AUTO-UPDATED

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

Cybersecurity threats this week highlight a surge in social engineering, legacy credential exploitation, and the weaponization of routine productivity tools to bypass traditional enterprise security defenses.

Key Points

  • Cloudflare introduced the Private Access Control Token (PACT) protocol to help browsers verify human users without relying on invasive tracking or traditional captchas.
  • A critical unauthenticated remote code execution flaw (CVE-2026-50160) in the Hoppscotch API platform allowed attackers to gain full server control via mass assignment vulnerabilities.
  • Research from Spur Intelligence found that over 34% of apps on LG and Samsung smart TVs contain proxyware that can relay third-party traffic through home networks.
  • Two members of the Scattered Spider criminal collective were convicted for a 2024 cyberattack on Transport for London that resulted in $38.2 million in losses.
  • Threat actors are increasingly using Microsoft 365 collaboration features, such as shared group mailboxes and calendar invites, to conduct sophisticated phishing campaigns.
  • Censys identified 8,500 global REDCap research servers, which have been targeted by the China-nexus group UNC6508 to exfiltrate sensitive clinical and military data.

Why it Matters

The current threat landscape demonstrates that attackers are successfully shifting away from complex exploits toward abusing trusted workflows and legacy infrastructure. Organizations must prioritize auditing forgotten credentials and securing non-traditional devices, as these "boring" vulnerabilities remain the most effective entry points for modern cybercriminals.
Internet Published by info@thehackernews.com (The Hacker News)
Read original