← All issues
cybersecurityCyberBubblead-fraud

Your TV Is Clicking Fake Ads — Plus an $88M Bitcoin Heist and a 9.4 cPanel Flaw

🌐  World Intel
UK: Data on 100,000+ Police Officers Leaked After PNLD Breach

A group calling itself ExfilSquad hit the UK's Police National Legal Database and walked away with contact information for more than 100,000 police officers and criminal justice staff. That's names, email addresses, and phone numbers for a huge chunk of the country's law enforcement community. Data like this is gold for anyone who wants to phish or physically intimidate officers.

↗ BleepingComputer
Russia: Midnight Blizzard Targets Hotel Wi-Fi to Hijack Microsoft 365 Accounts

Microsoft has tied a global campaign targeting hotel Wi-Fi networks to the Russian state-backed group Midnight Blizzard. The attackers plant custom malware on hospitality networks and use it to steal Microsoft 365 credentials from guests — especially business travelers who log in while staying at hotels. If you connect to hotel Wi-Fi and check work email, you could be a target.

↗ BleepingComputer
USA: Amgen Cloud Breach Exposes Patient Health and Proprietary Drug Data

Pharmaceutical giant Amgen says attackers broke into cloud systems run by third-party vendors and stole both patient health information and sensitive corporate data — potentially including drug development secrets. The company has not said how many patients are affected. Third-party cloud breaches are increasingly common, and they're hard to defend against because you're trusting someone else's security team to protect your most sensitive data.

↗ BleepingComputer
⚔️  Active Attacks
DOUBLECUP: Malware Hiding Inside Your Browser's Image Cache

A Russian loader-as-a-service called DOUBLECUP is tricking people through ClickFix lures — fake error pop-ups that tell you to paste a command to fix a problem. Once you do, it quietly drops a hidden image into your browser's cache. That image secretly contains malware code. The hidden payload then installs CountLoader (which works on both Windows and Mac) and a new remote access trojan called DeviceManager. The DeviceManager trojan uses a technique called EtherHiding to receive instructions, making it very hard to shut down.

🛡 What to do: Never paste commands into your terminal or browser address bar because a website or pop-up told you to — no legitimate software update ever requires this. If you see this prompt, close the tab immediately.
N-able N-central Auth Bypass Exploited in the Wild — MSPs Under Fire

Hackers are actively exploiting a patched-but-not-really flaw in N-able N-central, a tool that managed service providers use to remotely manage thousands of client computers. The bug (CVE-2026-18577) lets an attacker skip the login screen entirely and take full admin control of the N-central server. From there, they can push software — including malware — to every machine the MSP manages. CISA has added it to its list of known exploited vulnerabilities, meaning real attacks are confirmed.

🛡 What to do: If your IT provider uses N-able N-central, ask them today whether they've updated to version 2026.3 HF1. If they haven't patched yet, your organization's devices could be at risk.
🔓  New Vulnerabilities
CVE-2026-58048 cPanel & WHM / WP Squared CRITICAL 9.4

cPanel is the control panel software that runs on a huge number of shared web hosting servers worldwide. This flaw lets any customer with a basic hosting account run database commands as the server's all-powerful database administrator — a bit like giving a hotel guest the master key to every room. In some server configurations, that database access can be used as a stepping stone to take over the entire server's operating system. Any website hosted on a vulnerable server, even those belonging to other customers, could be at risk.

Status: Patch available. cPanel has released fixed builds (11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, and 138.1.6 for WP Squared). If you run a website on shared hosting, contact your hosting provider and ask if their cPanel version is patched.

CVE-2026-18577 N-able N-central HIGH 8.2

This is an authentication bypass in N-able N-central — the IT management platform widely used by companies that manage computers for other businesses. An attacker anywhere on the internet can exploit this to gain full admin access without needing a password. Because N-central is designed to control large fleets of computers, one compromised server can quickly become a launchpad to infect hundreds or thousands of client machines. This is an incomplete fix for a previous bug (CVE-2026-18556), meaning the original patch didn't fully close the hole.

Status: Patch available in version 2026.3 HF1. Actively exploited — CISA has added this to its Known Exploited Vulnerabilities catalog, meaning federal agencies must patch immediately. All N-central users should treat this as urgent.

CVE-2026-COLDCARD COLDCARD Hardware Wallet Firmware HIGH — $88.6M Bitcoin Stolen

A flaw in the hardware wallet firmware used by COLDCARD devices allowed a bad RNG to generate weak wallet seeds. A wallet seed is the master key to all your cryptocurrency. If your seed was generated with this flawed firmware, attackers could predict or reconstruct it and drain your funds. An estimated $88.6 million in Bitcoin has already been stolen from affected wallets.

Status: Firmware update available. If you own a COLDCARD wallet, update your firmware immediately and check whether your wallet was created during the vulnerable period. Consider moving funds to a freshly generated wallet as a precaution.

🛠  New Tech
Pass-ta-key: Researchers Demo Three Attacks Against Google-Synced Passkeys

Security researchers have discovered three new attack methods — collectively nicknamed "Pass-ta-key" — that can abuse passkeys synced through Google Password Manager. The attacks require malware to already be running on a Windows device, but from there they can steal the private key behind your passkeys, bypass user verification steps, and take over accounts. This matters because passkeys were widely promoted as a phishing-proof replacement for passwords — these findings show they're still vulnerable once a device itself is compromised. The researchers disclosed their findings to Google. The takeaway isn't to abandon passkeys — they're still far better than passwords — but to remember that keeping your device malware-free is the real first line of defense.

↗ BleepingComputer
💡  Deep Dive
Your Smart TV Is Secretly Someone Else's Internet Connection — And Now It's Clicking Fake Ads Too

Cheap streaming boxes and smart TV apps have a dirty secret: many of them are renting out your home internet connection to strangers. New research published today goes even further — it turns out some of these devices are also pretending to be mobile phones and clicking fake ads on AI-generated websites, committing large-scale fraud while your TV sits idle on the shelf.

Security researcher Pedro Falé at Bitsight got a lucky break when he registered an expired domain name that used to belong to the H96 TV streaming device ecosystem. He discovered that tens of thousands of H96 devices were still phoning home to that domain — and almost all of them were lying about what they were. Instead of identifying as TV boxes, they were claiming to be Samsung, Vivo, Huawei, and Xiaomi smartphones. Why? Because the ad fraud scheme only paid out when a "mobile phone" visited. The devices were being used to click ads on a network of AI-generated junk websites — fake news blogs about finance, health, and food — all operated by a Chinese company called Zhejiang Fengwo IoT Technology. That company, it turns out, also rents out over 120,000 "AI digital humans" for companionship and customer service. Quite the side hustle.

Meanwhile, LG has separately announced it will suspend any smart TV app that includes a residential proxy SDK — after researchers found that more than 42% of apps on its webOS store were turning LG TVs into proxy nodes. Samsung's Tizen platform had similar problems, with over a quarter of its apps affected. These proxy networks let criminals disguise their internet traffic as coming from real households, which helps them commit fraud, bypass geo-blocks, and avoid detection.

The implications for everyday people are real. If your TV or streaming box is part of one of these networks, crimes committed using your IP address could be traced back to you. Your internet bandwidth is being consumed without your consent. And the same companies building these devices have shown they're perfectly willing to hide this behavior in the fine print — or not disclose it at all. The fix is unglamorous: stick to name-brand streaming devices from companies with reputations to protect, keep firmware updated, and think twice before plugging in that suspiciously cheap 4K streaming stick you found for $18. If the hardware is nearly free, your internet connection might be the real product.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →