← Latest brief

Security news.

·Afternoon Brief

Today's security landscape highlights the ongoing challenges of mobile malware, with new Android threats emerging that leverage VPN permissions and target car head units. Supply chain attacks remain a critical concern across various platforms, while CISA continues to add actively exploited vulnerabilities to its catalog, urging immediate patching from federal agencies.

BLEEPINGMALWARE
Aug 23READ

ToxicPanda Android Malware Blocks Google Play

The ToxicPanda Android malware has evolved, using VPN permissions to block Google Play and expanding its targeting to 349 applications with support for 167 remote commands.

BLEEPINGMALWARE
Aug 22READ

Android Car Head Units Infected with Botnet Malware

A supply-chain attack is spreading malware through a legitimate device-update app for Android-based car head units, enlisting compromised devices in a proxy botnet or for ad fraud.

THNPOLICY
Aug 22READ

TikTok Settles Child Privacy Lawsuit for $400 Million

TikTok has agreed to pay $400 million to settle a 2024 lawsuit from the U.S. Department of Justice (DoJ) regarding violations of child privacy laws.

CISAKEV
Aug 21READ

CISA Adds Zimbra OS Command Injection to KEV Catalog

CISA has added one new vulnerability, CVE-2026-73570, an OS Command Injection in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities Catalog.

BLEEPINGPHISHING
Aug 21READ

New SynkLoader Malware in Microsoft Teams Phishing

A previously unknown malware family, SynkLoader, is being distributed via Microsoft Teams phishing campaigns to steal credentials using a fake lock screen.

THNSUPPLY CHAIN
Aug 21READ

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor

Cybersecurity researchers discovered 14 trojanized npm packages masquerading as utilities, engineered to deliver an AI-powered Linux implant called RedC2 4.0.

BLEEPINGBREACH
Aug 21READ

Hundreds of Leaked AWS Keys Grant Full Account Control

Over 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 remain active and valid, giving full control over corporate accounts.

THNEXPLOIT
Aug 21READ

Microsoft Defender Driver Weaponized to Delete Security Software

Check Point Research disclosed a technique allowing Microsoft Defender's legitimately signed boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations on Windows systems.

Generated twice daily from public security RSS feeds. Informational only.