ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
0 adds 167 remote commands, targets 349 financial institutions, and uses Android accessibility to harvest PINs.
0 adds 167 remote commands, targets 349 financial institutions, and uses Android accessibility to harvest PINs.
GoldFactory's Gigabud malware clones banking apps inside hidden Android Work Profiles, evading fraud detection.
Zimperium disclosed ToxicPanda 2.0 malware on August 23, which now targets 349 banking and finance applications and supports 167 remote commands. The evolved variant abuses VPN Service permissions to intercept device traffic and block Google Play updates, keeping the trojan installed.
# Manic : The # Android # Malware That Exfiltrates Data Even When the Phone Is Offline https:// securityaffairs.com/197570/mal ware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html # securityaffairs # hacking
Unrelated reports span Pluto's 20-year reclassification anniversary (2026-08-24), an SEC probe into AI hedge fund Situational Awareness (2026-08-25), instant ramen's invention history, security updates, immigration economic effects, and RDP honeypot data released between 2026-08-24 and 2026-11-17.
@ XposedOrNot += Harvard University Data Breach The Harvard University # databreach occurred in November 2025 when the private research university was allegedly breached by the ShinyHunters group. The incident exposed 851K unique email addresses and associated personal and donation-related information.
Cybersecurity researchers reported on August 22–23, 2026, that hackers compromised Android-based car infotainment systems (DoFun head units) through a legitimate firmware update app, enlisting devices in a proxy botnet for ad fraud and proxy operations. The supply-chain attack was first discovered by Kaspersky.
This cluster mixes two separate stories: CAF Bank suspending online services for 14,000 charities due to a third-party software security flaw, and unrelated Portuguese-language reporting about a Bolsonaro family corruption investigation.
Incoherent mix: projectile strike in Strait of Hormuz with crew death and oil price rise; UN report on Gaza cropland destruction (3% usable); unrelated social media posts about website design and AI code testing.
On September 8, 2026, Sergei Anatolyevich Filimonov, a 36-year-old Russian national and web developer, was extradited from the Republic of Georgia and arraigned in U.S. federal court on charges related to a large-scale transnational cyber-fraud conspiracy involving bank account takeovers that caused millions of dollars in losses.
21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.
Disparate reports cover Samsung Galaxy S27 camera redesigns (2026-08-25), Anthropic's Claude memory integration (2026-08-25), Bangkok flooding and California ocean phenomena (2026-09-28), and an NRC workforce assessment (2026-09-29). A systemd SSD issue also circulated online (2026-08-27).
com/2026/08/40-m... 40 malicious Firefox extensions pose as Web3 products to steal recovery phrases, private keys, keyrings, credentials, and clipboard data.
Between 2–5 September 2026, identity verification firm IDScan was publicly identified as the source of a breach exposing digital scans of over 153 million U.S. and Canadian driver's licenses offered for sale on the dark web marketplace Nexus. The FBI opened an investigation, and multiple lawsuits were filed against IDScan.
On 27–28 August 2026, OpenAI led an open letter signed by nearly 130 organizations—including Anthropic, Microsoft, Google, Amazon, and Cisco—warning of escalating AI-enabled cyberattacks and urging coordinated global cyber defenses. The coalition cautioned that sophisticated AI-powered attacks could proliferate within months without coordinated action.
Between 24 and 25 September 2026, Revolut customers in Ireland and elsewhere were impacted by a data breach at third-party provider DriveWealth. The breach exposed historical records of customers who used Revolut's US stock trading feature before December 2023.
A Jacksonville woman filed a lawsuit against VyStar Credit Union on August 14, 2026, alleging the institution failed to investigate and reimburse approximately $42,000 stolen from her accounts through identity theft. The lawsuit centers on the credit union's negligence in addressing the fraudulent activity.