Security researchers have recently uncovered widespread digital threats, ranging from pre-installed malware on budget Android streaming devices to sophisticated supply chain attacks and data breaches at major corporations.
Key Points
- Cheap Android streaming boxes were found pre-loaded with the Vo1d botnet, which enables ad-click fraud, residential proxy abuse, and unauthorized remote access.
- A researcher discovered that registering expired domains allowed for the potential hijacking of sensitive VoIP calls intended for military bases via the abandoned e164-arpa protocol.
- AliExpress is utilizing advanced browser fingerprinting, including silent audio waveform analysis, to track users even when traditional cookies are disabled.
- Signal patched two vulnerabilities in its Intel SGX Enclave contact discovery process that could have allowed attackers to extract private user contact lists.
- Boston Scientific operations were disrupted by an unspecified cyberattack, while Carhartt suffered a ransomware breach resulting in the leak of 13 million customer accounts.
- AI agents like Claude and Codex were observed executing malicious code hidden within website llms.txt files, posing significant risks to corporate data security.