Insikt Group identified 60 high-impact vulnerabilities in June 2026 (a 49% increase from May), with 23 listed in CISA's KEV catalog and 53 having public PoC exploits. The dominant theme was exploitation of externally reachable enterprise applications and appliances by multiple threat actors: StrikeShark chained 13 CVEs to deploy SharkLoader and Cobalt Strike, Lazarus exploited CVE-2025-55182 (React2Shell, CVSS 10.0) to deploy COPPERHEDGE and EtherRAT, APT36 targeted India via Microsoft Office/Windows CVEs, and Qilin ransomware was linked to Check Point gateway exploitation. 25 of the 60 vulnerabilities enabled RCE across 18 vendors, with CWE-22 (Path Traversal) being the most common flaw class.
Android
34 posts
June 2026 CVE Landscape Cyber Centre Daily Advisory Digest — 2026-07-07 (6 advisories) The Canadian Centre for Cyber Security released a daily advisory digest containing 6 security advisories for 2026-07-07. The advisories cover critical vulnerabilities in a range of products including Android and Samsung mobile devices, VMware Tanzu, ABB industrial control systems, Django web framework, and Zimbra collaboration software. Administrators are urged to review the referenced bulletins and apply the necessary patches and mitigations.
Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims Infoblox Threat Intel identifies a threat actor tracked as 'Lurking Lizard' who operates a comprehensive malicious residential proxy ecosystem spanning victim device recruitment through trojanized software (fake 7-Zip, WireVPN), proxy service monetization via lookalike storefronts, and fake review sites for marketing. The actor controls 230+ domains and has been active since at least August 2022, with current operations centered on WireVPN-branded payloads that enroll victim devices as proxy exit nodes rather than functioning as legitimate VPN clients. A shared IPLogger telemetry beacon, consistent API structures, code signing certificate, and deployment patterns link multiple campaigns across several years to a single operator likely based in Wuhan, China.
6th July – Threat Intelligence Report This weekly threat intelligence bulletin covers multiple active ransomware campaigns, four critical vulnerabilities under active exploitation, and emerging AI-driven threats. Notable items include actively exploited RCE flaws in Oracle E-Business Suite and Progress Kemp LoadMaster, a Citrix NetScaler memory disclosure flaw exploited within 24 hours of disclosure, a North Korean supply-chain campaign (PolinRider) deploying 108 malicious packages, and a proof-of-concept browser-native ransomware generated by an LLM abusing Chrome's File System Access API.
Google’s Continued Disruption of Malicious Residential Proxy Networks Google, in coordination with the FBI and Lumen, disrupted the NetNut residential proxy network (aka Popa), which is estimated to comprise at least 2 million consumer devices enrolled as proxy exit nodes via malicious SDKs embedded in apps and firmware. The network was used by 316 distinct threat clusters in a single week for masking origin IPs, password spraying, and other malicious activity. Google disabled associated C2 accounts, shared intelligence with partners, and enabled Google Play Protect to warn users about apps containing NetNut SDKs.
The Platform You Trust Is the Platform They Target Cofense Intelligence reports a strategic shift in phishing operations toward platform-aware delivery, where threat actors fingerprint victim devices via browser User-Agent strings and deliver OS-specific payloads from a single landing page. Windows users receive legitimate remote access tools like ConnectWise RAT or Itarian RAT repurposed as malware, while MacOS and Android users are redirected to credential phishing pages. The abuse of legitimate RATs evades signature-based detection, and platform-siloed security tools fail to correlate the campaign across operating systems, leaving organizations with an incomplete picture of the intrusion scope.
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool Insikt Group identified new infrastructure used by the TAG-182 threat cluster to disseminate MarkiRAT surveillance malware targeting Farsi-speaking users, particularly Iranians, via fake VPN and media player applications distributed through social media. TAG-182 demonstrates tradecraft overlaps with Ferocious Kitten, including identical BITS job command strings and similar domain naming conventions. The operation supports Iranian government surveillance objectives, with infrastructure spanning multiple hosting providers and dozens of lookalike domains impersonating legitimate services.
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique Check Point Research identified a DeepSeek-attributed malicious Python Flask sample that transforms a theoretical browser ransomware risk into a practical attack using the File System Access API. The sample, disguised as a Discord avatar AI upscaler named InfernoGrabber v9.0, leverages social engineering to trick users into granting folder-level file access via browser permission prompts. Once access is granted, the web page can enumerate, read, exfiltrate, and encrypt files in the selected directory — all without installing a native payload or exploiting a browser vulnerability. The technique is particularly dangerous on Android where Chrome 132+ exposes the File System Access API to web content, allowing access to high-value photo directories including DCIM.
State Digital Surveillance Risk Landscape Insikt Group's analysis of the global state digital surveillance landscape identifies 31 countries as high or very high risk, driven by the proliferation of commercial spyware, network interception technologies, and AI-powered data aggregation. The report outlines five primary surveillance vectors—network, endpoint, platform, public space, and data aggregation—and highlights the increasing threat to foreign nationals and business travelers, necessitating strict device management and travel security protocols.
Yarbo Android/iOS Mobile Application and Cloud Infrastructure (CVE-2026-10557, CVE-2026-7368) Yarbo Android and iOS applications contain hard-coded MQTT credentials (CVE-2026-10557) that, combined with missing cloud authorization controls (CVE-2026-7368), allow attackers to access global robot telemetry and issue unauthorized commands to any device in the fleet.
8th June – Threat Intelligence Report This threat intelligence report highlights active exploitation of critical vulnerabilities, including a Windows Netlogon RCE (CVE-2026-41089) and an Android Framework flaw. It also details significant data breaches affecting DentaQuest and the UN WFP, emerging AI-driven threats such as EDR evasion labs, a supply chain compromise of the Hola browser, and Iranian state-sponsored espionage operations utilizing Dutch hosting infrastructure.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2022-0492, CVE-2025-48595) CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to include CVE-2022-0492, a Linux Kernel improper authentication vulnerability, and CVE-2025-48595, an Android Framework integer overflow vulnerability, citing evidence of active exploitation in the wild.
Cyber Centre Daily Advisory Digest — 2026-06-02 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting security updates for Samsung mobile devices, Android devices, and HP Poly voice products. Notably, the Android June 2026 monthly rollup addresses CVE-2025-48595, which is reportedly under limited, targeted exploitation.
1st June – Threat Intelligence Report This threat intelligence bulletin highlights a surge in data breaches driven by social engineering, alongside the increasing weaponization of AI tools for phishing, malware development, and supply chain attacks. Active exploitation of vulnerabilities in PAN-OS GlobalProtect and Ghost CMS has been observed, while a critical unpatched RCE in Gogs remains a significant risk. Additionally, targeted campaigns like Grandoreiro and JINX-0164 continue to threaten the financial and cryptocurrency sectors using platform-specific malware and DLL side-loading.
ESET APT Activity Report Q4 2025–Q1 2026 ESET's Q4 2025–Q1 2026 APT Activity Report highlights global espionage and destructive campaigns by state-aligned actors. Notable incidents include a major supply chain compromise of the 'axios' npm library by Lazarus, destructive wiper attacks on Polish critical infrastructure by Sandworm, and the deployment of new edge-device implants like PhiliKit against Ivanti VPNs by China-aligned groups.
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations WithSecure identified GREYVIBE, a Russia-nexus threat group targeting Ukrainian entities using spear-phishing, ClickFix, and fraudulent websites. The group systematically leverages Generative AI to develop custom malware (PhantomRelay, LegionRelay, FallSpy) and obfuscators, blending state-aligned intelligence gathering with cybercrime ecosystem overlaps.
Major Cyber Attacks in May 2026: Fake Invitations, Agent Tesla, BlobPhish, and More In May 2026, ANY.RUN observed a surge in sophisticated phishing and malware campaigns utilizing fileless execution, browser-based credential theft, and legitimate workflow abuse. Key threats included Agent Tesla credential harvesting, ClickFix fileless malware, BlobPhish in-memory page generation, and phishing-to-RMM chains bypassing traditional MFA via real-time OTP interception.
Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks Russian threat actor UTA0355 is conducting targeted phishing campaigns against foreign policy and government professionals by spoofing European security conferences. The attackers use rapport-building techniques and out-of-band messaging to trick victims into authorizing malicious Microsoft 365 OAuth applications and Device Code workflows, granting unauthorized access to their accounts.
IT threat evolution in Q1 2026. Mobile statistics In Q1 2026, mobile banking Trojans saw a significant surge, with Mamont variants driving a 50% increase in malicious installation packages. Additionally, a sophisticated new variant of the SparkCat crypto stealer was identified in official app stores, employing custom virtual machines and OCR techniques to compromise both Android and iOS users.
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Project Zero researchers developed a 0-click exploit chain for the Google Pixel 10 by chaining a known Dolby vulnerability (CVE-2025-54957) with a newly discovered, trivial local privilege escalation flaw in the device's VPU driver. The VPU vulnerability allowed unbounded physical memory mapping via the mmap syscall, granting arbitrary read/write access to the kernel image and enabling full device compromise.
Fake call logs, real payments: How CallPhantom tricks Android users ESET researchers discovered a cluster of 28 fraudulent Android applications, dubbed CallPhantom, that accumulated over 7.3 million downloads on Google Play. These apps deceive users by falsely claiming to retrieve call and message logs for arbitrary phone numbers, instead presenting hardcoded, randomly generated data to extort subscription payments via Google Play billing, UPI, or direct card entry.
Cyber Centre Daily Advisory Digest — 2026-05-05 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting May 2026 security rollups for Qualcomm and Android, alongside a specific advisory for Apache HTTP Server versions 2.4.66 and prior. Organizations utilizing these technologies are advised to review the respective vendor bulletins and apply available patches to mitigate potential vulnerabilities.
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack North Korea-aligned APT ScarCruft executed a multi-platform supply-chain attack compromising the sqgame platform to target ethnic Koreans in China's Yanbian region. The campaign distributed the BirdCall backdoor via trojanized Android applications and malicious Windows updates (which initially dropped RokRAT), enabling extensive espionage capabilities including data exfiltration, audio recording, and screen capture.
Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs Threat actors are utilizing Traffic Distribution Systems (TDS) to direct mobile users to fake CAPTCHA pages that trick them into sending premium international SMS messages. This International Revenue Share Fraud (IRSF) scheme leverages social engineering and back button hijacking to generate multiple SMS messages per victim, resulting in significant financial charges.
When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks Researchers have disclosed AirSnitch, a novel set of attack techniques that bypass WPA2 and WPA3-Enterprise Wi-Fi encryption and client isolation. By exploiting vulnerabilities in protocol-infrastructure interactions such as MAC address tables and routing layers, attackers can achieve Meddler-in-the-Middle (MitM) capabilities to intercept and inject traffic across enterprise networks.
New NGate variant hides in a trojanized NFC payment app ESET researchers identified a new variant of the NGate Android malware that trojanizes the legitimate HandyPay application to facilitate NFC relay attacks and steal payment card PINs. Targeting users in Brazil through social engineering and fake app stores, the malware allows attackers to conduct unauthorized ATM cash-outs while requiring no suspicious device permissions.
Intelligence Center The Q1 2026 vulnerability landscape shows a continued rise in overall CVEs and KEVs, with a significant focus on software supply chain compromises and networking gear. A notable emerging threat is the abuse of the n8n AI workflow automation platform to bypass traditional security filters, alongside the discovery of the PowMix botnet targeting Czech workers and ongoing exploitation of legacy vulnerabilities.
Scams, Slaves and (Malware-as-a) Service: Tracking a Trojan to Cambodia’s Scam Centers An Android banking trojan is being distributed globally as a Malware-as-a-Service (MaaS) from scam centers in Cambodia, utilizing forced labor to conduct social engineering campaigns. The malware features extensive surveillance capabilities, including SMS interception and biometric capture, allowing attackers to bypass KYC and OTP protections to commit direct financial fraud.
The Growing Abuse of GitHub and GitLab in Phishing Campaigns Threat actors are increasingly abusing legitimate Git repository platforms like GitHub and GitLab to host malware and credential phishing pages. By leveraging the inherent trust organizations place in these domains, attackers successfully bypass secure email gateways (SEGs) to deliver dual-threat campaigns involving remote access trojans (RATs), infostealers, and credential harvesting.
Latin America and the Caribbean Cybercrime Landscape In 2025, the Latin America and the Caribbean (LAC) region faced escalating cybercriminal activity driven by rapid digital adoption and economic instability. Threat actors heavily utilized Telegram and dark web forums to distribute ransomware, banking trojans, and infostealers, increasingly targeting the healthcare, manufacturing, and government sectors while adapting to law enforcement disruptions.
Patterns, Pirates, and Provider Action: What We Learned Working with Keitaro Cybercriminals are widely abusing the Keitaro ad tracking software as a Traffic Distribution System (TDS) to route victims to malware, crypto drainers, and scams. By utilizing cracked licenses, advanced traffic filtering, and third-party cloaking integrations, threat actors effectively evade detection while precisely targeting users based on device and geolocation.
Active Magecart Campaign Targets Spain, Steals Card Data via Hijacked eStores for Bank Fraud A sophisticated, long-running Magecart campaign has been compromising e-commerce websites to steal payment card data, with a notable focus on the Spanish payment ecosystem. The attackers utilize multi-stage JavaScript payloads, mimic legitimate payment gateways like Redsys, and exfiltrate stolen data in real-time via WebSockets to evade traditional detection mechanisms.
Android devices ship with firmware-level malware Security researchers have identified the Keenadu backdoor embedded in the firmware of multiple low-cost Android devices. The malware compromises the core Zygote process via a trojanized shared object library, allowing it to download second-stage modules for ad fraud and potentially exposing corporate credentials on BYOD devices.
2025 Year in Review: Malicious Infrastructure In 2025, Insikt Group observed the continued dominance of Cobalt Strike, AsyncRAT, and infostealers like Vidar, alongside the rise of new offensive tools such as RedGuard, Ligolo, and CastleLoader. The report highlights the critical role of Threat Activity Enablers (TAEs) and the abuse of legitimate infrastructure services, such as CDNs, in sustaining cybercriminal and APT operations.