It’s not surprising when the guy who’s been yelling about the horrors of late-stage capitalism on Instagram for the last five years turns his ire towards ICE. But something different has been happening over the week or so, following the most recent shootings of civilians by federal agents — even accounts that stay laser focused on golfing, chopping wood, and playing cats like bongos have started to speak out.
Technology
Why your Android TV box may secretly be a part of a botnet
NEWYou can now listen to Fox News articles!
Android TV streaming boxes that promise “everything for one price” are everywhere right now.
You’ll see them on big retail sites, in influencer videos, and even recommended by friends who swear they’ve cut the cord for good. And to be fair, they look irresistible on paper, offering thousands of channels for a one-time payment. But security researchers are warning that some of these boxes may come with a hidden cost.
In several cases, devices sold as simple media streamers appear to quietly turn your home internet connection into part of larger networks used for shady online activity. And many buyers have no idea it’s happening.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
WHY JANUARY IS THE BEST TIME TO REMOVE PERSONAL DATA ONLINE
Android TV streaming boxes promising unlimited channels for a one-time fee may quietly turn home internet connections into proxy networks, according to security researchers. (Photo By Paul Chinn/The San Francisco Chronicle via Getty Images)
What’s inside these streaming boxes
According to an investigation by Krebs on Security, media streaming devices don’t behave like ordinary media streamers once they’re connected to your network. Researchers closely examine SuperBox, which is an Android-based streaming box sold through third-party sellers on major retail platforms. On paper, SuperBox markets itself as just hardware. The company claims it doesn’t pre-install pirated apps and insists users are responsible for what they install. That sounds reassuring until you look at how the device actually works.
To unlock the thousands of channels SuperBox advertises, you must first remove Google’s official app ecosystem and replace it with an unofficial app store. That step alone should raise eyebrows. Once those custom apps are installed, the device doesn’t just stream video but also begins routing internet traffic through third-party proxy networks.
What this means is that your home internet connection may be used to relay traffic for other people. That traffic can include ad fraud, credential stuffing attempts and large-scale web scraping.
During testing by Censys, a cyber intelligence company that tracks internet-connected devices, SuperBox models immediately contacted servers tied to Tencent’s QQ messaging service, run by Tencent, as well as a residential proxy service called Grass.
Grass describes itself as an opt-in network that lets you earn rewards by sharing unused internet bandwidth. This suggests that SuperBox devices may be using SDKs or tooling that hijack bandwidth without clear user consent, effectively turning the box into a node inside a proxy network.
Why SuperBox activity resembles botnet behavior
In simple terms, a botnet is a large group of compromised devices that work together to route traffic or perform online tasks without the owners realizing it.
Researchers discovered SuperBox devices contained advanced networking and remote access tools that have no business being on a streaming box. These included utilities like Tcpdump and Netcat, which are commonly used for network monitoring and traffic interception.
The devices performed DNS hijacking and ARP poisoning on local networks, techniques used to redirect traffic and impersonate other devices on the same network. Some models even contained directories labeled “secondstage,” suggesting additional payloads or functionality beyond streaming.
SuperBox is just one brand in a crowded market of no-name Android streaming devices. Many of them promise free content and quick setup, but often come preloaded with malware or require unofficial app stores that expose users to serious risk.
In July 2025, Google filed a lawsuit against operators behind what it called the BADBOX 2.0 botnet, a network of more than ten million compromised Android devices. These devices were used for advertising fraud and proxy services, and many were infected before consumers even bought them.
Around the same time, the Feds warned that compromised streaming and IoT devices were being used to gain unauthorized access to home networks and funnel traffic into criminal proxy services.
We reached out to SuperBox for comment but did not receive a response before our deadline.
8 steps you can take to protect yourself
If you already own one of these streaming boxes or are thinking about buying one, these steps can help reduce your risk significantly.
1) Avoid devices that require unofficial app stores
If a streaming box asks you to remove Google Play or install apps from an unknown marketplace, stop right there. This bypasses Android’s built-in security checks and opens the door to malicious software. Legitimate Android TV devices don’t require this.
2) Use strong antivirus software on your devices
Even if the box itself is compromised, strong antivirus software on your computers and phones can detect suspicious network behavior, malicious connections or follow-on attacks like credential stuffing. Strong antivirus software monitors behavior, not just files, which matters when malware operates quietly in the background. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
3) Put streaming devices on a separate or guest network
If your router supports it, isolate smart TVs and streaming boxes from your main network. This prevents a compromised device from seeing your laptops, phones or work systems. It’s one of the simplest ways to limit damage if something goes wrong.
4) Use a password manager
If your internet connection is being abused, stolen credentials often come next. A password manager ensures every account uses a unique password, so one leak doesn’t unlock everything. Many password managers also refuse to autofill on suspicious or fake websites, which can alert you before you make a mistake.
MAKE 2026 YOUR MOST PRIVATE YEAR YET BY REMOVING BROKER DATA
Investigators warn some Android-based streaming boxes route user bandwidth through third-party servers linked to ad fraud and cybercrime. (Photo Illustration by Thomas Fuller/SOPA Images/LightRocket via Getty Images)
Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2026 at Cyberguy.com.
5) Consider using a VPN for sensitive activity
A VPN won’t magically fix a compromised device, but it can reduce exposure by encrypting your traffic when browsing, banking or working online. This makes it harder for third parties to inspect or misuse your data if your network is being relayed.
For the best VPN software, see my expert review of the best VPNs for browsing the web privately on your Windows, Mac, Android and iOS devices at Cyberguy.com.
6) Watch your internet usage and router activity
Unexpected spikes in bandwidth, slower speeds or strange outbound connections can be warning signs. Many routers show connected devices and traffic patterns.
If you notice suspicious traffic or behavior, unplug the streaming box immediately and perform a factory reset on your router. In some cases, the safest option is to stop using the device altogether.
Also, make sure your router firmware is up to date and that you’ve changed the default admin password. Compromised devices often try to exploit weak router settings to persist on a network.
7) Be wary of “free everything” streaming promises
Unlimited premium channels for a one-time fee usually mean you’re paying in some other way, often with your data, bandwidth or legal exposure. If a deal sounds too good to be true, it usually is.
8) Consider a data removal service
If your internet connection or accounts have been abused, your personal details may already be circulating among data brokers. A data removal service can help opt you out of people-search sites and reduce the amount of personal information criminals can exploit for follow-up scams or identity theft. While it won’t fix a compromised device, it can limit long-term exposure.
10 SIMPLE CYBERSECURITY RESOLUTIONS FOR A SAFER 2026
Cyber experts say certain low-cost streaming devices behave more like botnet nodes than legitimate media players once connected to home networks. (Photo by Alessandro Di Ciommo/NurPhoto via Getty Images)
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.
Kurt’s key takeaway
Streaming boxes like SuperBox thrive on frustration. As subscriptions pile up, people look for shortcuts. But when a device promises everything for nothing, it’s worth asking what it’s really doing behind the scenes. Research shows that some of these boxes don’t just stream TV. They quietly turn your home network into a resource for others, sometimes for criminal activity. Cutting the cord shouldn’t mean giving up control of your internet connection. Before plugging in that “too good to be true” box, it’s worth slowing down and looking a little closer.
Would you still use a streaming box if it meant sharing your internet with strangers? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Creators and communities everywhere take a stand against ICE
The tenor on social media and Reddit took an even sharper turn yesterday, following the killing of Alex Pretti by ICE. Even the moderator of normally politics-free r/catbongos (a subreddit “Where gentlemen, gentlewomen, and gentlethems of quality gather to watch cats being played like bongos”) spokeout in a post where they declared that “If you still support Trump/ICE even slightly, you’re not welcome in this sub.”
That quilters on Instagram or a Facebook account dedicated to New England gravestones have decided enough, is enough, is one thing. But, judging from the comments, it seems like the government has lost the support of r/military as well. The subreddit is filled with angry posters decrying that “this is exactly what tyranny looks like” and sharing memes mocking Secretary of Defense Pete Hegseth. One poster claiming to be an active member of the U.S. Army who has served for 21 years said, “these guys are against all we stand for as Americans. Modern day brownshirts.”
All across Reddit, subs are being inundated with anti-ICE posts. From r/Fauxmoi, to r/NFCNorthMemeWar, and r/DungeonCrawlerCarl. There’s even been some limited signs of revolt among the members of r/conservative, some of whom have taken issue with Kristi Noem’s description of Alexi Pretti as a “domestic terrorist,” and suggested that she should “just be quiet for a while.” And arguments have broken out among community members over perceived hypocrisy around the Second Amendment.
Some big names have also joined the chorus, including Joe Santagato of The Basement Yard podcast, who posted that what was occurring on the streets of Minneapolis was “legit horrifying.” And when someone told him to “Stay out of politics,” and “get back to spitting water out of your mouth and de-jumbling words with your idiot friends.” He shot back, “De-jumble this: ksuc ym slalb.”
Canadian wrestlers and social media influencers Chris and Patrick Vörös have spoken out previously about their anti-ICE views, but took the opportunity to remind people of the only two ICE agents they support. Educational YouTube channel Primer also took to X to say this is no longer about politics, but about the “fabric of society.”
Canadian musician bbno$ decided to break his silence, even if it risked his visa and his current U.S. tour, to throw his support behind the abolish ICE movement. Even Thoren Bradley, the Axe Man himself, whose whole schtick is being a ripped rural dude who chops wood, has decided to call out the hypocrisy of the Christian conservatives to his 10.7 million followers.
That creators like Hank Green are speaking out is no surprise. But when fitness influencers, duck-painting TikTokers, football subreddits, and even Second Amendment rights activists have finally broken their silence, it seems like the government has lost control of the narrative. No matter how hard they try to spin it.
Let us know in the comments what other creators and communities have begun to speakout in the comments.
Updated January 25th: Added additional information about Reddit communities.
Technology
Google Fast Pair flaw lets hackers hijack headphones
NEWYou can now listen to Fox News articles!
Google designed Fast Pair to make Bluetooth connections fast and effortless. One tap replaces menus, codes and manual pairing. That convenience now comes with serious risk. Security researchers at KU Leuven uncovered flaws in Google’s Fast Pair protocol that allows silent device takeovers. They named the attack method WhisperPair. An attacker nearby can connect to headphones, earbuds or speakers without the owner knowing. In some cases, the attacker can also track the user’s location. Even more concerning, victims do not need to use Android or own any Google products. iPhone users are also affected.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
APPLE WARNS MILLIONS OF IPHONES ARE EXPOSED TO ATTACK
Fast Pair makes connecting Bluetooth headphones quick, but researchers found that some devices accept new pairings without proper authorization. (Kurt “CyberGuy” Knutsson)
What WhisperPair is and how it hijacks Bluetooth devices
Fast Pair works by broadcasting a device’s identity to nearby phones and computers. That shortcut speeds up pairing. Researchers found that many devices ignore a key rule. They still accept new pairings while already connected. That opens the door to abuse.
Within Bluetooth range, an attacker can silently pair with a device in about 10 to 15 seconds. Once connected, they can interrupt calls, inject audio or activate microphones. The attack does not require specialized hardware and can be carried out using a standard phone, laptop, or low-cost device like a Raspberry Pi. According to the researchers, the attacker effectively becomes the device owner.
Audio brands affected by the Fast Pair vulnerability
The researchers tested 17 Fast Pair compatible devices from major brands, including Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech and Google. Most of these products passed Google certification testing. That detail raises uncomfortable questions about how security checks are performed.
How headphones can become tracking devices
Some affected models create an even bigger privacy issue. Certain Google and Sony devices integrate with Find Hub, which uses nearby devices to estimate location. If a headset has never been linked to a Google account, an attacker can claim it first. That allows continuous tracking of the user’s movements. If the victim later receives a tracking alert, it may appear to reference their own device. That makes the warning easy to dismiss as an error.
GOOGLE NEST STILL SENDS DATA AFTER REMOTE CONTROL CUTOFF, RESEARCHER FINDS
Attacker’s dashboard with location from the Find Hub network. (KU Leuven)
Why many Fast Pair devices may stay vulnerable
There is another problem most users never consider. Headphones and speakers require firmware updates. Those updates usually arrive through brand-specific apps that many people never install. If you never download the app, you never see the update. That means vulnerable devices could remain exposed for months or even years.
The only way to fix this vulnerability is by installing a software update issued by the device manufacturer. While many companies have released patches, updates may not yet be available for every affected model. Users should check directly with the manufacturer to confirm whether a security update exists for their specific device.
Why convenience keeps creating security gaps
Bluetooth itself was not the problem. The flaw lives in the convenience layer built on top of it. Fast Pair prioritized speed over strict ownership enforcement. Researchers argue that pairing should require cryptographic proof of ownership. Without it, convenience features become attack surfaces. Security and ease of use do not have to conflict. But they must be designed together.
Google responds to the Fast Pair WhisperPair security flaws
Google says it has been working with researchers to address the WhisperPair vulnerabilities and began sending recommended patches to headphone manufacturers in early September. Google also confirmed that its own Pixel headphones are now patched.
In a statement to CyberGuy, a Google spokesperson said, “We appreciate collaborating with security researchers through our Vulnerability Rewards Program, which helps keep our users safe. We worked with these researchers to fix these vulnerabilities, and we have not seen evidence of any exploitation outside of this report’s lab setting. As a best security practice, we recommend users check their headphones for the latest firmware updates. We are constantly evaluating and enhancing Fast Pair and Find Hub security.”
Google says the core issue stemmed from some accessory makers not fully following the Fast Pair specification. That specification requires accessories to accept pairing requests only when a user has intentionally placed the device into pairing mode. According to Google, failures to enforce that rule contributed to the audio and microphone risks identified by the researchers.
To reduce the risk going forward, Google says it updated its Fast Pair Validator and certification requirements to explicitly test whether devices properly enforce pairing mode checks. Google also says it provided accessory partners with fixes intended to fully resolve all related issues once applied.
On the location tracking side, Google says it rolled out a server-side fix that prevents accessories from being silently enrolled into the Find Hub network if they have never been paired with an Android device. According to the company, this change addresses the Find Hub tracking risk in that specific scenario across all devices, including Google’s own accessories.
Researchers, however, have raised questions about how quickly patches reach users and how much visibility Google has into real-world abuse that does not involve Google hardware. They also argue that weaknesses in certification allowed flawed implementations to reach the market at scale, suggesting broader systemic issues.
For now, both Google and the researchers agree on one key point. Users must install manufacturer firmware updates to be protected, and availability may vary by device and brand.
SMART HOME HACKING FEARS: WHAT’S REAL AND WHAT’S HYPE
Unwanted tracking notification showing the victim’s own device. (KU Leuven)
How to reduce your risk right now
You cannot disable Fast Pair entirely, but you can lower your exposure.
1) Check if your device is affected
If you use a Bluetooth accessory that supports Google Fast Pair, including wireless earbuds, headphones or speakers, you may be affected. The researchers created a public lookup tool that lets you search for your specific device model and see whether it is vulnerable. Checking your device is a simple first step before deciding what actions to take. Visit whisperpair.eu/vulnerable-devices to see if your device is on the list.
2) Update your audio devices
Install the official app from your headphone or speaker manufacturer. Check for firmware updates and apply them promptly.
3) Avoid pairing in public places
Pair new devices in private spaces. Avoid pairing in airports, cafés or gyms where strangers are nearby.
4) Factory reset if something feels off
Unexpected audio interruptions, strange sounds or dropped connections are warning signs. A factory reset can remove unauthorized pairings, but it does not fix the underlying vulnerability. A firmware update is still required.
5) Turn off Bluetooth when not needed
Bluetooth only needs to be on during active use. Turning off Bluetooth when not in use limits exposure, but it does not eliminate the underlying risk if the device remains unpatched.
6) Reset secondhand devices
Always factory reset used headphones or speakers before pairing them. This removes hidden links and account associations.
7) Take tracking alerts seriously
Investigate Find Hub or Apple tracking alerts, even if they appear to reference your own device.
8) Keep your phone updated
Install operating system updates promptly. Platform patches can block exploit paths even when accessories lag behind.
Kurt’s key takeaways
WhisperPair shows how small shortcuts can lead to large privacy failures. Headphones feel harmless. Yet, they contain microphones, radios and software that need care and updates. Ignoring them leaves a blind spot that attackers are happy to exploit. Staying secure now means paying attention to the devices you once took for granted.
Should companies be allowed to prioritize fast pairing over cryptographic proof of device ownership? Let us know by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
On the ground in Minneapolis after the killing of Alex Pretti
Steven Garcia, as told to Gaby Del Valle:
I was in the middle of a frozen lake when I got the notification from the Minnesota Star Tribune that there had been a shooting. I was on assignment at a pond hockey event, and someone who was supposed to play later that evening said he probably wouldn’t be able to make it — they knew there would be protests and demonstrations happening.
I arrived a little over three hours later. Federal officers had already cleared the scene — the FBI had been there investigating — so the only law enforcement present were state and local officials: the Minneapolis Police Department, their SWAT team, the Hennepin County Sheriff’s Office, and the Minnesota State Patrol.
There were protesters at multiple intersections. People had blocked off the streets with trash cans and dumpsters, and there were mattresses on the ground. Protesters were heckling officers, but there were no physical altercations. Eventually law enforcement retreated by a block and started throwing tear gas. They drove their trucks over the mattresses as they left.
When those tear gas canisters go off, they pop and bang, kind of like a firework. Dozens of canisters were going off. Even initially, there were four, five, six canisters at a time that they were throwing. I had to duck in an alley for a little bit because it got through my mask. It’s not a fun experience, even in very small amounts. You have to keep your eyes closed. It burns your eyes, it burns your mouth. For some people, it causes nausea and burning on the skin. Another local reporter told me his neck was burning and he had to use a decon wipe.
I think because of George Floyd in 2020, people knew how to respond. Gregory Bovino, the head of the US Border Patrol who has been here the whole time, has said community members in Minneapolis are really prepared. A lot of people I’ve talked to have said, “I had my respirator ready from 2020,” and they just restocked on safety supplies, decon wipes, and first aid kits. Even if they weren’t immediately prepared, they could rapidly respond to these kinds of events. At all the events I’ve been to, people will set a table to hand out food and water and hand warmers. It was especially cold today — it wasn’t supposed to get above 0 degrees.
After the officers cleared the scene, everyone convened at the intersection of 26th and Nicolette, just a couple hundred feet from where Alex Pretti was shot. Some community members started a makeshift vigil for him at the location where he was killed. People were spelling his name out with pinecones and starting to leave flowers.
-
Sports1 week agoMiami’s Carson Beck turns heads with stunning admission about attending classes as college athlete
-
Illinois3 days agoIllinois school closings tomorrow: How to check if your school is closed due to extreme cold
-
Pittsburg, PA6 days agoSean McDermott Should Be Steelers Next Head Coach
-
Politics1 week agoNoem names Charles Wall ICE deputy director following Sheahan resignation
-
Lifestyle7 days agoNick Fuentes & Andrew Tate Party to Kanye’s Banned ‘Heil Hitler’
-
Technology1 week agoCasting is dead. Long live casting!
-
Culture1 week agoWhat Kind of Lover Are You? This William Blake Poem Might Have the Answer.
-
Sports6 days agoMiami star throws punch at Indiana player after national championship loss