Isometric network nodes illustrating critical cybersecurity flaws and automated ransomware attacks.

Daily Cybersecurity News - July 4, 2026

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

FatFs, the tiny filesystem library inside millions of embedded devices, just got seven vulnerabilities disclosed.

The flaws sit in how FatFs handles FAT and exFAT structures on USB drives and SD cards. runZero found the issues while examining firmware from security cameras and similar hardware.

FatFs ships in the firmware of cameras, industrial controllers, consumer gadgets, and anything else that reads or writes removable storage.

The library appears in over 1,200 open source projects on GitHub alone.

New Bad Epoll Linux Kernel Flaw Lets Unprivileged Users Gain Root Hits Android

Linux kernel flaw hands unprivileged users root on desktops, servers, and Android devices.

CVE-2026-46242 lives in the epoll subsystem. Attackers trigger a use-after-free with crafted event structures to overwrite kernel pointers and escalate privileges. CVSS 7.8, patch already released.

Affects kernels built on Linux 6.4 or newer unless patched, including affected Linux desktops, servers, and newer Android devices. Impacts any multi-user or containerized setup where low-privileged accounts exist.

Same code stretch that contained Anthropic's earlier mlock bug.

JadePuffer Ransomware Used AI Agent to Automate Entire Attack

A ransomware crew called JadePuffer ran an attack end-to-end with an AI agent instead of human operators.

They fed the large language model the target details and let it handle reconnaissance, credential access, lateral movement, and encryption without further input.

The novelty is the full automation loop. Most groups still keep a human in the chain for decision points even when they use AI for parts of the job.

Researchers flagged this as the first documented ransomware operation completed entirely by an LLM agent.

North Korean Hackers Push 108 Malicious Packages

Lazarus operators tied to the Contagious Interview operation are flooding open-source repositories with malware.

They published 108 packages across npm, Packagist, Go modules, and Chrome extensions. The packages use typosquatting and fake developer identities to reach developers.

This marks a shift from their usual job-interview lures. They are now embedding backdoors directly into developer tooling supply chains.

Campaign remains active with fresh packages still appearing as of July 2026.

NetNut Proxy Network Disrupted, 2 Million Devices Cut Off

Google and partners took down NetNut, a residential proxy service running on roughly two million compromised Android devices including smart TVs and streaming boxes.

The operation severed access for customers who paid to route traffic through those infected hosts. It hit the infrastructure hard enough to knock the whole network offline.

Real impact here. The devices stay infected but the proxy layer that monetized them is gone, at least for now.

Same crew rebuilt a prior network in under two weeks after an earlier disruption.