A streaming box shouldn’t need a threat model. Neither should a username field or a browser permission prompt. That’s the frustrating part this week: the dangerous stuff looked ordinary.
Google, the FBI, and Lumen took down the NetNut residential proxy network (also called Popa). It was massive — at least 2 million devices globally. The trick: NetNut hid SDKs in smart TVs and streaming boxes. People bought devices with malware pre-installed or downloaded apps with hidden proxy code. Attackers routed traffic through these home devices to mask their activity. Google disabled accounts and apps tied to the operation, building on the IPIDEA takedown from January.
WhatsApp is finally getting usernames. You’ll be able to connect with people without sharing your phone number. The feature is rolling out globally later this year. But India — their biggest market — has concerns about impersonation. Meta says it reserves usernames for public figures and government entities, but it’s not clear how they decide which lookalikes get blocked.
Security researchers, watch what you download. A new trojan called ChocoPoC is spreading through fake PoC exploit repos on GitHub. The proof-of-concept code looks clean, but the malware sits in a dependency named “skytext.” It steals passwords, cookies, browser history, text files, and more from Chrome, Brave, Edge, and Firefox. Also runs arbitrary commands on your machine.
A 19-year-old suspected Scattered Spider member was extradited to the US. Peter Stokes (aka Bouquet, Spencer, Jordan) has dual US and Estonian citizenship. More details as they come.
Keep your home devices patched. Don’t download sketchy PoCs. And yes, we’re at the point where you need to think twice about what your streaming box is doing.
