Security News

Popular Android Apps Like Xiaomi, WPS Office Vulnerable to File Overwrite Flaw
2024-05-02 14:22

Several popular Android applications available in Google Play Store are susceptible to a path traversal-affiliated vulnerability that could be exploited by a malicious app to overwrite arbitrary...

Android Malware Wpeeper Uses Compromised WordPress Sites to Hide C2 Servers
2024-05-01 13:41

Cybersecurity researchers have discovered a previously undocumented malware targeting Android devices that uses compromised WordPress sites as relays for its actual command-and-control (C2)...

Google now pays up to $450,000 for RCE bugs in some Android apps
2024-04-30 18:33

Google has increased rewards for reporting remote code execution vulnerabilities within select Android apps by ten times, from $30,000 to $300,000, with the maximum reward reaching $450,000 for exceptional quality reports. The list of in-scope apps includes Google Play Services, the Android Google Search app, Google Cloud, and Gmail.

New Wpeeper Android malware hides behind hacked WordPress sites
2024-04-30 16:41

A new Android backdoor malware named 'Wpeeper' has been spotted in at least two unofficial app stores mimicking the Uptodown App Store, a popular third-party app store for Android devices with over 220 million downloads. Wpeeper stands out for its novel use of compromised WordPress sites to act as relays for its actual command and control servers, acting as an evasion mechanism.

Google rejected 2.28 million risky Android apps from Play store in 2023
2024-04-29 16:00

Google blocked 2.28 million Android apps from being published on Google Play after finding various policy violations that could threaten user's security. In addition to blocking nearly 2.3 million apps and suspending 333,000 offending publishers, Google has rejected or remediated 200,000 app submissions requesting access to risky permissions such as SMS content and background location data without a good reason.

New 'Brokewell' Android Malware Spread Through Fake Browser Updates
2024-04-26 10:42

Fake browser updates are being used to push a previously undocumented Android malware called Brokewell. "Brokewell is a typical modern banking malware equipped with both data-stealing and...

New Brokewell malware takes over Android devices, steals data
2024-04-25 10:00

Security researchers have discovered a new Android banking trojan they named Brokewell that can capture every event on the device, from touches and information displayed to text input and the applications the user launches. Brokewell is under active development and features a mix of extensive device takeover and remote control capabilities.

New Android Trojan 'SoumniBot' Evades Detection with Clever Tricks
2024-04-18 10:31

A new Android trojan called SoumniBot has been detected in the wild targeting users in South Korea by leveraging weaknesses in the manifest extraction and parsing procedure. The malware is...

SoumniBot malware exploits Android bugs to evade detection
2024-04-17 21:38

A new Android banking malware named 'SoumniBot' is using a less common obfuscation approach by exploiting weaknesses in the Android manifest extraction and parsing procedure. The method enables SoumniBot to evade standard security measures found in Android phones and perform info-stealing operations.

'eXotic Visit' Spyware Campaign Targets Android Users in India and Pakistan
2024-04-10 14:24

An active Android malware campaign dubbed eXotic Visit has been primarily targeting users in South Asia, particularly those in India and Pakistan, with malware distributed via dedicated websites...