Your TV Box Is Committing Ad Fraud — Plus $88M in Bitcoin Stolen
Monday, August 3, 2026 · 5-minute read
The Police National Legal Database (PNLD) confirmed that names, work email addresses, and organizations belonging to police officers, government staff, and criminal justice professionals were stolen and published on the dark web. The breach was spotted on July 26. No passwords appear to have been taken — but having real names tied to real police email addresses is exactly the kind of detail that makes phishing attacks far more convincing.
↗ The Hacker NewsAn unknown Chinese group has been running a campaign against Apple iPhone users using a publicly leaked version of a powerful hacking toolkit called DarkSword. Researchers at Censys found over 100 fake websites — most pretending to be Amazon Web Services login pages — hosting the kit. The infrastructure is primarily based in Hong Kong but reaches into Japan, the US, and Europe. DarkSword was previously linked to commercial spyware vendors and suspected state-backed hackers targeting Saudi Arabia, Turkey, Malaysia, and Ukraine.
↗ The Hacker NewsThe US government's cybersecurity agency CISA is warning of a surge in attacks on programmable logic controllers (PLCs) at water and wastewater facilities. These are the devices that physically run pumps, valves, and treatment systems — if they're compromised, attackers could tamper with water supplies. CISA is urging water utilities to get these systems off the public internet immediately.
↗ CISAAttackers exploited a flaw in N-central, a platform that IT companies use to remotely manage their clients' computers. By bypassing authentication, they gained full admin access to N-central servers — and then used that foothold to reach every customer endpoint those servers managed. To stay in even after being partially evicted, attackers registered Cloudflare tunnels as persistent background services on compromised machines. N-able shipped a first fix that didn't fully close the hole; a complete patch (build 2026.3.1.7) only arrived August 2. The vulnerability is tracked as CVE-2026-18577.
A Chinese-speaking hacker is using the open-source DeepSeek AI model combined with an open-source tool called Hermes Agent to automatically find and attack internet-exposed servers — with very little human involvement. The AI scans for weaknesses, picks an attack method, and executes it on its own. This is an early real-world example of AI being used as an autonomous hacking tool, not just an assistant.
This flaw let attackers skip the login process entirely on N-central servers — a technique called authentication bypass. Once inside, they had full remote admin rights and could reach every computer the server managed. A first patch proved incomplete; attackers continued to operate. The full fix is build 2026.3.1.7, released August 2.
Status: Patch available — upgrade to build 2026.3.1.7 immediately.
This vulnerability affects software used in forensic DNA analysis labs. An attacker who gains access to the lab's systems could silently alter DNA data files before the analysis software reads them — and the changes would be nearly undetectable. In a criminal investigation context, that's a serious problem. Thermo Fisher has patched supported products by adding digital signatures to output files. Three older, end-of-life products will not receive patches.
Status: Patch available for supported products. End-of-life products have no fix — use additional lab controls.
A flaw in older COLDCARD hardware wallet firmware produced weak random number generation when creating wallet seed phrases. Seed phrases are the master keys to a crypto wallet — if they're not truly random, an attacker can guess them. Researchers believe this flaw is directly linked to the theft of approximately $88.6 million in Bitcoin from thousands of affected wallets.
Status: Firmware update available. If your wallet seed was generated on older firmware, consider moving funds to a freshly generated wallet.
Google is building a new Chrome security feature that would stop browser extensions from silently replacing your New Tab page or changing your default search engine without your permission. This specifically targets "policy-installed" extensions — ones pushed onto devices by employers or, in some cases, by malware pretending to be a legitimate IT policy. Hijacked New Tab pages are a classic way to redirect searches and serve ads or collect data. The feature isn't live yet, but Google is actively preparing it.
↗ BleepingComputerThe Arch Linux project has paused a feature that lets community members "adopt" and maintain packages in the Arch User Repository (AUR) after a wave of attackers took over legitimate, trusted packages and inserted malicious code. When you install a package from AUR, you trust whoever is maintaining it — and attackers have been snapping up unmaintained packages to slip in malware. The lockdown is temporary while the team works on stronger safeguards. If you use Arch Linux, be extra careful about AUR packages right now.
↗ BleepingComputerYou bought a $30 Android TV box online. It plays movies, streams everything, and never asks for a subscription. Sounds like a great deal. But new research from security firm Bitsight suggests those boxes may be quietly working a second job — faking ad clicks on fake websites — and you'd never know.
Researcher Pedro Falé stumbled onto the operation by registering an expired domain name that had been used to coordinate activity across tens of thousands of H96 streaming devices. When he looked at the traffic flowing to that domain, something immediately stood out: almost all of the TV boxes were identifying themselves as mobile phones — Samsung, Huawei, Xiaomi. They weren't, of course. But the spoofed identity was the point. The devices, all running apps from a Chinese company called Zhejiang Fengwo IoT Technology, were visiting a network of AI-generated websites stuffed with fake news articles about finance, health, food, and gaming. Those sites only showed ads when visited by something that looked like one of these specific spoofed phone profiles. Real human visitors saw nothing. The whole setup exists to generate fake ad revenue — a practice known as ad fraud. Bitsight traced the operation back to Fengwo Group, a mainland China company that also claims to operate over 120,000 AI-generated "digital humans" for customer service and companionship.
Meanwhile, smart TVs from major brands aren't completely off the hook either. A separate investigation found that more than 42% of apps available on LG's smart TV platform contained residential proxy SDKs — software that quietly routes strangers' internet traffic through your television. LG has now committed to suspending any app that doesn't remove this feature. Samsung's platform had similar issues in over a quarter of its apps.
The pattern here is worth paying attention to. Cheap, no-name streaming hardware and poorly vetted app stores are being turned into quiet infrastructure for fraud, surveillance, and traffic routing — all while sitting in your living room. The fix isn't complicated: stick to streaming devices from major, accountable brands (Roku, Apple TV, Amazon Fire TV), keep firmware updated, and think twice before sideloading apps from unknown sources.