ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much.
20 articles
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much.
Google turned on a transfer feature in Android that moves passwords and passkeys straight from one password manager to another, with no file to download alon...
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. E...
Deceptive apps in Early Access are being used by dishonest developers for their own benefit. The post Deceptive Android Apps Exploit Google Play Early Access...
MantaxOtax Android malware combines ransomware with extensive spyware capabilities
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, sec...
Amazon elected Kevin Mandia to its Board of Directors on September 8. Mandia founded Mandiant and served as its CEO before Google acquired the firm in Septem...
The BlueMoon exploit kit targeted U.S.
The WeWorm tool exploits a zero-click remote code execution vulnerability in WeChat's voice-over-IP stack.
Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG. The post AI Is Giving Lesser-Resou...
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components. The post Android’s September 2026 Updates Patch 180 Vu...
A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.
The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabil...
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to too...
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google relea...
ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
A multi-stage malware operation that combines fake Google CAPTCHA prompts, WebDAV-hosted DLL execution, malicious Cloudflare Workers and BNB Smart Chain smar...
A critical vulnerability has been identified in the Fortinet FortiPAM Chrome extension that could allow a malicious website to manipulate browser proxy setti...