threat-intel American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials An American man is facing prosecution for wiping his GrapheneOS-powered phone before handing it over to border officials. The feature, designed to protect user data by erasing the device upon incorrect passcode entry, ha… Schneier on Security · Jul 30, 2026 Medium privacysecurityconstitution
vulnerability Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser Researchers at Nebula Security discovered a vulnerability in Firefox's JIT compiler that allows a single malicious webpage visit to compromise the browser, including Tor Browser. This vulnerability, CVE-2026-10702, can b… The Hacker News · Jul 29, 2026 High CVE-2026-10702CVE-2026-43499jitsifirefoxexploit
threat-intel Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates A remote access trojan (RAT) called Flying Eagle, along with a related control kit called Night Dragon, is circulating through criminal Telegram channels. Researchers have identified 170 servers hosting the RAT framework… The Hacker News · Jul 29, 2026 High CNandroidrattelegram
vulnerability igloohome Smart Lock Mobile Application A vulnerability in the igloohome Smart Lock Mobile Application (Android 3.2.3) allows an unauthorized actor to access backend services. This could enable access to sensitive functionality and potentially compromise the s… CISA Advisories · Jul 28, 2026 Medium CVE-2026-16581vulnerabilitycwe-540smart lock
vulnerability Johnson Controls XAAP Android A vulnerability exists in the Johnson Controls XAAP Android application, version 1.53 and earlier. Attackers with physical access to a device could potentially read sensitive data stored locally without encryption. This… CISA Advisories · Jul 23, 2026 High CVE-2026-34490vulnerabilityandroidcleartext storage
threat-intel Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious Android application, dubbed ‘BH Alert,’ is being distributed through fake Google Play sites mimicking Bahraini government entities to deliver a four-stage surveillance platform. The app leverages users' trust… Dark Reading · Jul 22, 2026 High BHKUandroidspywaremalware
threat-intel Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini AI assistant on Android 16 devices has a vulnerability that allows unauthorized users to send SMS and WhatsApp messages from a locked phone. This is achieved through a specific multi-touch gesture when Ge… Graham Cluley · Jul 17, 2026 Medium androidgeminilock screen
supply-chain E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants The European Commission has ordered Google to allow rival AI assistants on Android to access device features like the microphone, camera, and screen, effectively dismantling Google's control over these functionalities. T… The Hacker News · Jul 17, 2026 High aiandroiddata-sharing
threat-intel Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking A University of Michigan, New Mexico, and IIT Delhi study found that 281 popular free Android VPN apps on the Google Play Store have significant security flaws, including leaking user traffic, sending data in plain text,… The Hacker News · Jul 10, 2026 High CVE-2016-6329CVE-2016-2183vpnandroidsecurity
threat-intel RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service A new Android malware operation, RedWing, is being sold on Telegram as a ready-made bank fraud service. Developed by a Russian threat actor group, RedWing allows even unskilled criminals to steal banking logins and one-t… The Hacker News · Jul 7, 2026 High RUandroidmalwarefraud
vulnerability New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android A newly discovered Linux kernel vulnerability, dubbed "Bad Epoll" (CVE-2026-46242), allows unprivileged users to gain root access on systems, including Android devices. The flaw, a "use-after-free" bug, was identified by… The Hacker News · Jul 3, 2026 High CVE-2026-46242CVE-2026-43074CVE-2026-31431USUKlinuxkernelepoll
vulnerability AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks Researchers have identified six security flaws in AirDrop and Quick Share, wireless file-sharing features used on Apple and Samsung devices. These vulnerabilities allow an attacker within range to trigger crashes, bypass… The Hacker News · Jun 30, 2026 High CVE-2024-38271CVE-2024-38272CVE-2024-10668USGBairdropquicksharecrash
vulnerability Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks Researchers discovered a long-standing vulnerability (CVE-2026-20971) in Samsung’s KNOX kernel across numerous Galaxy devices, from S9 to S25. The flaw, a race-condition use-after-free (UAF), allowed for potential kernel… SecurityWeek · Jun 23, 2026 High uafkernelrace condition
threat-intel Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google is implementing a new Android developer verification system, starting September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand, to combat app scams and malware. This will block installations of apps from… The Hacker News · Jun 22, 2026 Medium BRIDSGapp scamsdeveloper verificationopen source
threat-intel ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm A sprawling Android botnet called Popa, used for advertising fraud, account takeovers, and data scraping, has been linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd. Researchers discovere… Krebs on Security · Jun 18, 2026 High ISbotnetproxyandroid
malware New Rokarolla Android malware targets 217 banking, crypto apps A new Android banking trojan, Rokarolla, is targeting 217 banking and cryptocurrency applications through deceptive app distribution and sophisticated data theft techniques. The malware leverages Accessibility permission… BleepingComputer · Jun 16, 2026 High androidbanking trojandata theft
malware Rokarolla Android Trojan Levels Up to Full Device Control, Persistence The Rokarolla Android Trojan has evolved to offer full device control and persistence, moving beyond typical banking Trojan capabilities. Distributed through fake Chrome and TikTok downloads, the malware steals credentia… Dark Reading · Jun 16, 2026 High USandroidbanking trojandevice control
malware New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds A new Android banking trojan, Rokarolla, has been identified by Zimperium, targeting over 200 banking and cryptocurrency apps. The malware utilizes techniques like fake login pages and Accessibility abuse to steal sensit… The Hacker News · Jun 16, 2026 High androidbanking trojanpin theft
malware NFCShare Android malware spreads via fake banking app updates on GitHub A new variant of the NFCShare Android malware is spreading through fake updates for banking apps hosted on GitHub, targeting financial institutions across Europe. The malware leverages NFC technology to steal payment car… BleepingComputer · Jun 8, 2026 High ITSPGEnfcandroidbanking
threat-intel WhatsApp, Slack Notifications Could Hijack Google Gemini on Android This article details a vulnerability in Google Gemini on Android that allows malicious notifications from apps like WhatsApp, Slack, or SMS to hijack the voice assistant and perform actions such as opening windows, launc… The Hacker News · Jun 3, 2026 High voice assistantprompt injectionandroid