Security news.
Today's security landscape highlights the ongoing challenges of mobile malware, with new Android threats emerging that leverage VPN permissions and target car head units. Supply chain attacks remain a critical concern across various platforms, while CISA continues to add actively exploited vulnerabilities to its catalog, urging immediate patching from federal agencies.
ToxicPanda Android Malware Blocks Google Play
The ToxicPanda Android malware has evolved, using VPN permissions to block Google Play and expanding its targeting to 349 applications with support for 167 remote commands.
Android Car Head Units Infected with Botnet Malware
A supply-chain attack is spreading malware through a legitimate device-update app for Android-based car head units, enlisting compromised devices in a proxy botnet or for ad fraud.
TikTok Settles Child Privacy Lawsuit for $400 Million
TikTok has agreed to pay $400 million to settle a 2024 lawsuit from the U.S. Department of Justice (DoJ) regarding violations of child privacy laws.
CISA Adds Zimbra OS Command Injection to KEV Catalog
CISA has added one new vulnerability, CVE-2026-73570, an OS Command Injection in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities Catalog.
New SynkLoader Malware in Microsoft Teams Phishing
A previously unknown malware family, SynkLoader, is being distributed via Microsoft Teams phishing campaigns to steal credentials using a fake lock screen.
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor
Cybersecurity researchers discovered 14 trojanized npm packages masquerading as utilities, engineered to deliver an AI-powered Linux implant called RedC2 4.0.
Hundreds of Leaked AWS Keys Grant Full Account Control
Over 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 remain active and valid, giving full control over corporate accounts.
Microsoft Defender Driver Weaponized to Delete Security Software
Check Point Research disclosed a technique allowing Microsoft Defender's legitimately signed boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations on Windows systems.