threat-intel 'Yellow Teams' Are Defining the Future of AI Security A growing trend of ‘yellow teams’ – engineering groups building both attack and defense tools – is emerging as a crucial response to the increasing threat of AI-powered cyberattacks. These teams are using advanced AI mod… Dark Reading · Jul 13, 2026 High aicybersecurityvulnerability
threat-intel Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking A University of Michigan, New Mexico, and IIT Delhi study found that 281 popular free Android VPN apps on the Google Play Store have significant security flaws, including leaking user traffic, sending data in plain text,… The Hacker News · Jul 10, 2026 High CVE-2016-6329CVE-2016-2183vpnandroidsecurity
threat-intel RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service A new Android malware operation, RedWing, is being sold on Telegram as a ready-made bank fraud service. Developed by a Russian threat actor group, RedWing allows even unskilled criminals to steal banking logins and one-t… The Hacker News · Jul 7, 2026 High RUandroidmalwarefraud
vulnerability New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android A newly discovered Linux kernel vulnerability, dubbed "Bad Epoll" (CVE-2026-46242), allows unprivileged users to gain root access on systems, including Android devices. The flaw, a "use-after-free" bug, was identified by… The Hacker News · Jul 3, 2026 High CVE-2026-46242CVE-2026-43074CVE-2026-31431USUKlinuxkernelepoll
threat-intel 'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat This article details a new supply chain threat dubbed "Phantom Squatting," where large language models (LLMs) are hallucinating non-existent web domains linked to legitimate brands. Cybercriminals are exploiting this by… Dark Reading · Jul 1, 2026 High USllmsupply chainai
threat-intel Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data This report details a new security vulnerability impacting AI agent-based systems, specifically leveraging the Model Context Protocol (MCP). Attackers can inject malicious instructions into tool descriptions used by AI a… The Hacker News · Jun 30, 2026 High N/aiagentsupply-chain
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
vulnerability AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks Researchers have identified six security flaws in AirDrop and Quick Share, wireless file-sharing features used on Apple and Samsung devices. These vulnerabilities allow an attacker within range to trigger crashes, bypass… The Hacker News · Jun 30, 2026 High CVE-2024-38271CVE-2024-38272CVE-2024-10668USGBairdropquicksharecrash
threat-intel Justices rule that cellphone location histories are protected by the Fourth Amendment The Supreme Court ruled that police use of cellphone location history data obtained from tech companies constitutes a Fourth Amendment search and requires a warrant. This decision effectively rejects the "third-party doc… The Record · Jun 29, 2026 High USfourth amendmentlocation trackingprivacy
threat-intel Surviving the Mythos Era: Richard Bejtlich on the Case for NDR This article discusses the challenges security teams face in investigating incidents due to the increasing volume of telemetry data and the accelerating pace of vulnerability discovery – often referred to as the ‘Mythos… The Hacker News · Jun 25, 2026 Medium UKnetwork detectionthreat huntingai
threat-intel Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google is implementing a new Android developer verification system, starting September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand, to combat app scams and malware. This will block installations of apps from… The Hacker News · Jun 22, 2026 Medium BRIDSGapp scamsdeveloper verificationopen source
vulnerability In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum This week’s cybersecurity news highlights several significant vulnerabilities and attacks across various platforms and industries. A critical phpBB flaw enabled session hijacking, while vulnerabilities in Chrome extensio… SecurityWeek · Jun 19, 2026 High CVE-2025-20701CHISsession hijackingchrome extensionssupply chain attack
threat-intel ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm A sprawling Android botnet called Popa, used for advertising fraud, account takeovers, and data scraping, has been linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd. Researchers discovere… Krebs on Security · Jun 18, 2026 High ISbotnetproxyandroid
threat-intel AI Use by the US Government This article details the widespread and largely undocumented use of Artificial Intelligence (AI) by the US government under both the Trump and Biden administrations. The Office of Management and Budget (OMB) revealed a m… Schneier on Security · Jun 17, 2026 Medium USaigovernmentautomation
malware New Rokarolla Android malware targets 217 banking, crypto apps A new Android banking trojan, Rokarolla, is targeting 217 banking and cryptocurrency applications through deceptive app distribution and sophisticated data theft techniques. The malware leverages Accessibility permission… BleepingComputer · Jun 16, 2026 High androidbanking trojandata theft
malware New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds A new Android banking trojan, Rokarolla, has been identified by Zimperium, targeting over 200 banking and cryptocurrency apps. The malware utilizes techniques like fake login pages and Accessibility abuse to steal sensit… The Hacker News · Jun 16, 2026 High androidbanking trojanpin theft
threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
phishing FBI disrupts massive AI-powered phishing service using a million URLs The FBI, in collaboration with Google and Black Lotus Labs, successfully disrupted a large-scale Chinese phishing-as-a-service operation called Outsider Enterprise. This operation utilized AI to generate and distribute p… BleepingComputer · Jun 14, 2026 High CHphishingaisms
threat-intel Yarbo Android/iOS Mobile Application and Cloud Infrastructure A CISA advisory details a vulnerability in the Yarbo Android/iOS Mobile Application and Cloud Infrastructure, specifically related to hard-coded MQTT credentials. The application contains credentials that allow unauthori… CISA Advisories · Jun 11, 2026 High CVE-2026-10557CVE-2026-7368WOmqttcredentialsrobotics
threat-intel Hackers pose as women seeking romance to spy on Russian soldiers A previously unknown cyber espionage group, SiribClone, has been targeting Russian military personnel by impersonating women seeking romantic relationships. The group’s primary goal is to gather battlefield intelligence… The Record · Jun 9, 2026 High RUespionagesocial-engineeringmobile-malware