← All issues
cybersecurityCyberBubbleransomware

Your Streaming Box Might Be a Crime Tool — Plus Two Critical Patches You Need Now

🌐  World Intel
UK: Two Scattered Spider Hackers Plead Guilty Over Transport for London Attack

Thalha Jubair, 20, and Owen Flowers, 18, admitted in a UK court to hacking Transport for London in August 2024 — on the very first day of what was expected to be a six-week trial. The pair are key members of Scattered Spider, a group whose victims paid at least $115 million in ransoms across 47 US organisations. Flowers is also linked to hacks on US healthcare providers, while Jubair ran a SIM-swapping service on Telegram that targeted major wireless carriers.

↗ Krebs on Security
Russia: FBI Warns Hackers Are Now Targeting Signal Backup Recovery Keys

Russian-linked hackers have shifted tactics and are now going after the backup recovery keys that let you restore your Signal account on a new device. If they steal that key, they can read your past and future messages without ever touching your phone. The FBI flagged this shift after CISA noted that Russian intelligence services have been persistently targeting commercial messaging apps throughout June.

↗ BleepingComputer
Japan: Aflac Discloses Data Breach After Japan Subsidiary Is Hacked

American insurance giant Aflac has confirmed a breach after attackers hit its Japanese subsidiary and stole personal information and bank account details. This is the latest in a string of attacks hitting companies through their overseas subsidiaries — a reminder that your data is only as safe as the weakest link in a company's global operations. No ransom group has publicly claimed the attack yet.

↗ BleepingComputer
⚔️  Active Attacks
BlueHammer: A Windows Flaw Ransomware Gangs Are Now Actively Exploiting

CISA confirmed Monday that ransomware gangs are now actively exploiting a privilege escalation vulnerability in Microsoft Defender, nicknamed BlueHammer. The bug was already being used in targeted zero-day attacks, but it has now gone mainstream — meaning criminal groups with less sophistication are running it at scale. If you run Windows and haven't applied recent Microsoft updates, your machine could be compromised even if you have Defender running.

🛡 What to do: Open Windows Update right now and install any pending updates. BlueHammer is patched in the latest release — the fix is already available, you just need to apply it.
BioShocking: AI Browsers Tricked Into Handing Over Your Passwords

Security firm LayerX found a technique called BioShocking that tricks AI browser agents — including extensions for ChatGPT, Perplexity Comet, and Claude — into copying your login credentials and sending them to an attacker. The trick works through indirect prompt injection: a rogue webpage hides attacker commands inside ordinary-looking text, like fake game rules, and the AI can't tell the difference between those instructions and your own. Six different AI browsers were successfully fooled in testing.

🛡 What to do: Be cautious about enabling "agent mode" in AI browser extensions, especially on websites you don't fully trust. Until vendors patch this class of issue, don't let AI agents operate on sites where you're logged into sensitive accounts.
🔓  New Vulnerabilities
CVE-2026-48558 SimpleHelp Remote Support Software CRITICAL 10.0

SimpleHelp is a popular remote support tool that IT teams use to access and fix computers remotely. This flaw lets an attacker completely bypass login — no password needed — by sending a forged identity token. Once inside, they get full technician-level access. Hackers are already exploiting this in the wild to install a new credential stealer called Djinn Stealer, which works on Windows, Mac, and Linux.

Status: Patch available. If your IT team uses SimpleHelp, tell them to update it today — this is being actively exploited right now.

CVE-2026-8037 Progress Kemp LoadMaster CRITICAL 9.8

Progress Kemp LoadMaster is a piece of networking hardware that many enterprises use to manage web traffic. A bug in how it handles input means an attacker can send a specially crafted request to its API — without logging in — and run any command they want as the most powerful user on the device. Researchers published a full step-by-step exploit walkthrough on June 29, which significantly raises the risk of attacks starting soon.

Status: Patch available since June 4. No confirmed exploitation yet, but public exploit details are now out — update immediately if you run LoadMaster.

CVE-2026-46817 Oracle E-Business Suite HIGH

Oracle E-Business Suite is financial software used by large organisations to manage money, HR, and operations. Attackers have started actively exploiting a critical flaw in it, according to threat intelligence firm Defused. This flaw is related to a wave of attacks by the ShinyHunters extortion group, which also separately hit Nissan and the National Association of Insurance Commissioners this week using a related Oracle PeopleSoft zero-day.

Status: Actively exploited. Apply Oracle's patch immediately and review access logs for unusual activity.

🛠  New Tech
WhatsApp Finally Lets You Hide Your Phone Number With Usernames

WhatsApp has started rolling out usernames — a feature that lets you share a handle instead of your phone number when connecting with people not already in your contacts. Until now, giving someone your WhatsApp meant giving them your phone number, which is a real privacy risk. With a username, strangers can message you without ever seeing your number. It's a feature Signal and Telegram have offered for years, and it's a meaningful step forward for the world's most-used messaging app. To grab yours early, head into WhatsApp Settings and look for the username option.

↗ BleepingComputer
Microsoft Adds Bot Approval Controls to Teams Meetings

Microsoft has introduced a new admin policy for Teams that lets meeting organisers block third-party bots from joining calls without explicit approval. This matters because automated tools — some legitimate, some not — can silently join large organisation meetings, record transcripts, and exfiltrate information. The new control puts a human gatekeeper in the loop before any bot gets a seat at the table. IT admins at organisations using Teams should check if the policy is enabled in their tenant settings.

↗ BleepingComputer
💡  Deep Dive
The Popa Botnet: Your Cheap Streaming Box Might Be Doing Someone Else's Dirty Work

Imagine buying a $30 streaming box online that promises free access to Netflix, Disney+, and every sports channel on Earth — forever, for a one-time fee. Sounds too good to be true. It is. Researchers this week confirmed that millions of these devices are silently enrolled in a massive botnet called Popa, which routes criminal internet traffic through your home connection without you ever knowing.

Popa is linked to a residential proxy provider called NetNut, operated by publicly traded Israeli firm Alarum Technologies. The way it works: when you plug in one of these cheap Android TV boxes and connect it to your Wi-Fi, malware pre-installed on the device registers your home internet address as a relay point. Anyone — including criminals — can then pay to route their traffic through your connection. To the outside world, it looks like the traffic is coming from your home. Security firm Qurium stumbled onto this while investigating a wave of expensive data-scraping attacks in May 2026, tracing the activity across more than 1.4 million IP addresses.

For regular people, the risks are serious and underappreciated. Your internet address could appear in logs for fraud, harassment, or data theft that you had no part in. More worryingly, some of these proxy networks allow paying customers to probe and attack other devices on your home network — your laptop, your phone, your smart home gadgets. The FBI has warned about this category of device repeatedly, but cheap streaming boxes keep selling in huge volumes on major e-commerce platforms.

The simple rule: if a streaming device promises free premium content forever, it is almost certainly making money off you some other way. Stick to name-brand devices from Apple, Google, Roku, or Amazon. If you already own one of these cheap boxes, unplug it. And if you notice unusually high internet usage or sluggish speeds you can't explain, it may be worth checking what's connected to your network.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →