Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.

A recent investigation has revealed that certain SuperBox streaming devices and the CyberFlix TV application may be enrolling users' home internet connections into a residential proxy network, potentially allowing third parties to route traffic through their households. This activity could expose users to privacy risks, consume bandwidth, and associate their public IP addresses with illicit online activities.
The issue was initially identified in the CyberFlix TV app, which is available through SuperBox's custom app store. Researchers found that this application contains "Popanet" proxy functionality that registers the device with a server controlled by the proxy operator. Subsequent research indicates that these proxy networks can also serve as platforms for delivering additional malware to compromised devices.
Residential proxy networks operate by renting out ordinary home IP addresses to customers. This makes their internet traffic appear to originate from a legitimate consumer connection rather than a data center, which can help cybercriminals bypass IP-based fraud controls and reputation systems. Law enforcement agencies have previously warned that such proxies are used by "foreign entities" to conceal their identities and make their activities appear to come from someone else's home network. The FBI defines a residential proxy as an intermediary server that uses legitimate IP addresses assigned by an Internet Service Provider (ISP) to consumer IoT devices, such as streaming devices, to route traffic. Once compromised, a device's IP address can be used by threat actors to mask their online activity, potentially making the consumer appear responsible.
Beyond the impact on connectivity and the potential for a household's IP address to be linked to activities like credential stuffing, account abuse, or attempts to bypass enterprise security controls, the reported SuperBox configuration raises additional security concerns. Researchers discovered exposed Android Debug Bridge (ADB) access, root-level privileges without authentication, and the removal of protections that typically restrict untrusted app installation or prompt users to approve risky actions.
While many users might assume that placing a streaming device behind a home router offers sufficient protection, proxy-enabled devices can establish an encrypted outbound connection to a remote server. This creates a channel that the home router treats as legitimate traffic initiated from within the network, effectively bypassing typical network address translation and firewall protections against unsolicited inbound connections.
To mitigate these risks, users are advised against connecting devices or installing applications that promise unauthorized access to free movies and TV. If a SuperBox device is owned or CyberFlix TV has been installed, it is recommended to disconnect the device from the network. A factory reset may not be sufficient to secure the device, suggesting that replacement might be necessary. The core issue stems from a business model that monetizes user connections, which can compromise IP addresses, bandwidth, privacy, and local network security. Even network segmentation, such as placing the device on a separate guest network, may not fully address the risk posed by a product designed to establish a persistent proxy channel with weak device-level protection.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed