Your TV Box Is Committing Fraud While You Sleep
Saturday, August 1, 2026 · 5-minute read
Russian intelligence-linked hackers (the group the U.S. and U.K. governments call APT29) have been hijacking hotel Wi-Fi networks to push fake browser updates onto guests' laptops. The malware installed — called CornFlake — can silently record your webcam, microphone, and every keystroke you type. Microsoft researchers tied the operation to a sub-group they track as Storm-2945, operating under the broader Midnight Blizzard umbrella.
↗ The Hacker NewsSuspected Chinese-speaking hackers have been quietly breaking into government networks across Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria since January 2025. They use two newly discovered backdoors called OctLurk and SilkLurk, which can download extra attack tools on demand. Targets include foreign ministries, law enforcement agencies, and public health organizations — suggesting this is classic espionage, not financial crime.
↗ The Hacker NewsThe U.S. cybersecurity agency CISA says attacks on internet-connected control systems inside water and wastewater facilities have jumped sharply. Hackers are targeting PLCs, the devices that actually control physical equipment like pumps and valves. A successful attack could disrupt water treatment or delivery for entire communities.
↗ CISAHackers tampered with a third-party script served by ad-tech company Adform, which is used by many websites. Between July 27 and the time Adform caught it, anyone who visited an affected site and copied a Bitcoin, Ethereum, or Tron wallet address had that address silently swapped for one controlled by the attacker. The swap happened both via clipboard copy and directly inside form fields — so even if you typed an address manually on an affected page, it may have been replaced. Adform says the script has been removed, but it may still be saved in your browser's local cache.
Amazon has confirmed that North Korean hackers were behind supply-chain attacks on the npm ecosystem — the giant library of free JavaScript code that millions of developers use every day. The poisoned packages were named "Debug" and "Chalk," mimicking two extremely popular, legitimate tools. Any developer who unknowingly installed the malicious versions may have introduced malware into software they were building.
This is as bad as it gets — a perfect 10.0 severity score. Adobe's enterprise marketing platform Campaign Classic has a flaw that lets an attacker run any code they want on a server, with zero clicks required from any user. An attacker just needs network access to the system. This affects large organizations that use Adobe's tools to run email marketing campaigns.
Status: Patch available. Update to ACC v7 build 9398 immediately. Adobe says it has not seen this exploited in the wild yet — but a perfect-score flaw won't stay quiet for long.
A second flaw in Adobe Campaign Classic, this one an SQL injection vulnerability. An attacker could use it to read any file on the server's file system — think configuration files, credentials, private data. It doesn't run code on its own, but the information it leaks could enable far worse attacks.
Status: Patch available in the same update as the critical flaw above (ACC v7 build 9398). Apply now.
Broadcom patched five vulnerabilities in VMware products — including three critical ones. The worst allow attackers to bypass login authentication entirely, run arbitrary code, or escape from a virtual machine to take over the host server underneath it. VMware is used by countless businesses to run their server infrastructure.
Status: Patches released for vCenter, ESX, Workstation, and Fusion. If your IT team runs VMware, this needs immediate attention.
Google says artificial intelligence is now finding and fixing security vulnerabilities in the Chrome browser at a scale humans alone never could. More than 1,072 security bugs were patched across Chrome's two most recent releases — a dramatic increase directly tied to AI-assisted code analysis. Google is using AI to both hunt for new vulnerabilities and write the fixes. This doesn't mean Chrome is suddenly perfect, but it does mean one of the most widely used pieces of software on earth is getting safer, faster. It's a notable sign that AI is starting to pay real dividends in defensive security, not just offensive attacks.
If you bought one of those inexpensive Android TV streaming boxes — the kind that promises "unlimited free content" for a one-time fee of $30 or $40 — there's a real chance it's secretly moonlighting as a fraud machine while you watch TV. Researchers at Bitsight have uncovered a large, sophisticated operation running quietly inside a popular brand called H96, and the scale of it is genuinely surprising.
Here's how researcher Pedro Falé cracked it open: he registered an expired domain name that used to be controlled by the operation. Once he owned it, traffic from tens of thousands of H96 devices around the world started flowing to him — essentially checking in with what they thought was their controller. What he found was striking. Every single device was pretending to be a smartphone — a Samsung, a Huawei, a Vivo — not the TV box it actually was. The operation, traced to a Chinese company called Zhejiang Fengwo IoT Technology, runs a network of AI-generated websites stuffed with fake news articles and blog posts. These sites only show ads when the visiting "device" matches the spoofed mobile profile. Then the TV boxes click those ads, generating fraudulent ad revenue. It's a closed loop: Fengwo makes the fake sites, the fake sites serve ads, and the hijacked TV boxes in people's living rooms click the ads. The only loser is the advertiser paying for clicks that no real human ever sees.
For regular people, the immediate harm is subtle — your internet connection gets used without your permission, your TV box runs extra processes that can slow things down, and you're unknowingly participating in a fraud scheme. But residential proxy abuse also has a darker side: these same networks can be rented out to hide the origin of real cyberattacks or to bypass geo-restrictions on services. This week also saw LG announce it will suspend smart TV apps that contain proxy SDKs after researchers found over 42% of LG's webOS app store contained them. Samsung's platform wasn't far behind at over 25%.
The lesson here is uncomfortable but worth sitting with: the "smart" devices in your home are computers, and if they're made cheaply by companies you've never heard of, you have very little visibility into what they're actually doing. Before buying a streaming device, stick to well-known brands with established security track records. If you already own an H96 or similar no-name Android TV box, consider whether the free content is worth the trade-off. And if your home internet feels slower than it should, a mystery device on your network could be one reason why.