Tag: android
-
Product showcase: mSecure makes one vault do more than remember passwords
mSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/product-showcase-msecure-password-manager/
-
Mantax Otax Targets Android Phones With Spyware and Ransomware
Mantax Otax Android malware steals messages, PINs, and files, monitors screens, and uses ransomware and harassment to pressure victims into paying. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-mantax-otax-android-malware-apac-indonesia/
-
WhatsApp Restricted Chat locks a conversation to your primary phone
WhatsApp is building a per-chat setting that keeps a conversation on a single phone. The setting, called Restricted Chat, sits in the Android beta distributed through Google … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/14/whatsapp-restricted-chat-feature/
-
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/
-
Androids VPN-Sperre lässt sich wieder umgehen
Der Sicherheitsforscher Armin Å upuk entdeckte eine neue Schwachstelle, mit der man die VPN-Sperre von Android aushebeln kann. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/smartphones/androids-vpn-sperre-laesst-sich-weiterhin-umgehen-333390.html
-
Androids VPN-Sperre lässt sich wieder umgehen
Der Sicherheitsforscher Armin Å upuk entdeckte eine neue Schwachstelle, mit der man die VPN-Sperre von Android aushebeln kann. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/smartphones/androids-vpn-sperre-laesst-sich-weiterhin-umgehen-333390.html
-
Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion. Unlike conventional Android ransomware that focuses primarily on locking…
-
Indonesia Hit by Android Banking App-Cloning Campaign
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately. First seen on darkreading.com Jump to article: www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up…
-
Your passkeys can now move between password managers on Android
Google turned on a transfer feature in Android that moves passwords and passkeys straight from one password manager to another, with no file to download along the way. You … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/google-android-password-manager-transfer/
-
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.Early Access apps are apps that haven’t been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or…
-
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9.A work profile is a separate space that Android typically reserves for employer apps, and what’s inside it…
-
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/mantaxotax-android-malware/
-
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones.The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts.…
-
THost9 Android RAT Pairs Packed Loader With ADB Worm
THost9 hides its payload and uses ADB to spread across exposed Android devices and containers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/
-
Trotz Displaysperre: Whatsapp-Lücke lässt Angreifer private Fotos durchstöbern
Angreifer können auf einigen Android-Geräten per Videoanruf in Whatsapp Zugriff auf die Galerie erlangen – und das trotz aktiver Displaysperre. First seen on golem.de Jump to article: www.golem.de/news/trotz-displaysperre-whatsapp-luecke-laesst-angreifer-private-fotos-durchstoebern-2609-212594.html
-
Enterprise SSO in an Android App: AppAuth and OIDC, Step by Step
Tags: androidAdding enterprise SSO to an Android app means AppAuth, a Custom Tab, and an intent filter that routes the redirect back into your activity. You discover the issuer configuration, build an AuthorizationRequest with ResponseTypeValues.CODE, launch it with getAuthorizationRequestIntent(), catch the… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/enterprise-sso-in-an-android-app-appauth-and-oidc-step-by-step/
-
StreamRAT Abuses Android Accessibility, MediaProjection and HVNC for Full Device Takeover
StreamRAT, a newly identified Android banking trojan distributed through fake free-TV streaming advertisements on Meta and TikTok. The campaign, tracked as “Steamtv Esp.,” primarily targeted Spanish-speaking Android users and exposed an estimated 570,000 Meta users between June 11 and July 3, 2026. The operation highlights the continued effectiveness of piracy-themed social engineering. Victims who clicked…
-
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices.ThreatFabric said the campaign’s advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union First seen…
-
Gefälschte Indeed-Apps verbreiten Spyware unter Android-Jobsuchenden
Sicherheitsforscher von Malwarebytes warnen vor gefälschten Stellenanzeigen auf der großen Jobplattform Indeed. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/gefaelschte-indeed-apps
-
Android-ROM: GrapheneOS-Macher lästern über Pixel 11
Google hat bei der Pixel-11-Serie eine für GrapheneOS elementare Funktion deaktiviert – die neuen Modelle werden nicht unterstützt. First seen on golem.de Jump to article: www.golem.de/news/android-rom-grapheneos-macher-laestern-ueber-pixel-11-2609-212479.html
-
Indeed Job Scam: Fake Recruiters Are Spreading Android Spyware
Scammers are using fake Indeed interview apps to infect Android phones with spyware. Learn how the attack works and how job seekers can avoid it. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-indeed-fake-interview-app-android-malware/
-
Android 17 Adds New Network Security Features to Block 2G SMS Blaster Attacks
Android 17 introduces a new set of network security controls to reduce cellular downgrade attacks, protect local networks, and limit metadata exposure during encrypted web sessions. This update includes carrier-managed 2G shutdown capabilities designed to combat SMS blaster campaigns that increasingly target users in public spaces. Google states the Android 17 changes focus on four…
-
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication
Tags: access, android, authentication, control, cve, cvss, cyber, flaw, microsoft, mobile, open-source, vulnerabilityA critical vulnerability in Microsoft’s open-source UFO Desktop AgentOS could allow remote attackers to access and control Android devices connected via the platform’s Mobile Model Context Protocol (MCP) servers without requiring authentication. This vulnerability is tracked as CVE-2026-73296 and GHSA-24fq-m9rr-g3mm, carrying a CVSS v3.1 score of 9.4. It affects UFO versions up to and including…
-
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users’ home networks.Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting.”This new privacy standard works in…
-
Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping
Google introduced a batch of network security changes coming in Android 17, aimed at making it harder for network operators, snoops, and scammers to track what you do on your … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/28/android-17-network-security-features/
-
Android 17 adds ECH support to make web browsing harder to track
Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users’ home networks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/android-17-adds-ech-support-to-make-web-browsing-harder-to-track/

