2026-10-02 14:30 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-10-02 14:30 UTC
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek.
P0
2026-10-02 08:01 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 08:20 UTC
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a
P0
2026-10-01 16:00 UTC
Vendor Research
Google Security Blog · Il-Sung Lee · indexed 2026-10-01 16:20 UTC
A woman with Advanced Protection on Android enabled on her phone
P0
2026-09-30 14:00 UTC
Security Journalism
The Record · indexed 2026-09-30 14:25 UTC
'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.
P0
2026-09-29 21:30 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-29 21:35 UTC
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...]
P0
2026-09-28 17:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 18:40 UTC
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,
P0
2026-09-25 10:53 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-25 11:00 UTC
Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events. The post Windows, Linux, Android File Notification Systems Leak User Activity appeared first on SecurityWeek.
P0
2026-09-24 18:10 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 19:00 UTC
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not
P0
2026-09-24 12:05 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 12:15 UTC
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM
P0
2026-09-23 21:25 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-23 21:40 UTC
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]
P0
2026-09-23 07:26 UTC
Other
Group-IB · indexed 2026-09-23 08:10 UTC
Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.
P0
2026-09-21 12:51 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-21 12:55 UTC
The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion. The post RatHat Android Trojan Uses AI for Automation appeared first on SecurityWeek.
P0
2026-09-18 10:04 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-18 10:50 UTC
RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve traced to China-based operators, and what makes it different isn’t the credential theft, which is […]
P0
2026-09-18 06:17 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 06:30 UTC
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses
P0
2026-09-17 21:50 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-17 22:00 UTC
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]
P0
2026-09-17 20:00 UTC
Vendor Research
Google Security Blog · Maunik Shah · indexed 2026-09-17 20:25 UTC
Security State Library
P5
2026-09-16 07:00 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-16 07:15 UTC
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]
P25
2026-09-11 20:19 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-11 20:20 UTC
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
P0
2026-09-11 01:00 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-11 01:15 UTC
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
P0
2026-09-10 21:40 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 21:45 UTC
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]
P15
2026-09-10 17:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 19:00 UTC
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already
P0
2026-09-10 14:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 14:45 UTC
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their
P0
2026-09-10 13:39 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-10 13:50 UTC
Deceptive apps in Early Access are being used by dishonest developers for their own benefit. The post Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews appeared first on SecurityWeek.
P0
2026-09-10 11:33 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 13:15 UTC
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That
P0
2026-09-09 16:30 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 16:50 UTC
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components. The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek.
P15
2026-09-09 07:06 UTC
Other
Group-IB · indexed 2026-09-09 07:35 UTC
How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.
P0
2026-09-08 18:07 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-09-08 18:20 UTC
104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain Serv…
P65
2026-09-08 11:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 13:20 UTC
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since
P0
2026-09-02 12:22 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 13:45 UTC
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union
P0
2026-09-01 12:00 UTC
Vendor Research
Google Security Blog · Eric Lynch · indexed 2026-09-01 12:15 UTC
Checking phone to see image of digital credential
P0