threat-intel ToxicPanda Banking Trojan Matures into Enterprise Threat ToxicPanda, a banking Trojan, has evolved into a more sophisticated enterprise threat, expanding its reach beyond individual banking apps to compromise entire Android devices and potentially access corporate resources. The latest version, 2.0, boasts enhanced capabilities including device-level control, credential thef… Dark Reading · 6d ago High LAITPObankingmobileenterprise
threat-intel IT threat evolution in Q2 2026. Mobile statistics In Q2 2026, mobile malware attacks continued to decline, with Trojan-Banker applications representing the most prevalent threat. Despite a drop in new Trojan variants, the landscape remained dominated by Mamont banking T… Securelist · Aug 10, 2026 Medium mobilemalwarebanking
vulnerability How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones Two security researchers, Dimitrios Valsamaras and Ken Gannon, demonstrated a complex exploit chain targeting Samsung phones, leveraging vulnerabilities in the Samsung Members and Samsung Account apps to gain remote code… SecurityWeek · Aug 5, 2026 High CVE-2025-21079CVE-2025-58486CVE-2025-58487androidbixbyexploit
threat-intel Cognyte Sells a Mobile Cell Surveillance Van Cognyte, an Israeli surveillance firm, has sold a mobile cell surveillance van called FalcoNet, mimicking a cell tower to track nearby phones. This technology, similar to Stingrays, allows law enforcement to monitor comm… Schneier on Security · Jul 27, 2026 High ISsurveillanceprivacycell-site
threat-intel Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious Android application, dubbed ‘BH Alert,’ is being distributed through fake Google Play sites mimicking Bahraini government entities to deliver a four-stage surveillance platform. The app leverages users' trust… Dark Reading · Jul 22, 2026 High BHKUandroidspywaremalware
threat-intel ISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in widely used communication… SANS Internet Storm Center · Jul 10, 2026 High phishingvulnerabilityslack
vulnerability Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks Researchers discovered a long-standing vulnerability (CVE-2026-20971) in Samsung’s KNOX kernel across numerous Galaxy devices, from S9 to S25. The flaw, a race-condition use-after-free (UAF), allowed for potential kernel… SecurityWeek · Jun 23, 2026 High uafkernelrace condition
threat-intel Yarbo Android/iOS Mobile Application and Cloud Infrastructure A CISA advisory details a vulnerability in the Yarbo Android/iOS Mobile Application and Cloud Infrastructure, specifically related to hard-coded MQTT credentials. The application contains credentials that allow unauthori… CISA Advisories · Jun 11, 2026 High CVE-2026-10557CVE-2026-7368WOmqttcredentialsrobotics
malware Fake Android Apps Commit Carrier Billing Fraud for Premium Svcs. A coordinated campaign targeting Android users in Malaysia, Thailand, Romania, and Croatia has been identified, utilizing fake apps disguised as popular services to commit carrier billing fraud. The malware, employing te… Dark Reading · May 20, 2026 High MYTHROandroidcarrier billingfraud