threat-intel Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover A coding error in several Microsoft 365 Android applications, specifically Excel, Word, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot, exposed user accounts to potential compromise. The issue stemmed from a disabl… Dark Reading · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102authenticationtokensandroid
vulnerability Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag A vulnerability in Microsoft 365 Android apps allowed unauthorized apps to steal user account tokens, potentially granting access to sensitive data like emails and calendar information. The flaw, discovered by Enclave, s… The Hacker News · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102androidtokenspoofing
vulnerability Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk A critical vulnerability was discovered in six Microsoft 365 Android apps – Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote – due to a debug flag left enabled in production code. This allowed… SecurityWeek · Jun 2, 2026 Critical CVE-2026-41100USdebugaccess tokensupply chain
vulnerability Google fixes one actively exploited Android zero-day, 124 flaws Google has released a significant security update addressing 124 vulnerabilities in Android, including a previously exploited zero-day vulnerability (CVE-2025-48595). This update focuses on mitigating targeted attacks an… BleepingComputer · Jun 2, 2026 High CVE-2025-48595CVE-2025-48633CVE-2025-48572zero-dayandroidvulnerability
supply-chain OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack A supply chain attack targeting OpenAI Codex developers has been discovered through a malicious npm package named ‘codexui-android’. The package, developed by ‘friuns’ (Igor Levochkin) and promoted by ‘BrutalStrike’, sil… The Hacker News · Jun 1, 2026 High USsupply chainauthenticationtokens
malware BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model An advanced Android remote access Trojan, BTMOB RAT, is spreading across Brazil and Latin America through a malware-as-a-service (MaaS) model. Delivered via a no-code interface, it allows cybercriminals to create malicio… Dark Reading · May 28, 2026 High BRARandroidratmaas
threat-intel BTMOB: A stealthy RAT burrowing deep into Android devices BTMOB is a stealthy Android remote access trojan (RAT) that’s rapidly evolving and spreading through phishing campaigns and a ‘malware-as-a-service’ model. It allows attackers to steal data, take control of devices, and… WeLiveSecurity · May 26, 2026 High ARandroidmalwareremote access trojan
malware Fake Android Apps Commit Carrier Billing Fraud for Premium Svcs. A coordinated campaign targeting Android users in Malaysia, Thailand, Romania, and Croatia has been identified, utilizing fake apps disguised as popular services to commit carrier billing fraud. The malware, employing te… Dark Reading · May 20, 2026 High MYTHROandroidcarrier billingfraud
malware Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps A new Android ad fraud scheme, dubbed Trapdoor, has been identified by HUMAN Threat Intelligence, utilizing 455 malicious apps and 183 C2 domains to generate 659 million daily bid requests. The operation leverages malver… The Hacker News · May 19, 2026 High USandroidad fraudmalvertising
threat-intel IT threat evolution in Q1 2026. Mobile statistics This Securelist report analyzes mobile threat trends in Q1 2026, based on Kaspersky Security Network data. The report highlights a decrease in overall attack volume, primarily due to reduced adware and RiskTool detection… Securelist · May 18, 2026 Medium USmobile malwarebanking trojancrypto stealer
threat-intel A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Google Project Zero researchers discovered a critical 0-click vulnerability in the Google Pixel 10's VPU driver, allowing for arbitrary kernel code execution. The vulnerability stems from a flaw in the `vpu_mmap` functio… Google Project Zero · May 13, 2026 Critical CVE-2025-54957zero-clickkernel-exploitationdriver-vulnerability
malware Fake call logs, real payments: How CallPhantom tricks Android users This report details a widespread Android scam, dubbed CallPhantom, where fraudulent apps masquerading as call log retrieval services tricked users into paying for randomly generated data. Twenty-eight apps, collectively… WeLiveSecurity · May 7, 2026 Medium INscamfraudandroid
threat-intel A rigged game: ScarCruft compromises gaming platform in a supply-chain attack A North Korean-aligned APT group, ScarCruft (also known as APT37 or Reaper), conducted a supply-chain attack targeting a video game platform used by ethnic Koreans in the Yanbian region of China. The attackers injected a… WeLiveSecurity · May 5, 2026 High CNKPsupply-chainnorth-koreaespionage
malware New NGate variant hides in a trojanized NFC payment app A new variant of the NGate malware, dubbed NGate, is targeting Android users in Brazil by abusing the legitimate HandyPay app. Threat actors used generative AI to modify HandyPay, allowing them to steal NFC data, includi… WeLiveSecurity · Apr 21, 2026 High BRnfcandroidmalware