Advertisement
ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN
ToxicPanda 2.0 Android malware uses VPN permissions to block Google Play and abuses Wireless ADB to gain shell access and deploy overlays.
Android Car Head Unit Malware Spreads via Built-In Updaters
Kaspersky discovered a new malware family targeting Android car head units via DoFun firmware updaters to build an ad fraud and proxy botnet.
Unisoc Modem Exploit Chain: Android Takeover via Video Call
An exploit chain targeting Unisoc modems allows remote Android device takeover through a malicious video call, requiring victim interaction.
Kimwolf v7 Botnet Evolves with Advanced DDoS and C2 Resilience
Kimwolf v7, an Android/IoT botnet, enhances DDoS capabilities with HTTP/2 fingerprinting and robust, multi-layered C2 infrastructure.
Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder
Project Zero details a zero-click exploit chain targeting Google Pixel 9 via the Dolby Unified Decoder, leading to arbitrary code execution.
Project Zero Uncovers Android 0-Click Exploit Chain Ecosystem Weaknesses
Project Zero details findings from a Pixel 9 0-click exploit chain, highlighting critical Android ecosystem issues and proposing security enhancements.
Advertisement
Fake Bahrain Alert Apps Deploy Android Surveillance Malware
Analyzing fake Bahrain alert apps distributing four-stage Android surveillance malware via phony app stores, exploiting geopolitical tensions for extensive data…
RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis
RedWing MaaS is an Android bank fraud malware-as-a-service rented on Telegram, enabling low-skill attackers to steal banking logins and OTPs.
CVE-2026-46242: Linux Kernel Bad Epoll Flaw Grants Root on Servers, Android
Critical Linux kernel 'Bad Epoll' flaw (CVE-2026-46242) allows unprivileged users to gain root access on servers, desktops, and Android devices. Patch now.
Google's €4.1B EU Fine Stands: Android Antitrust Implications
Google loses final appeal against its €4.1 billion EU antitrust fine concerning Android's dominance. Understand the compliance implications for tech giants.
AirDrop and Quick Share: Proximity Flaws Cause Crashes and Bypass Checks
Researchers found six security flaws in AirDrop and Quick Share, enabling nearby attackers to crash devices and bypass security checks without user interaction.
Google Android Scam Detection: Real-Time AI Defense Against Fraud
Google introduces AI-powered Scam Detection for Android, utilizing on-device Gemini Nano to identify fraud patterns and protect users from voice-based phishing.
Android June 2024 Update: CVE-2024-32896 Zero-Day Exploit Patched
Google fixes 124 vulnerabilities including an actively exploited Pixel firmware zero-day and critical RCE flaws in the June 2024 Android security update.
Trapdoor Android Ad Fraud: 455 Apps Generate 659M Daily Bid Requests
Researchers reveal the Trapdoor ad fraud scheme, involving 455 Android apps and 183 C2 domains generating over 600 million daily fraudulent bid requests.
Pixel 10 0-Click Exploit Chain: Re-Targeting CVE-2025-54957 for Root
Analysis of a zero-click exploit chain targeting the Google Pixel 10, achieving root via an adapted Dolby vulnerability (CVE-2025-54957). Critical threat. Patch now.
Android CVE-2026-0073: Critical System RCE Patch Guidance
Google addresses a critical zero-click RCE vulnerability (CVE-2026-0073) in the Android System component. Learn how to mitigate this high-impact security flaw.
Android Dirty Stream Path Traversal: Detecting and Patching App Exploits
Microsoft identifies Dirty Stream vulnerabilities in Android apps, allowing path traversal and unauthorized file manipulation. Learn how to secure your apps.
CVE-2024-21390: EngageLab SDK Vulnerability Risks Android Crypto Wallets
Microsoft reveals a vulnerability in the EngageLab SDK affecting millions of Android crypto wallet users, potentially allowing for private key theft.
Android StrongBox DoS Vulnerability Patched – Update Now
A critical Denial-of-Service vulnerability in Android's StrongBox keymaster and Framework component has been patched. Immediate updates are crucial for device security.
SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases
A new SparkCat malware variant targets iOS and Android users, stealing crypto wallet recovery phrase images from compromised apps on official stores.
NoVoice Android Malware on Google Play: 2.3 Million Devices Infected
NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.
Android Developer Identity Verification: New Google Play Mandates
Google mandates identity verification for all Android developers to reduce malicious app distribution and improve Play Store transparency starting September.
Google Play Protect Advanced Flow for Android Sideloading
Google introduces Advanced Flow to Play Protect, enhancing security for Android sideloading to combat financial fraud and malicious APK installations.
Google Android Security: 24-Hour Wait for Unverified Sideloading
Google introduces a mandatory 24-hour cooling-off period for sideloading unverified Android applications to mitigate malware and financial scams.