How to Copy and Backup RFID Access Cards and NFC Key Fobs with Chameleon Ultra
https://www.mobile-hacker.com/2026/09/07/chameleon-ultra-guide-to-rfid-reading-emulation-and-testing/
https://www.mobile-hacker.com/2026/09/07/chameleon-ultra-guide-to-rfid-reading-emulation-and-testing/
Mobile Hacker
Chameleon Ultra: Guide to RFID Reading, Emulation and Testing - Mobile Hacker
Contactless cards and key fobs are now part of everyday life. They unlock apartment buildings, identify employees, open hotel rooms, record attendance and interact with electronic locks. Although many of these credentials look similar from the outside, theโฆ
๐29๐ฅ20
1-click could expose every contact saved on your Android, even if you never gave permission to access them (CVE-2026-28576)
Blog: https://www.mobilehackinglab.com/blog/cve-2026-28576-contacts-provider-sqli
Demo: https://www.youtube.com/shorts/nWzdx0uuULM
PoC APK: https://github.com/mobilehackinglab/CVE-2026-28576-poc
Blog: https://www.mobilehackinglab.com/blog/cve-2026-28576-contacts-provider-sqli
Demo: https://www.youtube.com/shorts/nWzdx0uuULM
PoC APK: https://github.com/mobilehackinglab/CVE-2026-28576-poc
๐24๐ฅ20โค9
TeleGapper is a black-box dynamic analysis tool for Telegram Mini Apps on Android devices
https://github.com/Mobile-IoT-Security-Lab/TeleGapper
https://github.com/Mobile-IoT-Security-Lab/TeleGapper
GitHub
GitHub - Mobile-IoT-Security-Lab/TeleGapper: Black Box Dynamic Analysis Telegram Mini App Tool to detect Privacy Policy Violations
Black Box Dynamic Analysis Telegram Mini App Tool to detect Privacy Policy Violations - Mobile-IoT-Security-Lab/TeleGapper
๐21๐ฅด21๐คฎ5
Hagaseca: Inside a Packed Android RAT Loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
๐34โค12
WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android
https://calif.io/research/weworm
https://calif.io/research/weworm
Calif
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
๐ฅ35โค18
RCE in mexc Android app via Bypass URL validation to access the WebView, JS-Bridge with Path Traversal leads to Native-Library Cache Overwrite.
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
โค33๐25
Vwork: Weaponized Open-source Software as an Addon for Gigabud
https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
Group-IB
Vwork: Weaponized Open-source Software as an Addon for Gigabud
How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.
๐33โค6
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
Zimperium
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
true
โก18โค15๐2
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
Zimperium
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
true
โค16๐12โก11
Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC
https://www.mobile-hacker.com/2026/09/21/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc/
https://www.mobile-hacker.com/2026/09/21/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc/
Mobile Hacker
Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC - Mobile Hacker
Do you have an older rooted Android phone sitting unused in a drawer? Instead of leaving it there, you can turn it into a practical NFC reader and USB keyboard for your computer. With a custom Android app (NFC to HID), your phone can read the unique indentationโฆ
๐20โค9๐3
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL
https://blog.nns.ee/2026/09/24/oneplus-root/
https://blog.nns.ee/2026/09/24/oneplus-root/
nns.ee
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL | nns.ee
Chaining an AtlasService binder command injection and an olc2 HAL binder method into uid 0 with all Linux capabilities from a plain installable app on OxygenOS 16.
โค15๐ฅ7๐คฃ4
RemControl: AI Built the Overlays. Victims Lose their PINs
https://www.group-ib.com/blog/remcontrol-android-banking-trojan/
https://www.group-ib.com/blog/remcontrol-android-banking-trojan/
Group-IB
RemControl: AI Built the Overlays. Victims Lose their PINs
Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.
โก7โค5
A native APK and DEX decompiler written in Rust
https://github.com/Ch0pin/rdx
https://github.com/Ch0pin/rdx
GitHub
GitHub - Ch0pin/rdx: A native APK and DEX decompiler written in Rust
A native APK and DEX decompiler written in Rust. Contribute to Ch0pin/rdx development by creating an account on GitHub.
๐ฑ14๐8โค7
apk-reverse: An Agent Skill for Android APK reverse engineering, debloating, ad removal, surgical dex patching, repacking, and runtime/server analysis
https://github.com/newliver666/apk-reverse
https://github.com/newliver666/apk-reverse
GitHub
GitHub - newliver666/apk-reverse: Suitable for Android APK reverse engineering analysis
Suitable for Android APK reverse engineering analysis - newliver666/apk-reverse
โค7๐6๐ฉ6๐1
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
Cleafy
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat | Cleafy
Cleafy's TIR team analyzed the operator infrastructure behind RATHat, an Android banking trojan that abuses Accessibility Services to enable wireless debugging on the victim's phone, obtain a shell, and deploy a hidden native service outside the app. Theโฆ
๐6โค1
How we found 24 Android vulnerabilities using our open source AI security agent
https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/
https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/
The GitHub Blog
How we found 24 Android vulnerabilities using our open source AI security agent
A look at the targeted AI taskflows behind these findings, the bugs they uncovered, and how to run the same open-source agent on your own app.
โค5โก3๐ค2
CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF โ iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC) https://github.com/0xjohnnydev/CVE-2026-20687-AppleJPEGDriver-UAF
GitHub
GitHub - 0xjohnnydev/CVE-2026-20687-AppleJPEGDriver-UAF: CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF โ iOS/macOS kernelโฆ
CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF โ iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC) - 0xjohnnydev/CVE-2026-20687-AppleJPEGDriver-UAF
๐ฑ3๐ฉ2