This media is not supported in your browser
VIEW IN TELEGRAM
Android 17 root: full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 (CVE-2026-10702)
Click on the link -> root Android
https://x.com/nebusecurity/status/2069707520160227688
Click on the link -> root Android
https://x.com/nebusecurity/status/2069707520160227688
π₯55π±29β€13π€8π7π6π5
Glitch SPY: New Android RAT Distributed Through a Fake Polish Rental App
https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app/
https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app/
Cyble
Glitch SPY RAT Distributed Via Fake Polish Rental App
CRIL analyzes Glitch SPY, an Android RAT with 70+ commands, crypto-clipping, and a silent remote browser, giving attackers full device control.
RedWing: A Mobile Malware-as-a-Service Operation
https://zimperium.com/blog/redwing-a-mobile-malware-as-a-service-operation
https://zimperium.com/blog/redwing-a-mobile-malware-as-a-service-operation
Zimperium
RedWing: A Mobile Malware-as-a-Service Operation
true
π28β‘19π16β€10
GoldPickaxe Returns: When Your Biometric Information is as Important as Your Money
https://zimperium.com/blog/goldpickaxe-returns-when-your-biometric-information-is-as-important-as-your-money
https://zimperium.com/blog/goldpickaxe-returns-when-your-biometric-information-is-as-important-as-your-money
Zimperium
GoldPickaxe Returns: When Your Biometric Information is as Important as Your Money
true
π22π13β€9
How to Bypass mTLS on Android with Frida
https://kiratliygt.medium.com/how-to-bypass-mtls-on-android-with-frida-45c5e71373e8
https://kiratliygt.medium.com/how-to-bypass-mtls-on-android-with-frida-45c5e71373e8
Medium
How to Bypass mTLS on Android with Frida
Keywords: mTLS bypass Android, Frida mTLS, Android mutual TLS bypass, Burp Suite mTLS Android, Android mTLS pentest, PKCS12 Androidβ¦
π35β€23
RedHook Android malware abuses ADB Wireless Debugging and Shizuku to get shell-level privileges
https://www.group-ib.com/blog/redhook-android-rat-upgraded/
https://www.group-ib.com/blog/redhook-android-rat-upgraded/
Group-IB
RedHook Returns with a Dangerous Upgrade
Group-IB analysts examine this resurfaced Android Remote Access Trojan, demonstrating new, sophisticated and malicious functionalities including autonomous privilege abuse, expanded command-and-control capabilities, and a robust persistence stack.
π18π14π€‘9β€8π₯6π5
Forwarded from The Bug Bounty Hunter
Reading Contact Photos Without READ_CONTACTS: A Google Messages Confused Deputy Bug
https://blog.devploit.dev/posts/google-messages-avatarcontentprovider-contacts-bypass/
https://blog.devploit.dev/posts/google-messages-avatarcontentprovider-contacts-bypass/
devploit / blog
Reading Contact Photos Without READ_CONTACTS: A Google Messages Confused Deputy Bug
What happens if an app without READ_CONTACTS asks Google Messages for Android to load a Contacts photo for it?
β€34π7
List of 140 vulnerabilities in Samsung preinstalled Android apps reported in 2022
https://github.com/oversecured/Samsung_Vulnerabilities
https://github.com/oversecured/Samsung_Vulnerabilities
GitHub
GitHub - oversecured/Samsung_Vulnerabilities: 176 vulnerabilities in Samsung preinstalled Android apps
176 vulnerabilities in Samsung preinstalled Android apps - oversecured/Samsung_Vulnerabilities
β€29π₯17β‘12
Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post
https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post
https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post
Dreamgroup
How a Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post | | Dream Security Blog
π―8π7β€5π2
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
hunt.io
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.
π6β€3
Inside an N26 Impersonation Campaign: From Vishing and Fake Control 1.0 to the Copybara Android RAT
https://www.d3lab.net/inside-an-n26-impersonation-campaign-from-vishing-and-fake-control-1-0-to-the-copybara-android-rat/
https://www.d3lab.net/inside-an-n26-impersonation-campaign-from-vishing-and-fake-control-1-0-to-the-copybara-android-rat/
www.d3lab.net
Inside an N26 Impersonation Campaign: From Vishing and Fake Control 1.0 to the Copybara Android RAT β D3Lab
From a fake N26 support call to the Copybara Android RAT: inside a human-operated phishing campaign designed for on-device financial fraud.
β€5π2π₯±1