# Archive

Browse past daily curated stories

Aug 24 Aug 23 Aug 22 Aug 21 Aug 20 Aug 19 Aug 18 Aug 16 Aug 15 Aug 14 Aug 13 Aug 12 Aug 09 Aug 08 Aug 07 Aug 06 Aug 05 Aug 04 Aug 03 Aug 02 Aug 01 Jul 31 Jul 30 Jul 29 Jul 28 Jul 27 Jul 26 Jul 25 Jul 24 Jul 23

Monday, August 24, 2026

  1. 1
    0
    BleepingComputer general
    ToxicPanda Android malware uses VPN permissions to block Google Play

    ToxicPanda Android malware has undergone significant expansion, now targeting 349 applications and supporting 167 remote commands. The updated variant abuses VPN permissions to block Google Play, likely to prevent security updates or competing app installations. Security teams managing Android device fleets should review VPN permission grants and monitor for unauthorized command-and-control activity.

  2. 2
    0
    SecurityWeek general
    Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

    Three active banking trojans are highlighted: Manic (equipped with spyware capabilities), Grandoreiro (ongoing campaigns across Latin America and Europe), and ToxicPanda 2.0 (expanded targeting). The convergence of spyware functionality into banking trojans represents an escalation in credential-theft tooling. Financial sector defenders should update detection rules for all three malware families.

  3. 3
    0
    BleepingComputer general
    Hackers infect Android car head units with proxy botnet malware

    A supply-chain attack targeting Android-based automotive head units is distributing malware through a trojanized legitimate device-update application. Compromised units are enrolled into a proxy botnet or used for ad fraud, affecting an embedded device category with limited endpoint security tooling. The attack vector — a legitimate update mechanism — makes detection particularly difficult without firmware integrity verification.

  4. 4
    0
    Dark Reading general
    Hardware Makers Implement Post-Quantum Cryptography as Security Threats Near

    Hardware manufacturers are actively implementing post-quantum cryptography (PQC) algorithms in response to the anticipated threat of cryptographically relevant quantum computers capable of breaking RSA and ECC. Tech companies are beginning to integrate NIST-standardized PQC algorithms into silicon and firmware. Security architects planning long-lifecycle hardware deployments should prioritize crypto-agility and PQC readiness in procurement requirements.

  5. 5
    0
    Dark Reading general
    How an Emerging Industrial Protocol Family Could Put OT at Risk

    New research exposes attack vectors against Time-Sensitive Networking (TSN) protocols used in industrial OT environments, where insufficient protection could allow attackers to disrupt or manipulate physical processes. TSN is an emerging IEEE 802.1 protocol family increasingly adopted in industrial automation and smart manufacturing. OT security teams should audit TSN deployments for missing authentication and encryption controls.

  6. 6
    0
    The Hacker News general
    TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

    ByteDance-owned TikTok agreed to pay $400 million to settle a 2024 U.S. DoJ lawsuit alleging violations of child privacy laws, with $300 million due immediately and $100 million contingent on vacating a prior consent decree. The settlement follows years of regulatory scrutiny over TikTok's data handling practices affecting minors. Privacy and compliance teams at consumer platforms should note the scale of enforcement action as a benchmark for COPPA-related liability.

  7. 7
    0
    BleepingComputer general
    Named Pipes Under Attack: Securing Windows Interprocess Communication

    ThreatLocker published analysis of attack techniques targeting Windows named pipes, a mechanism used for interprocess communication (IPC) that can expose privileged services to untrusted processes when access controls are misconfigured. Recommended mitigations include endpoint verification, command authorization, strict input validation, and least-privilege scoping for pipe access. Windows endpoint defenders should audit named pipe ACLs, particularly for services running as SYSTEM or high-integrity processes.

  8. 8
    0
    Ars Technica Security general
    Due to need for 'absolute success,' China delays critical Moon launch to 2027

    China has delayed its Chang'e 7 lunar mission to 2027, citing conditions that do not meet requirements for launch. This story is not directly relevant to cybersecurity but may be of peripheral interest given the geopolitical context of space programs. No cybersecurity implications are detailed in the article.

  9. 9
    0
    CyberScoop general
    Postal Service moves to finalize mail ballot regs before SCOTUS ruling

    The U.S. Postal Service is moving to finalize mail ballot regulations ahead of a potential Supreme Court ruling, despite the rules being rejected by multiple state courts. This is a policy and election administration story with limited direct cybersecurity relevance. Election security practitioners may monitor for related digital influence or disinformation operations.

  10. 10
    0
    Ars Technica Security general
    Volcanoes that made history

    This Ars Technica article covers the historical climate and societal impact of major volcanic eruptions, with no cybersecurity content. It is included only to fulfill the selection count requirement and has no relevance to the security community.