Google’s September 2026 Android security update resolves 34 vulnerabilities, led by critical zero-click remote code execution defects in the Android System framework.
Bitdefender reveals threat actors are exploiting Google Play’s Early Access program to bypass user reviews and star ratings, pushing deceptive apps with over 1M downloads.
ThreatFabric uncovers StreamRAT, a sophisticated Android banking trojan promoted via fraudulent Meta TV streaming ads, hijacking Accessibility services to drain accounts.
Group-IB uncovered a major evolution in the Gigabud banking trojan, which uses Android enterprise Work Profiles to isolate tampered banking apps and blind client security checks.