LIVE · cybersecurity feed
Live wire
CVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update releaseAttackers exploit zero-days in consistently besieged SonicWall productIntroducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsHPE patches critical ArubaOS-CX remote code execution flawCVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No Patch
security

Free streaming boxes may be routing criminal traffic through your home

Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.

zeroday.news ·

A recent investigation has revealed that certain SuperBox streaming devices and the CyberFlix TV application may be enrolling users' home internet connections into a residential proxy network, potentially allowing third parties to route traffic through their households. This activity could expose users to privacy risks, consume bandwidth, and associate their public IP addresses with illicit online activities.

The issue was initially identified in the CyberFlix TV app, which is available through SuperBox's custom app store. Researchers found that this application contains "Popanet" proxy functionality that registers the device with a server controlled by the proxy operator. Subsequent research indicates that these proxy networks can also serve as platforms for delivering additional malware to compromised devices.

Residential proxy networks operate by renting out ordinary home IP addresses to customers. This makes their internet traffic appear to originate from a legitimate consumer connection rather than a data center, which can help cybercriminals bypass IP-based fraud controls and reputation systems. Law enforcement agencies have previously warned that such proxies are used by "foreign entities" to conceal their identities and make their activities appear to come from someone else's home network. The FBI defines a residential proxy as an intermediary server that uses legitimate IP addresses assigned by an Internet Service Provider (ISP) to consumer IoT devices, such as streaming devices, to route traffic. Once compromised, a device's IP address can be used by threat actors to mask their online activity, potentially making the consumer appear responsible.

Beyond the impact on connectivity and the potential for a household's IP address to be linked to activities like credential stuffing, account abuse, or attempts to bypass enterprise security controls, the reported SuperBox configuration raises additional security concerns. Researchers discovered exposed Android Debug Bridge (ADB) access, root-level privileges without authentication, and the removal of protections that typically restrict untrusted app installation or prompt users to approve risky actions.

While many users might assume that placing a streaming device behind a home router offers sufficient protection, proxy-enabled devices can establish an encrypted outbound connection to a remote server. This creates a channel that the home router treats as legitimate traffic initiated from within the network, effectively bypassing typical network address translation and firewall protections against unsolicited inbound connections.

To mitigate these risks, users are advised against connecting devices or installing applications that promise unauthorized access to free movies and TV. If a SuperBox device is owned or CyberFlix TV has been installed, it is recommended to disconnect the device from the network. A factory reset may not be sufficient to secure the device, suggesting that replacement might be necessary. The core issue stems from a business model that monetizes user connections, which can compromise IP addresses, bandwidth, privacy, and local network security. Even network segmentation, such as placing the device on a separate guest network, may not fully address the risk posed by a product designed to establish a persistent proxy channel with weak device-level protection.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

nation-state

G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules

The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition

CVE-2026-14894critical

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

vulnerability

Most of the bugs Claude Mythos found have never been checked by a human

Anthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings became published security advisories, with counts current as of May 22, 2026. The other 21,119 candidates have not been reviewed by any

vulnerability

New infosec products of the week: September 4, 2026

Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’s AI-powered web application firewall (WAF) is capable in delivering real-time protections because of its strategic posi