Security News

Cybersecurity news aggregator

INFO News The Hacker News

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

  • What: ThreatsDay Bulletin covers various security topics including smart TV proxyware and AI crime forums.
  • Impact: Cybersecurity professionals and organizations interested in emerging threats.
Read Full Article →

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories  Ravie Lakshmanan  Jun 25, 2026 Hacking News / Cybersecurity News It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence, and “normal” workflows turning into phishing pipes because apparently email was not enough hell already. The worst part is how cheap some of it feels. Not elite. Not cinematic. Just stale secrets, fake updates, lazy trust, and random boxes quietly becoming someone else’s infrastructure. Same internet, fresh headache. Let’s get into it. Privacy-first bot defense Cloudflare Partners With Browser Makers for PACT Cloudflare has teamed up with Google Chrome, Microsoft Edge, and Mozilla Firefox to create a privacy-preserving protocol that websites can use to separate desirable web traffic from undesirable network requests. This involves the use of Private Access Control Tokens (PACT), which allow websites to issue anonymous tokens that assert a given browsing session is being run by a human. "A user's browser can then provide these tokens to other sites to prove that a human is in the loop, reducing the need for annoying and clunky captchas or invasive tracking," Cloudflare said . "PACT is designed so that sites cannot leverage it to track or identify users or their browsing history." Six curl CVEs Multiple Flaws in curl AISLE said it discovered six vulnerabilities in curl, which range from "classic memory-lifetime issues to logic bugs in how libcurl decides whether a connection, credential, or host identity is still valid." One of the notable vulnerabilities is CVE-2026-8932 , which allows the library to "reuse a previously created connection even when some mTLS config-related option had been changed that should have prohibited reuse." AISLE described it as the oldest curl vulnerability reported so far, adding that it has been shipped in releases since curl version 7.7 , which was released on March 22, 2001. The identified flaws have been addressed in version 8.21.0 . Unauthenticated takeover Maximum-Severity Bug in Hoppscotch A critical security flaw has been disclosed in self-hosted versions of Hoppscotch(CVE-2026-50160, CVSS score: 10.0), an open source API platform, that can result in complete compromise. Offgrid Security's autonomous AI security agent, Kiro, has been credited with discovering the bug. "The POST /v1/onboarding/config endpoint allows an unauthenticated attacker to inject arbitrary InfraConfig keys -- including JWT_SECRET and SESSION_SECRET -- into the database via mass assignment," the project maintainers said . "These keys are not declared in the SaveOnboardingConfigRequest DTO, but because the NestJS ValidationPipe does not strip extra properties, they pass through to the service layer, where Object.entries(dto) iterates all keys without restriction." A successful exploitation leads to full server compromise and persistent access that survives password resets. OffGrid Security told The Hacker News that four independent weaknesses are combined to allow an unauthenticated attacker to overwrite the JWT signing key in a single HTTP request, and the exploit requires no credentials. The issue has been fixed in hoppscotch-backend version 2026.5.0. Proxyware in smart TVs Residential Proxy SDKs Hidden in LG and Samsung Smart TV Apps A new report from Spur Intelligence has revealed that more than one-third of LG and Samsung smart TV apps it reviewed contain proxyware that can relay third-party traffic through the TV owner's internet connection with users' consent. The company said it scanned 6,038 apps across LG webOS and Samsung Tizen and found 2,058 that contain residential proxy software. This includes clocks, screensavers, games, fish tanks, and other low-utility apps. On LG webOS, 42.5% of apps carried such code. On Samsung Tizen, the rate was 26.9%. Across both platforms, it reached 34.1%. Bright Data, Massive, and Oxylabs take up the top three SDK providers for webOS and Tizen. "Smart TVs are almost ideal proxy hosts. They sit on the same home network as everything else, but they do not feel like computers, so people rarely audit them like computers," Spur said. "There is no battery drain to notice, no cellular bill to spike, no app switcher full of suspicious background activity. A TV can stay plugged in, signed in, and online for years while the user thinks of it as furniture." The threat intelligence firm said this dynamic also changes the consent equation, as users may not realize what it actually means to sell access to their residential IP address. "Technically, these applications are compliant with gaining consent based on how they inform the user," Spur CTO Alastair Parr told The Hacker News. "However, there is often no verification that the user is either of age or authorized to provide consent on the device. The reality is that there are likely many smart TVs scattered across office spaces and residential homes, quietly part of these networks, without the responsible owners' awareness or consent." Amazon's Device and System Abuse Policy explicitly bars apps that facilitate proxy services for third parties. Similar protections have been enabled by Roku as well. However, LG and Samsung are yet to enforce an equivalent policy. Edgecution via Teams Payouts King Ransomware IAB Deploys Edgecution Malware An initial access broker (IAB) affiliated with Payouts King ransomware has been observed masquerading as IT personnel in social engineering attacks conducted via Microsoft Teams to deliver a malicious Microsoft Edge browser extension dubbed Edgecution. "The technique utilizes a malicious Microsoft Edge browser extension that exploits the Chrome native messaging protocol to interact with host-native applications beyond the confines of the browser sandbox," Zscaler ThreatLabz said . "By abusing this interface, the attackers gain direct host access, enabling them to manipulate the local filesystem, launch processes, and execute arbitrary code on the compromised host." The malware has two components: a Microsoft Edge browser extension named "Edge Monitoring Agent" that beacons to a command-and-control (C2) server and relays host-based commands to a Python-based backdoor, which can collect system information, enumerate running processes, provide filesystem access, and execute arbitrary Python code and shell commands. The extension will be invisible to a user as it's loaded in a headless Microsoft Edge browser. A similar attack chain involving a Chromium-based extension codenamed SNOWBELT was detailed by Google-owned Mandiant in April 2026. Legacy credential breach Klue Says Stolen Credential Dates Back to 2022 Competitive intelligence company Klue has revealed that a credential dating back to 2022, which was used as part of a limited pilot, was exploited by the Icarus extortionists to steal Salesforce data from its corporate customers, including several cybersecurity companies. In a statement shared with TechCrunch, the company said the credential was "originally provided to a third-party in 2022, for a limited pilot." Klue did not share specifics about the purpose of the pilot, the duration for which it ran, or the identity of the third-party to whom the company gave the credentials. It's also unclear why the credential wasn't revoked immediately, assuming the pilot had concluded. Questions remain about how the attackers managed to acquire this legacy credential in the first place. A number of companies have come forward to confirm they have had limited Salesforce information stolen during the attack, including 8x8, BeyondTrust, Gong, Jamf, HackerOne, Insurity, LastPass, OneTrust, Pendo, Recorded Future, Snyk, Sprout Social, and Tanium. State-crime convergence Nation-State Actors Adopt Cybercriminal Tactics NCC Group said it has found growing evidence of nation-state actors increasingly leveraging tools and tactics traditionally associated with financially motivated cybercrime to disguise their espionage and intelligence-gathering operations, blurring the line between the two sets of activities. "Historically, organisations could draw a relatively clear distinction between ransomware attacks driven by financial gain and nation-state operations designed to support strategic objectives. That distinction is becoming increasingly difficult to make," Matt Hull, VP of Cyber Intelligence and Response at NCC Group, said . "What we're seeing is a convergence of criminal and state-backed activity. Threat actors are sharing infrastructure, adopting common tooling and, in some cases, deliberately operating behind established ransomware brands to obscure attribution and delay response efforts." Admin reset alerts Google Expands Admin Password Reset Alerts Google said it's expanding the existing "Super Admin password reset" alert into a broader Admin password reset alert in Alert Center . "Previously, this rule only triggered alerts when a super admin's password was changed," the company said . "With this update, the alert will now cover password resets for all administrator roles within your organization. This update provides admins with better visibility and control over the security of their organization's privileged accounts. Monitoring password changes for all admin roles provides a higher level of oversight to respond more quickly to potential account compromises or unauthorized changes." The change is applicable to all Google Workspace customers. ClickFix targets macOS New ClickFix Attack Mounts DMG Images to Deliver macOS Infostealer A new ClickFix campaign has been observed tricking users into copying malicious commands and pasting them to the Terminal app that silently downloads and mounts a malicious DMG file. The disk image file contains a self-signed information stealer that can harvest a user's system password, data from we

Share this article