
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
Two concurrent Android banking malware campaigns — GoldFactory’s Gigabud trojan and Mantax Otax ransomware-spyware hybrid — target Indonesian users with

Two concurrent Android banking malware campaigns — GoldFactory’s Gigabud trojan and Mantax Otax ransomware-spyware hybrid — target Indonesian users with

Malicious developers abuse Google Play’s Early Access program to push thousands of deceptive Android apps promising money, rewards, and premium

China-linked UNC3569 exploited a vulnerability in Tencent’s Sogou Input Method, one of the most widely used Chinese typing tools for

Threat actors exploit BYOD gaps through vishing to gain M365 access, then use Microsoft Graph API to enumerate corporate structure

Critical authentication bypass vulnerability CVE-2026-19490 in Citrix NetScaler has been actively exploited since September 3, enabling unauthenticated attackers to bypass

Cybercriminals harvest AI session tokens from infostealer malware logs to hijack Google, Anthropic, and OpenAI accounts, bypassing MFA through token

Google released Chrome security update on September 9 patching CVE-2026-87491, an out-of-bounds write in V8 engine — the seventh actively

SophosLabs published analysis of PoisonedRefresh, a fileless Linux rootkit that injects PHP web shells directly into F5 BIG-IP APM Apache

Microsoft’s September security updates cause Remote Desktop Services failures on Windows Server 2019, 2022, and 2025, with some systems requiring

Microsoft’s KB5002914 Office security update breaks copy-and-paste operations and formula dragging in Excel, with affected users removing the update to
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.