with permission via bug bounty programmes) and found roughly 700 vulnerable to HTTP desynchronisation attacks — a subtle flaw that can trick web infrastructure into serving one user's private data to someone else. The system discovered entirely new attack techniques on its own, including a "dangling-byte" method that makes a class of attack called response queue poisoning more reliable. A separate human-guided investigation using the same research also turned up a zero-day vulnerability in Apache Traffic Server. It's a glimpse of how AI is starting to accelerate the discovery of web flaws — for defenders and, eventually, attackers too.

💡  Deep Dive
Your Cheap Streaming Box Might Be Committing Ad Fraud While You Watch TV

Millions of people buy generic Android TV streaming boxes online — they're cheap, promise "unlimited" content, and seem like a bargain. But security researchers at Bitsight have uncovered something disturbing: a popular brand called H96 is secretly running an ad fraud network in the background, and your home internet connection is the engine powering it.

Researcher Pedro Falé got his first clue by registering an expired domain name that H96 devices had been phoning home to. Once he took control of it, data from tens of thousands of these streaming sticks started flooding in. Here's the twist: almost every device claimed to be a Samsung, Vivo, Huawei, or Xiaomi smartphone — not an Android TV box. The devices were disguising themselves as phones so they could visit a network of AI-generated fake websites and click on ads, making those clicks look like real mobile users browsing the web. The whole operation traces back to a Chinese company called Zhejiang Fengwo IoT Technology, which even holds patents describing exactly how this system works.

For regular people, this matters for a few reasons. First, your home internet bandwidth is being silently consumed without your knowledge or consent. Second, these boxes are essentially botnet nodes sitting in your living room. Third, because they run a heavily modified version of Android, they're almost impossible to fully audit or secure. The advertisers being defrauded lose money too — costs that eventually filter back to consumers through higher prices.

The simplest takeaway: avoid no-name streaming boxes sold for suspiciously low prices, especially on Amazon or AliExpress. Stick to name-brand devices like a Roku, Apple TV, or an official Google Chromecast. If you already own an H96 or similar device, treat it as untrusted — keep it on a separate Wi-Fi network away from your phones, laptops, and smart home devices.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →