-
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].
·
A Little Sunshine, Alarum Technologies Ltd, BadBox 2.0, Black Lotus Labs, Brendan O’Connell, Chris Formosa, Confederation of Open Access Repositories, CRICFy, CyberFlix, David Brunsdon, Directory of Open Access Journals, DooFlix, Flixoid, Include Security, Jérôme Meyer, Latest Warnings, LG, Lumen Technologies, NetNut, Nick Sundvall, Ninajtech, Nokia Deepfield, OceanStreams, Popa botnet, Qurium, Rapid Streamz, residential proxies, RoboVPN, RTS Tv, Samsung, Sean Simmons, Sprozfy, Spur, Synthient, The Coming Storm, TvMob, Vo1d botnet¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers — including Apple, Google, Microsoft, Mozilla and Oracle — fixing near record volumes of security bugs, and/or quickening the tempo of their patch releases.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed “BlueHammer.” Separately, Google Chrome fixed its fourth zero-day of 2026, and an emergency update for Adobe Reader nixes an actively exploited flaw that can lead to remote code execution.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


