Your Streaming Box Might Be Spying for Hackers — Plus 110M Stolen Passwords
Wednesday, June 24, 2026 · 5-minute read
The U.S. Department of Justice seized a cloud computing account belonging to subsidiaries of HuiOne Group, a Cambodian corporate conglomerate. These subsidiaries allegedly helped criminals move billions of dollars in cryptocurrency fraud proceeds through a Telegram-based underground marketplace called HuiOne Guarantee. At the same time, the Treasury Department hit nine individuals and 26 linked companies with fresh sanctions.
↗ The Hacker NewsOwen Flowers, 18, and Thalha Jubair, 20, admitted in a UK court to hacking Transport for London in August 2024 — the agency that runs London's buses, trains, and underground network. The pair are key members of Scattered Spider, a group linked to over 120 corporate break-ins and at least $115 million in ransom payments across the U.S. and U.K. Jubair also faces separate U.S. federal charges for running a SIM-swapping service and a mass phishing campaign that hit over 130 companies.
↗ Krebs on SecurityTata Electronics — part of India's giant Tata conglomerate — confirmed it was hit by a cyberattack that disrupted parts of its IT systems. Hackers have already started leaking data online, though Tata has not yet said how many people are affected. Tata Electronics manufactures components for major global brands, making a breach here potentially significant beyond India's borders.
↗ BleepingComputerA Russian-speaking criminal group has been running a campaign called FortiBleed since February 2026, targeting firewalls made by Fortinet. The attackers broke into over 430,000 FortiGate devices globally and installed a custom-built eavesdropping tool called FortigateSniffer. This tool silently reads network traffic passing through the firewall and captures usernames and passwords — even ones that are partially scrambled. So far, they have collected over 110 million credentials, which they then crack and reuse to break into corporate networks.
A new attack targeting Mac users is spreading through malicious websites that show a fake error message. The page tells you to open Terminal — Mac's command-line tool — and paste in a command to "fix" the problem. What that command actually does is silently download and install infostealer malware from a disguised disk image file. The technique is called ClickFix and has been spreading on Windows for months — now it has arrived on macOS.
Cisco's Unified Communications Manager — software that runs phone and video systems for thousands of businesses — has a flaw that lets anyone on the internet send it a specially crafted web request. That request can trick the server into writing files to its own operating system, which attackers then use to gain full administrator control. No login is required. Attackers have already started actively exploiting this vulnerability in the wild.
Status: Patch available from Cisco — apply it now. Cisco released the fix earlier this month.
Researchers at Novee Security found a class of weakness in the automated build pipelines used by GitHub repositories at companies including Microsoft, Google, Apache, and Cloudflare. The flaw lets anyone with a free GitHub account fake an approval, push malicious code, or steal secret keys — no special access needed. Over 300 high-profile repositories were confirmed fully exploitable out of 30,000 scanned. This is a supply chain attack risk, meaning bad code could end up in software that millions of people download and use.
Status: No single patch — each affected organization must audit and fix its own CI/CD pipeline configurations. Novee Security has notified affected organizations.
FFmpeg is an open-source tool used by an enormous number of apps and websites to process video — think YouTube-style video conversion, video editing software, and streaming services. A newly disclosed flaw nicknamed PixelSmash lives in its widely used video decoder. An attacker could craft a malicious video file that, when processed by FFmpeg, triggers the bug and potentially allows remote code execution. Because FFmpeg is embedded in so many products, the blast radius could be very wide.
Status: FFmpeg has released a fix. If you use software that processes video, check with your vendor for an updated version.
Microsoft has started rolling out a new feature called Point-in-Time Restore in the latest Windows 11 preview update (KB5095093). It works a lot like Apple's Time Machine: Windows quietly saves snapshots of your system so you can roll back to an earlier state if something goes wrong — including after a ransomware attack or a bad software install. The feature is included in the same update that fixes several existing bugs. It won't be on by default for everyone right away, but it represents a meaningful new safety net for everyday Windows users who might not have set up backups on their own.
If you bought an inexpensive Android TV box online — one of those small gadgets that promises to unlock hundreds of streaming channels for a one-time fee — there's a real chance it is quietly renting out your home internet connection to criminals right now, without you knowing.
Researchers this week confirmed that a massive network of compromised TV boxes called the botnet Popa is linked to a company called NetNut, operated by the publicly traded Israeli firm Alarum Technologies. These boxes come pre-loaded with hidden software that registers your home internet address as a residential proxy. That means anyone who pays for NetNut's service — including scammers, fraudsters, and data scrapers — can route their traffic through your connection. To the outside world, it looks like the traffic is coming from your house. The Popa botnet spans over 1.4 million IP addresses, and researchers discovered it while investigating a wave of aggressive data scraping attacks in May 2026.
For regular people, this matters in a few ways. Your internet could slow down because someone else is using your bandwidth. More worryingly, illegal activity routed through your connection could — at least theoretically — be traced back to you. Some of these proxy networks also give customers the ability to probe other devices on your home network, putting your phones, laptops, and smart home gadgets at risk.
The boxes involved are sold under countless brand names on Amazon, eBay, and similar sites — they are extremely hard to identify by name alone. The FBI has warned about these devices before. The safest move: stick to name-brand streaming devices from Apple, Google, Amazon, or Roku. If you already own a cheap Android box, unplug it and look up its model number against known Vo1d or Popa botnet reports before plugging it back in.