threat-intel Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google is implementing a new Android developer verification system, starting September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand, to combat app scams and malware. This will block installations of apps from… The Hacker News · Jun 22, 2026 Medium BRIDSGapp scamsdeveloper verificationopen source
vulnerability In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum This week’s cybersecurity news highlights several significant vulnerabilities and attacks across various platforms and industries. A critical phpBB flaw enabled session hijacking, while vulnerabilities in Chrome extensio… SecurityWeek · Jun 19, 2026 High CVE-2025-20701CHISsession hijackingchrome extensionssupply chain attack
threat-intel ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm A sprawling Android botnet called Popa, used for advertising fraud, account takeovers, and data scraping, has been linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd. Researchers discovere… Krebs on Security · Jun 18, 2026 High ISbotnetproxyandroid
malware New Rokarolla Android malware targets 217 banking, crypto apps A new Android banking trojan, Rokarolla, is targeting 217 banking and cryptocurrency applications through deceptive app distribution and sophisticated data theft techniques. The malware leverages Accessibility permission… BleepingComputer · Jun 16, 2026 High androidbanking trojandata theft
malware New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds A new Android banking trojan, Rokarolla, has been identified by Zimperium, targeting over 200 banking and cryptocurrency apps. The malware utilizes techniques like fake login pages and Accessibility abuse to steal sensit… The Hacker News · Jun 16, 2026 High androidbanking trojanpin theft
threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
phishing FBI disrupts massive AI-powered phishing service using a million URLs The FBI, in collaboration with Google and Black Lotus Labs, successfully disrupted a large-scale Chinese phishing-as-a-service operation called Outsider Enterprise. This operation utilized AI to generate and distribute p… BleepingComputer · Jun 14, 2026 High CHphishingaisms
threat-intel Yarbo Android/iOS Mobile Application and Cloud Infrastructure A CISA advisory details a vulnerability in the Yarbo Android/iOS Mobile Application and Cloud Infrastructure, specifically related to hard-coded MQTT credentials. The application contains credentials that allow unauthori… CISA Advisories · Jun 11, 2026 High CVE-2026-10557CVE-2026-7368WOmqttcredentialsrobotics
threat-intel Hackers pose as women seeking romance to spy on Russian soldiers A previously unknown cyber espionage group, SiribClone, has been targeting Russian military personnel by impersonating women seeking romantic relationships. The group’s primary goal is to gather battlefield intelligence… The Record · Jun 9, 2026 High RUespionagesocial-engineeringmobile-malware
threat-intel Will AI Kill the Bug Bounty Industry? This article discusses the potential disruption of the bug bounty industry by advancements in artificial intelligence, specifically Anthropic’s Claude Mythos model. The rise of AI-powered tools like Claude is enabling bo… SecurityWeek · Jun 9, 2026 Medium aiartificial intelligencebug bounty
malware NFCShare Android malware spreads via fake banking app updates on GitHub A new variant of the NFCShare Android malware is spreading through fake updates for banking apps hosted on GitHub, targeting financial institutions across Europe. The malware leverages NFC technology to steal payment car… BleepingComputer · Jun 8, 2026 High ITSPGEnfcandroidbanking
threat-intel UK gives big tech 3 months to create device controls to block nude images of kids The UK government is mandating that major tech companies, including Apple and Google, implement device controls within three months to block nude images of children from smartphones and tablets. This initiative aims to c… The Record · Jun 8, 2026 High UKchild sexual abuseonline safetydevice security
threat-intel ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cyberc… The Hacker News · Jun 8, 2026 High CVE-2025-48595CVE-2026-28318CVE-2026-39210CHUSGEsupply-chainzero-daycybercrime
threat-intel FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins A wave of fraudulent activity targeting FIFA World Cup 2026 fans is underway, involving fake websites, banking malware, and stolen login credentials. The operation, spearheaded by the Chinese-speaking group ‘GHOST STADIU… The Hacker News · Jun 5, 2026 High USCAMXfraudphishingmalware
threat-intel Apple removes Russia’s state-backed messaging app Max from its store Apple removed the state-backed Russian messaging app Max from its App Store, citing sanctions regulations. This action has drawn criticism from Russian officials who view it as an unfriendly move and has impacted the app… The Record · Jun 4, 2026 Medium RUsanctionsrussiamessaging
threat-intel WhatsApp, Slack Notifications Could Hijack Google Gemini on Android This article details a vulnerability in Google Gemini on Android that allows malicious notifications from apps like WhatsApp, Slack, or SMS to hijack the voice assistant and perform actions such as opening windows, launc… The Hacker News · Jun 3, 2026 High voice assistantprompt injectionandroid
threat-intel Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover A coding error in several Microsoft 365 Android applications, specifically Excel, Word, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot, exposed user accounts to potential compromise. The issue stemmed from a disabl… Dark Reading · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102authenticationtokensandroid
threat-intel Google adds Android protection against AI deepfake scam calls Google is launching a new Android security feature, "fake call detection," to combat increasingly sophisticated scams utilizing AI-generated deepfake calls. The system works by verifying call authenticity in real-time, a… BleepingComputer · Jun 3, 2026 High USdeepfakeaiscam
vulnerability Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk A critical vulnerability was discovered in six Microsoft 365 Android apps – Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote – due to a debug flag left enabled in production code. This allowed… SecurityWeek · Jun 2, 2026 Critical CVE-2026-41100USdebugaccess tokensupply chain
vulnerability Google fixes one actively exploited Android zero-day, 124 flaws Google has released a significant security update addressing 124 vulnerabilities in Android, including a previously exploited zero-day vulnerability (CVE-2025-48595). This update focuses on mitigating targeted attacks an… BleepingComputer · Jun 2, 2026 High CVE-2025-48595CVE-2025-48633CVE-2025-48572zero-dayandroidvulnerability