Your Streaming Box Might Be a Crime Tool — Plus Two Critical Patches You Need Now
Tuesday, June 30, 2026 · 5-minute read
Thalha Jubair, 20, and Owen Flowers, 18, admitted in a UK court to hacking Transport for London in August 2024 — on the very first day of what was expected to be a six-week trial. The pair are key members of Scattered Spider, a group whose victims paid at least $115 million in ransoms across 47 US organisations. Flowers is also linked to hacks on US healthcare providers, while Jubair ran a SIM-swapping service on Telegram that targeted major wireless carriers.
↗ Krebs on SecurityRussian-linked hackers have shifted tactics and are now going after the backup recovery keys that let you restore your Signal account on a new device. If they steal that key, they can read your past and future messages without ever touching your phone. The FBI flagged this shift after CISA noted that Russian intelligence services have been persistently targeting commercial messaging apps throughout June.
↗ BleepingComputerAmerican insurance giant Aflac has confirmed a breach after attackers hit its Japanese subsidiary and stole personal information and bank account details. This is the latest in a string of attacks hitting companies through their overseas subsidiaries — a reminder that your data is only as safe as the weakest link in a company's global operations. No ransom group has publicly claimed the attack yet.
↗ BleepingComputerCISA confirmed Monday that ransomware gangs are now actively exploiting a privilege escalation vulnerability in Microsoft Defender, nicknamed BlueHammer. The bug was already being used in targeted zero-day attacks, but it has now gone mainstream — meaning criminal groups with less sophistication are running it at scale. If you run Windows and haven't applied recent Microsoft updates, your machine could be compromised even if you have Defender running.
Security firm LayerX found a technique called BioShocking that tricks AI browser agents — including extensions for ChatGPT, Perplexity Comet, and Claude — into copying your login credentials and sending them to an attacker. The trick works through indirect prompt injection: a rogue webpage hides attacker commands inside ordinary-looking text, like fake game rules, and the AI can't tell the difference between those instructions and your own. Six different AI browsers were successfully fooled in testing.
SimpleHelp is a popular remote support tool that IT teams use to access and fix computers remotely. This flaw lets an attacker completely bypass login — no password needed — by sending a forged identity token. Once inside, they get full technician-level access. Hackers are already exploiting this in the wild to install a new credential stealer called Djinn Stealer, which works on Windows, Mac, and Linux.
Status: Patch available. If your IT team uses SimpleHelp, tell them to update it today — this is being actively exploited right now.
Progress Kemp LoadMaster is a piece of networking hardware that many enterprises use to manage web traffic. A bug in how it handles input means an attacker can send a specially crafted request to its API — without logging in — and run any command they want as the most powerful user on the device. Researchers published a full step-by-step exploit walkthrough on June 29, which significantly raises the risk of attacks starting soon.
Status: Patch available since June 4. No confirmed exploitation yet, but public exploit details are now out — update immediately if you run LoadMaster.
Oracle E-Business Suite is financial software used by large organisations to manage money, HR, and operations. Attackers have started actively exploiting a critical flaw in it, according to threat intelligence firm Defused. This flaw is related to a wave of attacks by the ShinyHunters extortion group, which also separately hit Nissan and the National Association of Insurance Commissioners this week using a related Oracle PeopleSoft zero-day.
Status: Actively exploited. Apply Oracle's patch immediately and review access logs for unusual activity.
WhatsApp has started rolling out usernames — a feature that lets you share a handle instead of your phone number when connecting with people not already in your contacts. Until now, giving someone your WhatsApp meant giving them your phone number, which is a real privacy risk. With a username, strangers can message you without ever seeing your number. It's a feature Signal and Telegram have offered for years, and it's a meaningful step forward for the world's most-used messaging app. To grab yours early, head into WhatsApp Settings and look for the username option.
↗ BleepingComputerMicrosoft has introduced a new admin policy for Teams that lets meeting organisers block third-party bots from joining calls without explicit approval. This matters because automated tools — some legitimate, some not — can silently join large organisation meetings, record transcripts, and exfiltrate information. The new control puts a human gatekeeper in the loop before any bot gets a seat at the table. IT admins at organisations using Teams should check if the policy is enabled in their tenant settings.
↗ BleepingComputerImagine buying a $30 streaming box online that promises free access to Netflix, Disney+, and every sports channel on Earth — forever, for a one-time fee. Sounds too good to be true. It is. Researchers this week confirmed that millions of these devices are silently enrolled in a massive botnet called Popa, which routes criminal internet traffic through your home connection without you ever knowing.
Popa is linked to a residential proxy provider called NetNut, operated by publicly traded Israeli firm Alarum Technologies. The way it works: when you plug in one of these cheap Android TV boxes and connect it to your Wi-Fi, malware pre-installed on the device registers your home internet address as a relay point. Anyone — including criminals — can then pay to route their traffic through your connection. To the outside world, it looks like the traffic is coming from your home. Security firm Qurium stumbled onto this while investigating a wave of expensive data-scraping attacks in May 2026, tracing the activity across more than 1.4 million IP addresses.
For regular people, the risks are serious and underappreciated. Your internet address could appear in logs for fraud, harassment, or data theft that you had no part in. More worryingly, some of these proxy networks allow paying customers to probe and attack other devices on your home network — your laptop, your phone, your smart home gadgets. The FBI has warned about this category of device repeatedly, but cheap streaming boxes keep selling in huge volumes on major e-commerce platforms.
The simple rule: if a streaming device promises free premium content forever, it is almost certainly making money off you some other way. Stick to name-brand devices from Apple, Google, Roku, or Amazon. If you already own one of these cheap boxes, unplug it. And if you notice unusually high internet usage or sluggish speeds you can't explain, it may be worth checking what's connected to your network.