Bransys ELD is facing serious security vulnerabilities that could allow unauthorized access to sensitive telemetry data and firmware. The vulnerabilities, identified as CVE-2026-86520, CVE-2026-86689, and CVE-2026-77960, affect versions of the Bransys ELD app on Android devices older than 11.00.00 and iOS devices older than 1.1.54. The issues include hardcoded credentials for MQTT and FTP, which could enable attackers to read real-time data and access sensitive information transmitted in cleartext. Users are urged to update their apps to the latest versions to protect against these risks, as exploitation could have significant implications for data integrity and privacy, especially in the transportation sector where the system is deployed.
Articles tagged "Android"
Found 58 articles
Google has rolled out its September 2026 security patches to fix 110 vulnerabilities across its Pixel devices, including a significant zero-day flaw that has been actively exploited in targeted attacks. This zero-day vulnerability poses a risk to users, as it can be exploited by attackers to gain unauthorized access to devices. The timely release of these patches is crucial, as it helps protect users from potential data breaches and other malicious activities. Pixel device owners are encouraged to update their devices promptly to mitigate the risk associated with this flaw and the other vulnerabilities addressed in the patch. Staying up to date with security updates is essential for maintaining device security.
Indonesia is facing a cybersecurity threat from a group known as GoldFactory, which is using a technique involving the Android Work Profile feature to distribute the Gigabud Trojan. This malicious software targets Android banking apps, allowing attackers to steal sensitive financial information from users. Another group, Mantax Otax, is reportedly spreading malware independently. This situation raises concerns for Android users in Indonesia, particularly those who rely on banking apps for financial transactions. The ability of these groups to exploit legitimate features in Android underscores the need for heightened vigilance among users and better security measures from app developers.
The Hacker News
Researchers from the security firm Calif have demonstrated a new worm that can take over WeChat accounts through incoming calls, without the recipient needing to answer or interact with their phone. This attack requires that the caller is already in the victim's WeChat contacts. Calif tested the worm on three different phones, successfully showing how it propagates. The company reported this vulnerability to Tencent, the owner of WeChat, in July 2023. This type of attack raises significant concerns for users, as it exploits a common communication method and could potentially compromise personal information or lead to unauthorized access to accounts.
The latest Android 17 update introduces support for Encrypted Client Hello (ECH), a feature designed to enhance privacy by encrypting parts of the initial connection handshake, making it harder for network snoopers to intercept data. This update also includes a '2G kill switch' feature, allowing users to disable 2G connections, which are more susceptible to security vulnerabilities. These changes aim to protect users from unwanted surveillance and spam SMS messages, which can be a significant nuisance and security risk. Overall, the update is a step forward in securing mobile communications, especially for users concerned about privacy. By implementing these features, Android 17 users will have better control over their data and enhanced protection against various cyber threats.
A group known for operating a click-fraud botnet is now targeting infotainment systems in vehicles, exploiting legitimate update mechanisms to spread malware. This new tactic allows attackers to hijack the update process, potentially infecting car head units with malicious software. The implications of this are concerning, as it could compromise the functionality of car systems and expose personal data of drivers and passengers. This type of attack not only puts individuals at risk but also raises questions about the security of automotive software updates. Users of affected vehicle infotainment systems should remain vigilant and consider how they manage software updates to protect against these threats.
Security Affairs
A new version of the malware known as ToxicPanda has been reported, now dubbed ToxicPanda 2.0. This upgraded malware is expanding its reach and has been detected in 16 different countries. Researchers have found that it specifically targets Android car head units, hijacking them for malicious purposes. This poses significant risks for drivers as it can compromise vehicle systems and potentially allow attackers to manipulate navigation and other functions. Users and manufacturers of affected devices need to be vigilant and implement security measures to protect against this evolving threat.
A new Android malware called Manic has emerged, targeting users across several European countries. This malware is particularly concerning because it can exfiltrate data not just through traditional means, but also by leveraging nearby infected devices. This makes it more difficult for users to detect and defend against. Researchers have identified the malware's ability to communicate with other compromised devices, potentially allowing attackers to gather sensitive information from a wider network of victims. This situation raises alarms about the security of Android devices and the need for users to be vigilant about app permissions and device security.
The Hacker News
Researchers from SSD Secure Disclosure have identified a serious vulnerability in Unisoc modem firmware that allows attackers to gain full access to the Android kernel through a VoLTE video call. This exploit chain, disclosed on August 17, 2026, is a continuation of a previous discovery from March 2026, which involved remote code execution. Currently, there is no fix available from Unisoc, leaving devices that use this firmware at risk. The implications of this vulnerability are significant, as it can potentially allow attackers to control affected devices completely. Users with devices running Unisoc chipsets should be particularly cautious, as they are directly impacted by this security issue.
Help Net Security
Researchers from Group-IB have identified a new Android malware called WindRelay that poses a significant threat to users by capturing real-time payment card data via NFC (Near Field Communication). The malware works in conjunction with the SpyNote remote access trojan, enabling attackers to gain control over a victim's device and relay sensitive information directly to them. The attack typically begins with a phone call from a fraudster impersonating a bank representative, tricking victims into revealing their financial data. This malware not only compromises personal financial security but also highlights the growing sophistication of cybercriminal tactics. Users need to be vigilant about unsolicited calls and consider additional security measures to protect their payment information.
The Hacker News
Researchers from Palo Alto Networks Unit 42 have identified a new version of the Kimwolf botnet, known as Kimwolf v7, which targets Android devices and Internet of Things (IoT) devices. This upgraded botnet enhances its ability to launch distributed denial-of-service (DDoS) attacks by disguising its HTTP/2 traffic to resemble legitimate web browsing. This makes it harder for security systems to detect and mitigate the attacks. The discovery of Kimwolf v7 raises concerns for users of vulnerable Android and IoT devices, as attackers can exploit these weaknesses to disrupt services and potentially gain unauthorized access to sensitive information. Companies and users need to be vigilant and ensure their devices are secured against such threats.
Researchers from Flare have examined the underground market for BTMOB, a type of Android malware. Their analysis revealed a complex network of resellers, vendors offering source code, and various customized versions of the malware being sold across different platforms. This fragmentation indicates that the malware operation has evolved significantly, with multiple players now involved in its distribution and refinement. The implications are serious, as this could lead to more widespread attacks on Android users, putting sensitive data at risk. Understanding this ecosystem is crucial for cybersecurity professionals who need to combat the increasing sophistication of mobile threats.
The Hacker News
The source code for the Flying Eagle Android remote access trojan (RAT) has been found circulating in criminal Telegram channels, raising concerns about potential exploitation. Researchers from Hunt.io and NetAskari traced this malicious framework to 170 internet servers, linking it to a deceptive application masquerading as a Chinese Public Security service. This application targets Android users in China and reportedly supports functionalities related to payment passwords. The distribution of this RAT poses significant risks to users, as it can enable attackers to gain unauthorized control over devices, potentially leading to data theft and financial fraud. Users in China, particularly those using the compromised app, should be vigilant and avoid downloading unverified applications to protect their personal information.
A vulnerability in the igloohome Smart Lock Mobile Application has been discovered, affecting version 3.2.3 and earlier. This flaw, identified as CVE-2026-16581, allows unauthorized access to backend services due to sensitive information being included in the application's source code. As a result, attackers could exploit this weakness to access functionality that should be protected by authentication measures. igloohome has addressed the issue by enhancing access controls to prevent unauthorized requests. Users are advised to ensure they are using the latest version of the app to mitigate risks.
A vulnerability has been identified in the Johnson Controls XAAP Android application, specifically in versions prior to 1.53. This flaw allows sensitive data to be stored in cleartext on devices, making it accessible to attackers who have physical access or can exploit another vulnerability on the device. The issue does not require network access and poses risks to users worldwide, particularly in critical manufacturing sectors. Johnson Controls advises users to upgrade to version 1.53 or later to mitigate this risk, and recommends implementing additional security measures such as restricting physical access, enabling device encryption, and using Mobile Device Management solutions to enforce security policies. Currently, there have been no reports of this vulnerability being actively exploited in the wild.