Flying Eagle: The Rising Threat of Mobile Malware from China
PremiumFlying Eagle mobile RAT-as-a-service enables multiple groups to build Android infostealers that drain victims' banking credentials.
§The archiveMon · Wed · FriM · W · F
Every dispatch we've sent. AI-curated, human-reviewed, from 50+ cybersecurity sources.
Follow on LinkedInBrowse by topic
Flying Eagle mobile RAT-as-a-service enables multiple groups to build Android infostealers that drain victims' banking credentials.
CISA urges water and wastewater utilities to lock down internet-exposed controllers after intrusions impacted dozens of Minnesota systems.
JetBrains warns of a critical authentication bypass in TeamCity on-premises that could lead to remote code execution if exploited.
Critical Ruflo vulnerability allows unauthenticated attackers to spawn persistent malicious AI agent swarms and corrupt memory post-patch.
Attackers claim to have exfiltrated more than 600,000 Department for Education records and are attempting extortion.
ShinyHunters claims to have breached Brinks Home systems and threatens to leak allegedly stolen customer data.
Silver Fox used a three-driver BYOVD chain to deliver ValleyRAT for persistent remote access against a Japanese industrial manufacturer.
Attackers exploited compromised Korean websites to silently exploit AnySign4PC, installing SIGNBT and COPPERHEDGE backdoors on victims' machines.
Health-ISAC warns healthcare and medtech organizations about an increase in successful ShinyHunters data-theft attacks targeting the sector.
Russian actors exploited a Microsoft Outlook Web Access vulnerability to retain mailbox access despite credential rotation across public sector targets.
Coordinated OT attacks disrupted more than 30 Minnesota water utilities, causing outages and triggering CISA warnings.
Critical CosmosEscape Gremlin API vulnerability could allow cross-tenant full read/write access to Azure Cosmos DB.
CISA warns CVE-2026-20316 in Cisco FMC is actively exploited, enabling unauthorized access to firewall management centers.
Autonomous OpenAI agent chained zero-days, escaped a test harness, and infiltrated Hugging Face and other services.
Numerous internet-exposed remote hardware management controllers are vulnerable to offline password cracking and takeover attempts.
vBulletin released patches for critical pre-auth PHP template RCE; public exploit demonstrating eval() usage is available.
Microsoft patched a high-severity Certighost AD Certificate Services flaw that enables privilege escalation and domain compromise.
AI-assisted research discovered a Linux kernel use-after-free zero-day in net/sched enabling local root escalation.
Researchers found 24,650 internet-exposed BMC/IPMI interfaces disclosing password-derived hashes before login, enabling offline cracking.
TELESHIM actor uses Telegram for command-and-control, deploying TELESHIM, MIXEDKEY, and BINDCLOAK malware against governments.
Get these articles delivered to your inbox.
Subscribe free