Malware targeting Android-based automotive head units spread through built-in firmware updates (botnet proxy malware)
https://securelist.com/android-head-unit-malware/121106/
https://securelist.com/android-head-unit-malware/121106/
👍16
Mesh network cache poisoning: exploiting BitChat's BLE authentication
Blog: https://barghest.asia/blog/bitchat-cache-poisoning/
PoC: https://github.com/BARGHEST-ngo/PoC_Bitchat1.15.0_iOS-BLEcache-poisoning
Blog: https://barghest.asia/blog/bitchat-cache-poisoning/
PoC: https://github.com/BARGHEST-ngo/PoC_Bitchat1.15.0_iOS-BLEcache-poisoning
Barghest
BitChat cache poisoning and replay in Bluetooth mesh
BARGHEST found a cache poisoning attack in BitChat and replay flaw in BLE mesh synchronization that enabled durable network disruption before patching.
👍13🔥7❤4
JADX MCP: a MCP (Model Context Protocol) server as a jadx-gui plugin
https://github.com/0xdad0/jadx-mcp
https://github.com/0xdad0/jadx-mcp
GitHub
GitHub - 0xdad0/jadx-mcp: MCP (Model Context Protocol) server as a jadx-gui plugin. Lets an AI client (Claude Code, Claude Desktop…
MCP (Model Context Protocol) server as a jadx-gui plugin. Lets an AI client (Claude Code, Claude Desktop, or any MCP client) analyze the app currently loaded in jadx-gui. - 0xdad0/jadx-mcp
❤14🤔7🎃3
How to Install Proxmark3 on the uConsole to read, write and clone some of RFID and NFC tokens
https://www.mobile-hacker.com/2026/08/31/how-to-install-proxmark3-on-the-clockworkpi-uconsole/
https://www.mobile-hacker.com/2026/08/31/how-to-install-proxmark3-on-the-clockworkpi-uconsole/
Mobile Hacker
How to Install Proxmark3 on the ClockworkPi uConsole - Mobile Hacker
The ClockworkPi uConsole is already an interesting portable Linux computer. By connecting a Proxmark3, it can also become portable RFID research for exploring and understanding contactless cards and tags, cloning them and identifying how different cards work…
👍14🔥8
PolicyGapper: A Multi-Prompt LLM-Based App Privacy Compliance Analysis
https://github.com/Mobile-IoT-Security-Lab/PolicyGapper
https://github.com/Mobile-IoT-Security-Lab/PolicyGapper
GitHub
GitHub - Mobile-IoT-Security-Lab/PolicyGapper: This repository proposes a novel methodology for automated privacy compliance analysis…
This repository proposes a novel methodology for automated privacy compliance analysis of mobile applications based on multi-prompt Large Language Model (LLM) cooperation. The framework applies to ...
❤6🤔4👍3👎1
Beware of fake Indeed interview apps used to install spyware
https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware
https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware
Malwarebytes
Beware of fake Indeed interview apps used to install spyware
Scammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware.
👍9🤬6
Reproducing the Acode Zero-Day Vulnerability
-ACode is a simple code editor for Android
https://hackmd.io/@sal/Reproducing-the-Acode-Zero-Day-Vulnerability
-ACode is a simple code editor for Android
https://hackmd.io/@sal/Reproducing-the-Acode-Zero-Day-Vulnerability
HackMD
Reproducing the Acode Zero Day Vulnerability - HackMD
Hello friends, in this blog we’re going to talk about a challenge I took while learning Android Security. I took this challenge while following a really great Android security course on Hextree. The course is sponsored by Google, and the material is excellent…
🔥9❤5⚡2
Uncovering StreamRat: From Meta Ads to Full Device Takeover
https://www.threatfabric.com/blogs/from-meta-ads-to-full-device-takeover-uncovering-streamrat
https://www.threatfabric.com/blogs/from-meta-ads-to-full-device-takeover-uncovering-streamrat
ThreatFabric
Uncovering StreamRat: From Meta Ads to Full Device Takeover
ThreatFabric researchers have uncovered StreamRat, a new Android banking trojan promoted to Spanish-speaking users through Meta and TikTok advertisements.
⚡15
Your photos can be accessed without unlocking your Android when you receive a WhatsApp video call [not fixed]
https://www.mobile-hacker.com/2026/09/02/whatsapp-lets-you-view-photos-without-unlocking-smartphone/
https://www.mobile-hacker.com/2026/09/02/whatsapp-lets-you-view-photos-without-unlocking-smartphone/
Mobile Hacker
WhatsApp Lets You View Photos Without Unlocking Smartphone - Mobile Hacker
Most people assume that once their phone is locked, their photos are protected from anyone who picks up the device. However, a behavior discovered Jose Rodriguez shows that photos may be accessible during an incoming WhatsApp video call, even while the phone…
😁15👍9🔥8❤4⚡3🤯3
How to Copy and Backup RFID Access Cards and NFC Key Fobs with Chameleon Ultra
https://www.mobile-hacker.com/2026/09/07/chameleon-ultra-guide-to-rfid-reading-emulation-and-testing/
https://www.mobile-hacker.com/2026/09/07/chameleon-ultra-guide-to-rfid-reading-emulation-and-testing/
Mobile Hacker
Chameleon Ultra: Guide to RFID Reading, Emulation and Testing - Mobile Hacker
Contactless cards and key fobs are now part of everyday life. They unlock apartment buildings, identify employees, open hotel rooms, record attendance and interact with electronic locks. Although many of these credentials look similar from the outside, the…
👍14🔥1
1-click could expose every contact saved on your Android, even if you never gave permission to access them (CVE-2026-28576)
Blog: https://www.mobilehackinglab.com/blog/cve-2026-28576-contacts-provider-sqli
Demo: https://www.youtube.com/shorts/nWzdx0uuULM
PoC APK: https://github.com/mobilehackinglab/CVE-2026-28576-poc
Blog: https://www.mobilehackinglab.com/blog/cve-2026-28576-contacts-provider-sqli
Demo: https://www.youtube.com/shorts/nWzdx0uuULM
PoC APK: https://github.com/mobilehackinglab/CVE-2026-28576-poc
👍12❤4🔥2
TeleGapper is a black-box dynamic analysis tool for Telegram Mini Apps on Android devices
https://github.com/Mobile-IoT-Security-Lab/TeleGapper
https://github.com/Mobile-IoT-Security-Lab/TeleGapper
GitHub
GitHub - Mobile-IoT-Security-Lab/TeleGapper: Black Box Dynamic Analysis Telegram Mini App Tool to detect Privacy Policy Violations
Black Box Dynamic Analysis Telegram Mini App Tool to detect Privacy Policy Violations - Mobile-IoT-Security-Lab/TeleGapper
👍11🥴5🤮2
Hagaseca: Inside a Packed Android RAT Loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android
https://calif.io/research/weworm
https://calif.io/research/weworm
Calif
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
🔥7
RCE in mexc Android app via Bypass URL validation to access the WebView, JS-Bridge with Path Traversal leads to Native-Library Cache Overwrite.
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
❤4