← All issues
cybersecurityCyberBubblesupply-chain

Your Streaming Box Might Be Spying for Hackers — Plus 110M Stolen Passwords

🌐  World Intel
Cambodia: U.S. Seizes Crypto Scam Infrastructure Tied to HuiOne Group

The U.S. Department of Justice seized a cloud computing account belonging to subsidiaries of HuiOne Group, a Cambodian corporate conglomerate. These subsidiaries allegedly helped criminals move billions of dollars in cryptocurrency fraud proceeds through a Telegram-based underground marketplace called HuiOne Guarantee. At the same time, the Treasury Department hit nine individuals and 26 linked companies with fresh sanctions.

↗ The Hacker News
UK: Two Scattered Spider Hackers Plead Guilty Over Transport for London Attack

Owen Flowers, 18, and Thalha Jubair, 20, admitted in a UK court to hacking Transport for London in August 2024 — the agency that runs London's buses, trains, and underground network. The pair are key members of Scattered Spider, a group linked to over 120 corporate break-ins and at least $115 million in ransom payments across the U.S. and U.K. Jubair also faces separate U.S. federal charges for running a SIM-swapping service and a mass phishing campaign that hit over 130 companies.

↗ Krebs on Security
India: Tata Electronics Confirms Cyberattack as Stolen Data Leaks Online

Tata Electronics — part of India's giant Tata conglomerate — confirmed it was hit by a cyberattack that disrupted parts of its IT systems. Hackers have already started leaking data online, though Tata has not yet said how many people are affected. Tata Electronics manufactures components for major global brands, making a breach here potentially significant beyond India's borders.

↗ BleepingComputer
⚔️  Active Attacks
FortiBleed: Russian Hackers Are Quietly Reading Your Network Traffic on 430,000 Firewalls

A Russian-speaking criminal group has been running a campaign called FortiBleed since February 2026, targeting firewalls made by Fortinet. The attackers broke into over 430,000 FortiGate devices globally and installed a custom-built eavesdropping tool called FortigateSniffer. This tool silently reads network traffic passing through the firewall and captures usernames and passwords — even ones that are partially scrambled. So far, they have collected over 110 million credentials, which they then crack and reuse to break into corporate networks.

🛡 What to do: If your organization uses FortiGate firewalls, apply all pending Fortinet security updates immediately and follow CISA's June 18 hardening guidance for Fortinet devices. Check for any unfamiliar logins or new accounts on your network.
macOS ClickFix: A Fake Error Message That Tricks You Into Infecting Your Own Mac

A new attack targeting Mac users is spreading through malicious websites that show a fake error message. The page tells you to open Terminal — Mac's command-line tool — and paste in a command to "fix" the problem. What that command actually does is silently download and install infostealer malware from a disguised disk image file. The technique is called ClickFix and has been spreading on Windows for months — now it has arrived on macOS.

🛡 What to do: Never paste commands into Terminal based on instructions from a website. If a webpage tells you to "fix an error" this way, close it immediately — that is the attack.
🔓  New Vulnerabilities
CVE-2026-20230 Cisco Unified Communications Manager HIGH 8.6

Cisco's Unified Communications Manager — software that runs phone and video systems for thousands of businesses — has a flaw that lets anyone on the internet send it a specially crafted web request. That request can trick the server into writing files to its own operating system, which attackers then use to gain full administrator control. No login is required. Attackers have already started actively exploiting this vulnerability in the wild.

Status: Patch available from Cisco — apply it now. Cisco released the fix earlier this month.

Cordyceps (no single CVE) GitHub CI/CD Workflows — Multiple Orgs CRITICAL

Researchers at Novee Security found a class of weakness in the automated build pipelines used by GitHub repositories at companies including Microsoft, Google, Apache, and Cloudflare. The flaw lets anyone with a free GitHub account fake an approval, push malicious code, or steal secret keys — no special access needed. Over 300 high-profile repositories were confirmed fully exploitable out of 30,000 scanned. This is a supply chain attack risk, meaning bad code could end up in software that millions of people download and use.

Status: No single patch — each affected organization must audit and fix its own CI/CD pipeline configurations. Novee Security has notified affected organizations.

PixelSmash (FFmpeg) FFmpeg Video Decoder HIGH

FFmpeg is an open-source tool used by an enormous number of apps and websites to process video — think YouTube-style video conversion, video editing software, and streaming services. A newly disclosed flaw nicknamed PixelSmash lives in its widely used video decoder. An attacker could craft a malicious video file that, when processed by FFmpeg, triggers the bug and potentially allows remote code execution. Because FFmpeg is embedded in so many products, the blast radius could be very wide.

Status: FFmpeg has released a fix. If you use software that processes video, check with your vendor for an updated version.

🛠  New Tech
Windows 11 Gets "Point-in-Time Restore" — Think Time Machine for Your PC

Microsoft has started rolling out a new feature called Point-in-Time Restore in the latest Windows 11 preview update (KB5095093). It works a lot like Apple's Time Machine: Windows quietly saves snapshots of your system so you can roll back to an earlier state if something goes wrong — including after a ransomware attack or a bad software install. The feature is included in the same update that fixes several existing bugs. It won't be on by default for everyone right away, but it represents a meaningful new safety net for everyday Windows users who might not have set up backups on their own.

💡  Deep Dive
Your Cheap Streaming Box Might Be Secretly Working for Hackers

If you bought an inexpensive Android TV box online — one of those small gadgets that promises to unlock hundreds of streaming channels for a one-time fee — there's a real chance it is quietly renting out your home internet connection to criminals right now, without you knowing.

Researchers this week confirmed that a massive network of compromised TV boxes called the botnet Popa is linked to a company called NetNut, operated by the publicly traded Israeli firm Alarum Technologies. These boxes come pre-loaded with hidden software that registers your home internet address as a residential proxy. That means anyone who pays for NetNut's service — including scammers, fraudsters, and data scrapers — can route their traffic through your connection. To the outside world, it looks like the traffic is coming from your house. The Popa botnet spans over 1.4 million IP addresses, and researchers discovered it while investigating a wave of aggressive data scraping attacks in May 2026.

For regular people, this matters in a few ways. Your internet could slow down because someone else is using your bandwidth. More worryingly, illegal activity routed through your connection could — at least theoretically — be traced back to you. Some of these proxy networks also give customers the ability to probe other devices on your home network, putting your phones, laptops, and smart home gadgets at risk.

The boxes involved are sold under countless brand names on Amazon, eBay, and similar sites — they are extremely hard to identify by name alone. The FBI has warned about these devices before. The safest move: stick to name-brand streaming devices from Apple, Google, Amazon, or Roku. If you already own a cheap Android box, unplug it and look up its model number against known Vo1d or Popa botnet reports before plugging it back in.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →