Your Streaming Box Might Be a Criminal's Tool — Plus 119 Fake Browser Extensions Busted
Monday, June 29, 2026 · 5-minute read
Thalha Jubair, 20, and Owen Flowers, 18, admitted in a UK court to hacking Transport for London — the agency that runs London's buses, tubes, and trains — in August 2024. The two are key members of Scattered Spider, a group linked to at least $115 million in ransom payments across 120 breaches of US companies. Flowers is also separately accused of hacking US healthcare providers SSM Health and Sutter Health.
↗ Krebs on SecurityRussian APT group Gamaredon ran 35 separate targeted email attack campaigns against Ukrainian government and military institutions throughout 2025, security firm ESET found. The group's goal is simple: steal sensitive information to support Russia's war effort. Their latest trick uses booby-trapped archive files and a technique called HTML smuggling to sneak malware past defenses.
↗ The Hacker NewsJapanese telecom giant KDDI disclosed that hackers broke into an email system it shares with five other internet service providers, exposing up to 14.2 million email logins. If you use a smaller Japanese ISP for email, assume your address and password may be out there. Change your email password now and never reuse it on other accounts.
↗ BleepingComputerThe FBI and CISA are warning that a phishing campaign linked to Russian intelligence has levelled up. Attackers aren't just trying to access your current Signal messages — they're now specifically hunting for your Signal Backup Recovery Key. Grabbing that key lets them restore your entire chat history on their own device, giving them access to everything you've ever sent or received on the app. The campaign targets people who might have sensitive conversations: journalists, activists, government workers, and anyone in contact with Ukraine-related networks.
Researchers at Infoblox found that scammers have built over 236,000 fraudulent websites using templates made from a legitimate app-building tool called DCloud Uni-App. The sites look like real cryptocurrency exchanges, investment platforms, or brand-name services. They're actually pig-butchering scams and wallet drainers dressed up professionally. The operation has been quietly scaling for two years, suggesting an organized criminal network behind it.
This flaw in the Linux kernel lets any local user on a vulnerable server quietly promote themselves to full administrator ("root") using a trick involving cloned network packets. It works on default installations of Debian, Ubuntu, and Fedora — three of the most common Linux flavors used by servers, cloud systems, and developer machines worldwide. Researchers from JFrog say it's especially dangerous on shared servers where multiple users log in, because any one of them could use it to take over the whole machine.
Status: Patch in progress — check your Linux distribution's security updates and apply as soon as one is available.
SimpleHelp is software that IT teams use to remotely access and fix computers. A critical flaw in it is now being actively exploited to install a brand-new piece of infostealer malware called Djinn Stealer. This malware runs on Windows, Mac, and Linux — so it's a triple threat. If your workplace uses SimpleHelp for IT support, your IT team needs to patch this immediately.
Status: Actively exploited in the wild — patch available, apply urgently.
Oracle E-Business Suite is financial software used by thousands of companies to manage accounting, payroll, and procurement. Attackers are now actively exploiting a vulnerability in it — meaning they've moved past the testing phase and are hitting real targets. A successful attack could let hackers access or manipulate sensitive financial records.
Status: Actively exploited — Oracle has issued patches; apply immediately if your organization runs this software.
Microsoft removed 119 extensions from its Edge browser store after discovering they used steganography — hiding malicious code inside normal-looking image and font files — to sneak past security checks. The extensions posed as ad blockers, VPNs, and video downloaders, doing their advertised job while quietly waiting. Days after install, a hidden payload woke up to steal login credentials and commit ad fraud. Microsoft is calling the operation "StegoAd" and says it's been running since at least 2021, with up to 2.6 million installs across the 119 extensions. This is a reminder that even official browser stores aren't perfectly safe — install only extensions you genuinely need, from developers you can verify.
You might have bought it for thirty or forty dollars — a small Android TV box promising free access to every streaming service on the planet. It streams fine. But quietly, it may also be renting out your home internet connection to criminals. Welcome to the Popa botnet, and the company researchers are now linking it to.
Security researchers at Qurium were investigating a wave of data scraping attacks — essentially bots hammering websites to steal their content — when they noticed the attacking traffic was spread across more than 1.4 million different internet addresses. That's a telltale sign of a botnet built from residential proxies. Those are real home connections — like yours — being used to disguise where the malicious traffic comes from. Qurium traced the network back to domains connected to a botnet called Popa, which researchers believe is a component of the larger Vo1d malware campaign. Multiple security firms have now linked Popa's infrastructure to NetNut, a residential proxy service operated by Israeli public company Alarum Technologies.
The devices at the heart of this are those unofficial Android TV boxes sold under dozens of brand names on Amazon, eBay, and other online marketplaces. They advertise things like "500+ free channels" or "lifetime IPTV." The FBI has warned about these devices repeatedly. Once you plug one in and connect it to your WiFi, software pre-installed on the device quietly enrolls your home internet address into a proxy network. Anyone — including criminals — can then pay to route their traffic through your connection. That means illegal activity could appear to originate from your home. Some of these proxy networks also leave your local network exposed, potentially letting paying customers reach other devices in your home like laptops, smart home gadgets, or security cameras.
The simplest way to protect yourself: don't buy unofficial Android streaming boxes from unknown brands, no matter how good the deal sounds. If you already own one and aren't sure of its origin, unplug it from your network. Stick with named devices like Roku, Apple TV, Google Chromecast, or Amazon Fire TV. And if you notice your internet slowing down at odd hours, or your router showing unexpected outbound traffic, it may be worth investigating what's quietly using your connection.