⤷ Title: Samsung Galaxy S25 Zero-Day exploit: How Hackers Could Access Camera and Location
════════════════════════
𐀪 Author: Himanshu Bhatt
════════════════════════
ⴵ Time: Sun, 26 Oct 2025 07:02:13 GMT
════════════════════════
⌗ Tags: #accessibility #galaxy #samsung #exploit #hacking
════════════════════════
𐀪 Author: Himanshu Bhatt
════════════════════════
ⴵ Time: Sun, 26 Oct 2025 07:02:13 GMT
════════════════════════
⌗ Tags: #accessibility #galaxy #samsung #exploit #hacking
Medium
Samsung Galaxy S25 Zero-Day exploit: How Hackers Could Access Camera and Location
Researchers at a well-known hacking contest called Pwn2Own Ireland 2025 showed they could use a fresh, previously unknown software flaw (a…
⤷ Title: Next-Gen Android Banking Trojan Hides in Digital ID App, Automates Crypto Wallet Theft and Evades Emulators
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:08:58 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android Banking Trojan #anti_emulation #BankBot_YNRK #crypto wallet theft #JobScheduler #Southeast Asia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:08:58 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android Banking Trojan #anti_emulation #BankBot_YNRK #crypto wallet theft #JobScheduler #Southeast Asia
Daily CyberSecurity
Next-Gen Android Banking Trojan Hides in Digital ID App, Automates Crypto Wallet Theft and Evades Emulators
Cyfirma exposed Android/BankBot-YNRK, a Trojan cloning Indonesia’s Digital ID app to steal credentials and crypto assets. It uses anti-emulation checks and JobScheduler for persistent device takeover.
⤷ Title: Android 16 Update: AI Notification Summaries & Gemini-Powered Accessibility Suite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:10:23 +0000
════════════════════════
⌗ Tags: #Android #accessibility #AI Notifications #Android 16 #Circle to Search #dark theme #Expressive Captions #Gemini #Pixel Update #TalkBack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:10:23 +0000
════════════════════════
⌗ Tags: #Android #accessibility #AI Notifications #Android 16 #Circle to Search #dark theme #Expressive Captions #Gemini #Pixel Update #TalkBack
Daily CyberSecurity
Android 16 Update: AI Notification Summaries & Gemini-Powered Accessibility Suite
Android 16's second update brings AI notification summaries and anti-scam tools. Accessibility gains Gemini-powered TalkBack and Expressive Captions for enhanced user experience.
⤷ Title: GoldFactory Malware Injects FriHook/SkyHook into Banking Apps to Exploit 11K SE Asia Users
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:55:06 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Abuse #Android #FriHook #Gigabud #GoldFactory #Group_IB #Mobile Banking Malware #phishing #SkyHook #Southeast Asia
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:55:06 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Abuse #Android #FriHook #Gigabud #GoldFactory #Group_IB #Mobile Banking Malware #phishing #SkyHook #Southeast Asia
Penetration Testing Tools
GoldFactory Malware Injects FriHook/SkyHook into Banking Apps to Exploit 11K SE Asia Users
The GoldFactory group has launched a new wave of attacks targeting mobile-banking users across Southeast Asia. Disguising themselves
❤1
⤷ Title: Evolved ClayRat Spyware Gains Self-Defense, Using Accessibility Abuse to Block Uninstallation and Steal Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:22:44 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android Spyware #ClayRat #dropbox #Keylogger #Lockscreen Bypass #MediaProjection API #Self_Defense
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:22:44 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android Spyware #ClayRat #dropbox #Keylogger #Lockscreen Bypass #MediaProjection API #Self_Defense
Daily CyberSecurity
Evolved ClayRat Spyware Gains Self-Defense, Using Accessibility Abuse to Block Uninstallation and Steal Keys
Evolved ClayRat spyware uses Accessibility Services to install a keylogger and lockscreen bypass. It leverages self-defense (blocking uninstallation) and screen recording for comprehensive surveillance.
⤷ Title: Total Takeover: Droidlock Android Malware Locks Phones, Records Screen, and Bypasses Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:42:21 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android malware #Device Admin #Droidlock #mobile security #phishing #ransomware #Screen Capture #Zimperium
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:42:21 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android malware #Device Admin #Droidlock #mobile security #phishing #ransomware #Screen Capture #Zimperium
Penetration Testing Tools
Total Takeover: Droidlock Android Malware Locks Phones, Records Screen, and Bypasses Security
A new Android malware known as Droidlock turns an infected smartphone into a device fully controlled by attackers.
⤷ Title: The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:33:47 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Service #Android security #Belarus #Journalists #KGB #Physical Access #Reporters Without Borders #ResidentBat #spyware #surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:33:47 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Service #Android security #Belarus #Journalists #KGB #Physical Access #Reporters Without Borders #ResidentBat #spyware #surveillance
Daily CyberSecurity
The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools
RSF uncovers ResidentBat, a Belarusian KGB spyware physically installed during interrogations to hijack encrypted messages and monitor journalists.
⤷ Title: New TCC Bypass (CVE-2025-43530) Exposes macOS to Unchecked Automation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 00:06:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #accessibility #Apple #AppleScript #CVE_2025_43530 #macOS #macOS Sequoia #macOS Sonoma #macOS Tahoe #Mickey Jin #privacy #TCC Bypass #TOCTOU #Voiceover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 00:06:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #accessibility #Apple #AppleScript #CVE_2025_43530 #macOS #macOS Sequoia #macOS Sonoma #macOS Tahoe #Mickey Jin #privacy #TCC Bypass #TOCTOU #Voiceover
Daily CyberSecurity
New TCC Bypass (CVE-2025-43530) Exposes macOS to Unchecked Automation
Apple’s privacy fortress, the Transparency, Consent, and Control (TCC) framework, has been breached once again. Security researcher Mickey Jin (@patch1t) has disclosed a sophisticated new vulnerab…
⤷ Title: AI Hub Hijacked: Polymorphic Android RAT Abuses Hugging Face to Steal Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services Abuse #Android RAT #Banking Trojan #Bitdefender #Cybercrime #Hugging Face #mobile security #Polymorphic Malware #Premium Club #TrustBastion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services Abuse #Android RAT #Banking Trojan #Bitdefender #Cybercrime #Hugging Face #mobile security #Polymorphic Malware #Premium Club #TrustBastion
Daily CyberSecurity
AI Hub Hijacked: Polymorphic Android RAT Abuses Hugging Face to Steal Data
⤷ Title: PortSwigger Labs: User ID Controlled by Request Parameter (Lab 7 & 8)
════════════════════════
𐀪 Author: Sanjivani Dobhal
════════════════════════
ⴵ Time: Sun, 22 Feb 2026 17:29:51 GMT
════════════════════════
⌗ Tags: #hacking #portswigger #accessibility #penetration_testing #idor
════════════════════════
𐀪 Author: Sanjivani Dobhal
════════════════════════
ⴵ Time: Sun, 22 Feb 2026 17:29:51 GMT
════════════════════════
⌗ Tags: #hacking #portswigger #accessibility #penetration_testing #idor
Medium
PortSwigger Labs: User ID Controlled by Request Parameter (Lab 7 & 8)
In this blog, I explain Lab 7 and Lab 8 from the PortSwigger Web Security Academy, both focused on Insecure Direct Object Reference (IDOR)…