← All issues
cybersecurityCyberBubblead-fraud

Your TV Box Is Committing Ad Fraud — Plus $88M in Bitcoin Stolen

🌐  World Intel
UK: Police contact data dumped on the dark web

The Police National Legal Database (PNLD) confirmed that names, work email addresses, and organizations belonging to police officers, government staff, and criminal justice professionals were stolen and published on the dark web. The breach was spotted on July 26. No passwords appear to have been taken — but having real names tied to real police email addresses is exactly the kind of detail that makes phishing attacks far more convincing.

↗ The Hacker News
China: iOS exploit kit leaks into the wild — and someone's already using it

An unknown Chinese group has been running a campaign against Apple iPhone users using a publicly leaked version of a powerful hacking toolkit called DarkSword. Researchers at Censys found over 100 fake websites — most pretending to be Amazon Web Services login pages — hosting the kit. The infrastructure is primarily based in Hong Kong but reaches into Japan, the US, and Europe. DarkSword was previously linked to commercial spyware vendors and suspected state-backed hackers targeting Saudi Arabia, Turkey, Malaysia, and Ukraine.

↗ The Hacker News
USA: CISA warns hackers are going after water plant controllers

The US government's cybersecurity agency CISA is warning of a surge in attacks on programmable logic controllers (PLCs) at water and wastewater facilities. These are the devices that physically run pumps, valves, and treatment systems — if they're compromised, attackers could tamper with water supplies. CISA is urging water utilities to get these systems off the public internet immediately.

↗ CISA
⚔️  Active Attacks
IT management platform hijacked — attackers tunneled into thousands of customer systems

Attackers exploited a flaw in N-central, a platform that IT companies use to remotely manage their clients' computers. By bypassing authentication, they gained full admin access to N-central servers — and then used that foothold to reach every customer endpoint those servers managed. To stay in even after being partially evicted, attackers registered Cloudflare tunnels as persistent background services on compromised machines. N-able shipped a first fix that didn't fully close the hole; a complete patch (build 2026.3.1.7) only arrived August 2. The vulnerability is tracked as CVE-2026-18577.

🛡 What to do: If your IT provider uses N-able N-central, ask them to confirm they've upgraded to build 2026.3.1.7 or later — and that they've checked managed endpoints for unexpected services or tunnels.
DeepSeek AI used to run autonomous attacks on exposed servers

A Chinese-speaking hacker is using the open-source DeepSeek AI model combined with an open-source tool called Hermes Agent to automatically find and attack internet-exposed servers — with very little human involvement. The AI scans for weaknesses, picks an attack method, and executes it on its own. This is an early real-world example of AI being used as an autonomous hacking tool, not just an assistant.

🛡 What to do: Make sure any servers you run aren't exposed directly to the internet without a firewall or access controls — automated scanners find open services within minutes of exposure.
🔓  New Vulnerabilities
CVE-2026-18577 N-able N-central HIGH (actively exploited)

This flaw let attackers skip the login process entirely on N-central servers — a technique called authentication bypass. Once inside, they had full remote admin rights and could reach every computer the server managed. A first patch proved incomplete; attackers continued to operate. The full fix is build 2026.3.1.7, released August 2.

Status: Patch available — upgrade to build 2026.3.1.7 immediately.

CVE-2026-17583 Thermo Fisher Applied Biosystems (DNA Analysis Software) HIGH 8.2

This vulnerability affects software used in forensic DNA analysis labs. An attacker who gains access to the lab's systems could silently alter DNA data files before the analysis software reads them — and the changes would be nearly undetectable. In a criminal investigation context, that's a serious problem. Thermo Fisher has patched supported products by adding digital signatures to output files. Three older, end-of-life products will not receive patches.

Status: Patch available for supported products. End-of-life products have no fix — use additional lab controls.

No CVE assigned yet COLDCARD Hardware Bitcoin Wallet (Firmware RNG flaw) CRITICAL — $88M stolen

A flaw in older COLDCARD hardware wallet firmware produced weak random number generation when creating wallet seed phrases. Seed phrases are the master keys to a crypto wallet — if they're not truly random, an attacker can guess them. Researchers believe this flaw is directly linked to the theft of approximately $88.6 million in Bitcoin from thousands of affected wallets.

Status: Firmware update available. If your wallet seed was generated on older firmware, consider moving funds to a freshly generated wallet.

🛠  New Tech
Google Chrome to block extensions that hijack your New Tab page

Google is building a new Chrome security feature that would stop browser extensions from silently replacing your New Tab page or changing your default search engine without your permission. This specifically targets "policy-installed" extensions — ones pushed onto devices by employers or, in some cases, by malware pretending to be a legitimate IT policy. Hijacked New Tab pages are a classic way to redirect searches and serve ads or collect data. The feature isn't live yet, but Google is actively preparing it.

↗ BleepingComputer
Arch Linux temporarily locks down its community package system to stop a malware flood

The Arch Linux project has paused a feature that lets community members "adopt" and maintain packages in the Arch User Repository (AUR) after a wave of attackers took over legitimate, trusted packages and inserted malicious code. When you install a package from AUR, you trust whoever is maintaining it — and attackers have been snapping up unmaintained packages to slip in malware. The lockdown is temporary while the team works on stronger safeguards. If you use Arch Linux, be extra careful about AUR packages right now.

↗ BleepingComputer
💡  Deep Dive
Your cheap streaming box might be quietly committing ad fraud — and your TV might be next

You bought a $30 Android TV box online. It plays movies, streams everything, and never asks for a subscription. Sounds like a great deal. But new research from security firm Bitsight suggests those boxes may be quietly working a second job — faking ad clicks on fake websites — and you'd never know.

Researcher Pedro Falé stumbled onto the operation by registering an expired domain name that had been used to coordinate activity across tens of thousands of H96 streaming devices. When he looked at the traffic flowing to that domain, something immediately stood out: almost all of the TV boxes were identifying themselves as mobile phones — Samsung, Huawei, Xiaomi. They weren't, of course. But the spoofed identity was the point. The devices, all running apps from a Chinese company called Zhejiang Fengwo IoT Technology, were visiting a network of AI-generated websites stuffed with fake news articles about finance, health, food, and gaming. Those sites only showed ads when visited by something that looked like one of these specific spoofed phone profiles. Real human visitors saw nothing. The whole setup exists to generate fake ad revenue — a practice known as ad fraud. Bitsight traced the operation back to Fengwo Group, a mainland China company that also claims to operate over 120,000 AI-generated "digital humans" for customer service and companionship.

Meanwhile, smart TVs from major brands aren't completely off the hook either. A separate investigation found that more than 42% of apps available on LG's smart TV platform contained residential proxy SDKs — software that quietly routes strangers' internet traffic through your television. LG has now committed to suspending any app that doesn't remove this feature. Samsung's platform had similar issues in over a quarter of its apps.

The pattern here is worth paying attention to. Cheap, no-name streaming hardware and poorly vetted app stores are being turned into quiet infrastructure for fraud, surveillance, and traffic routing — all while sitting in your living room. The fix isn't complicated: stick to streaming devices from major, accountable brands (Roku, Apple TV, Amazon Fire TV), keep firmware updated, and think twice before sideloading apps from unknown sources.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →