Germany's Federal Office of Information Security (BSI) disrupted a malware operation known as BADBOX, which came pre-installed on at least 30,000 internet-connected devices sold within the country. These devices, including digital picture frames, media players, and low-cost Android devices, were found to have outdated Android versions and embedded malware upon delivery. By sinkholing the command-and-control (C2) domains, the BSI severed communication between the infected devices and their operators, significantly mitigating the threat. Users were advised to disconnect these devices from the internet immediately. The BADBOX malware, first identified in 2023 by HUMAN's Satori Threat Intelligence team, utilized the Triada Android malware to target supply chain vulnerabilities. This malware enabled data theft, installation of additional malicious payloads, and the operation of a fraudulent ad botnet named PEACHPIT. PEACHPIT spoofed legitimate apps to generate fake ad impressions, exploiting infected devices for programmatic advertising fraud. Additionally, BADBOX devices were leveraged as residential proxies, enabling threat actors to route traffic and create online accounts while evading detection. The operation is suspected to have been orchestrated by actors based in China. The BSI's sinkholing operation redirected BADBOX device traffic, involving internet providers with over 100,000 subscribers to enforce the redirection. This initiative highlighted the risks of unvetted supply chains and cheap off-brand devices in enabling sophisticated cyberattacks. The incident underscores the need for consumers to vet purchases and for manufacturers to address supply chain vulnerabilities to prevent preloaded malware infections on devices.
On September 15, 2025, Apple rolled out a significant security update for iOS 26 and iPadOS 26, addressing 27 vulnerabilities across 23 critical system components. The update suppo...
Two medium-severity vulnerabilities, CVE-2025-41248 and CVE-2025-41249, have been discovered in Spring Security and Spring Framework, impacting method-level security in enterprise ...
Security researcher BitsByWill recently analyzed two critical Linux kernel vulnerabilities—CVE-2023-52440 and CVE-2023-4130—impacting the in-kernel SMB server (ksmbd). The firs...