🚨 ACTIVE EXPLOITS & INCIDENTS
- NetNut proxy network disrupted, 2 million infected devices cut off — BleepingComputer A coordinated takedown involving Google dismantled the NetNut residential proxy network, which leveraged millions of compromised Android devices including smart TVs and streaming boxes. This disruption cuts off a major source of abused infrastructure used for fraud, scraping, and anonymized attacks.
🔓 VULNERABILITIES & CVEs
- New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android — The Hacker News CVE-2026-46242 is a critical Linux kernel vulnerability (CVSS 9.1) allowing local unprivileged users full root control. It affects Linux desktops, servers, and Android devices. A patch is available; immediate kernel updates are strongly advised to prevent privilege escalation attacks.
🕵️ THREAT RESEARCH & DEEP DIVES
- New Avalon Malware Framework Packs CrownX Ransomware Capabilities — The Hacker News Researchers uncovered "Avalon," a modular malware framework distributed via multi-stage phishing that bypasses traditional defenses. Avalon integrates credential theft, lateral movement, remote access, recovery disruption, and ransomware (CrownX), representing a sophisticated all-in-one threat chain.
- North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets — The Hacker News North Korean threat actors deployed malicious npm packages ("rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core") impersonating legitimate Rollup polyfill tooling. These packages enable remote access and exfiltration of developer secrets, highlighting ongoing supply chain risks in open source ecosystems.
📰 LESSER-KNOWN / UNDER-REPORTED
- ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit — BleepingComputer A new phishing-as-a-service platform, ARToken, linked to EvilTokens affiliates, offers an extensive Microsoft 365 credential harvesting toolkit. This PhaaS lowers barriers for phishing campaigns targeting enterprise cloud environments, signaling increased phishing sophistication and scale.
- In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting — SecurityWeek Notable updates include the sentencing of a Canadian hacker tied to Anonymous, disclosure of zero-days in open source projects by a security researcher, and US sentencing of Venezuelan nationals for ATM jackpotting schemes. These underscore ongoing legal and threat actor activity trends.