-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Android | Breaking Cybersecurity News | The Hacker News

Category — Android
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Sep 02, 2026 Malvertising / Mobile Security
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported. Device takeover requires the victim to grant a succession of controls after sideloading the Android Package (APK). Users should stop the installation when a streaming app requests system controls unrelated to streaming. "There is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem," ThreatFabric said in its  StreamRat analysis . ThreatFabric did not attribute the campaign t...
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Aug 28, 2026 Cellular Security / Encryption
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello ( ECH ), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem with private DNS to obscure the domain names you visit, hiding metadata that can be used to profile you," Google's Bram Bonné and Shuaibo Huang said . "By encrypting the destination website name from the very start, ECH helps ensure that, for supported websites and apps, network providers and network snoopers can no longer easily see which websites or apps you are accessing."
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

Aug 25, 2026 Authentication / Password Security
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023, before expanding to iOS in early 2024. Meta also followed it up by integrating passkeys into Facebook logins in June 2025. Users can manage their passkeys by navigating to Settings > Account > Passkeys. Along with the update, WhatsApp said it's adding a full password option as part of two-step verification, and users on Android will see more context on calls from people who aren't in their contacts. "Two-step verification is an extra protection layer that helps prevent someone from taking over your account, even if they get hold of your one-time passcode," WhatsApp...
cyber security

Shadow AI Agents Are Multiplying. Here's How to Find and Secure Them

websiteNudge SecuritySaaS Security / AI Security
Learn how eight common discovery approaches work, what they find, and what they don’t.
cyber security

Gartner: 70% of SOCs Will Pilot AI Agents. Only 15% Will See Results

websiteProphet SecurityAI SOC / Cybersecurity
Here are Gartner’s key questions to ask when pressure-testing AI SOC vendors in production.
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Aug 14, 2026 Malware / Cybercrime
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party. During the first half of 2026, 50,400 dropcatch domains were re-registered each day in the generic top-level domains (gTLDs) like ".com" alone, a figure that jumps to around 65,000 when country code top-level domains (ccTLDs) are taken into consideration. These account for nearly 20% of all daily gTLD and ccTLD registrations, meaning one out of five newly registered domains is a dropcatch domain. "These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life," Infoblox said in an exhaustive three-part report shared with The Ha...
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

Aug 11, 2026 IoT Security / Mobile Security
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it switched on in 9 of them, and used it to run their own code on a commercial EV charger. Six of the eight cellular modules they tested accepted the command. Only 3 of 18 phones did: the OPPO Find X5, the OPPO Reno 14 F 5G, and the ASUS Zenfone 9. No iPhone or Pixel was among them. The exposure is in machine-to-machine hardware. Five of the six were Quectel parts, three of them pulled from an EV charger, an industrial router, and a car's telematics control unit. Knowing the victim's number is not enough: every attack starts with a hostile card already in the slot, swapped by hand,...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources