← Latest brief

Security news.

·Afternoon Brief

Today's security landscape highlights the ongoing challenges of mobile malware, with new Android threats emerging that leverage VPN permissions and target car head units. Supply chain attacks remain a critical concern across various platforms, while CISA continues to add actively exploited vulnerabilities to its catalog, urging immediate patching from federal agencies.

BLEEPINGMALWARE
7h agoREAD

ToxicPanda Android Malware Blocks Google Play

The ToxicPanda Android malware has evolved, using VPN permissions to block Google Play and expanding its targeting to 349 applications with support for 167 remote commands.

BLEEPINGMALWARE
1d agoREAD

Android Car Head Units Infected with Botnet Malware

A supply-chain attack is spreading malware through a legitimate device-update app for Android-based car head units, enlisting compromised devices in a proxy botnet or for ad fraud.

THNPOLICY
1d agoREAD

TikTok Settles Child Privacy Lawsuit for $400 Million

TikTok has agreed to pay $400 million to settle a 2024 lawsuit from the U.S. Department of Justice (DoJ) regarding violations of child privacy laws.

CISAKEV
2d agoREAD

CISA Adds Zimbra OS Command Injection to KEV Catalog

CISA has added one new vulnerability, CVE-2026-73570, an OS Command Injection in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities Catalog.

BLEEPINGPHISHING
2d agoREAD

New SynkLoader Malware in Microsoft Teams Phishing

A previously unknown malware family, SynkLoader, is being distributed via Microsoft Teams phishing campaigns to steal credentials using a fake lock screen.

THNSUPPLY CHAIN
2d agoREAD

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor

Cybersecurity researchers discovered 14 trojanized npm packages masquerading as utilities, engineered to deliver an AI-powered Linux implant called RedC2 4.0.

BLEEPINGBREACH
2d agoREAD

Hundreds of Leaked AWS Keys Grant Full Account Control

Over 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 remain active and valid, giving full control over corporate accounts.

THNEXPLOIT
2d agoREAD

Microsoft Defender Driver Weaponized to Delete Security Software

Check Point Research disclosed a technique allowing Microsoft Defender's legitimately signed boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations on Windows systems.

Generated twice daily from public security RSS feeds. Informational only.