codes

AppWizard
September 22, 2026
Cybersecurity researchers at Zimperium have identified a new strain of malware called RatHat, targeting Android devices and linked to threat actors from China. RatHat uses generative AI to maintain persistence and control over infected devices. The malware is typically spread through social engineering, tricking users into downloading counterfeit applications that appear legitimate. Once installed, RatHat requests accessibility permissions, activates Wireless Debugging, and can capture text messages, create overlays, and steal passwords and multi-factor authentication codes. Its AI capabilities allow it to navigate the device interface in real-time, making detection by security software more difficult. To protect against RatHat, users should avoid downloading apps from untrustworthy sources, and removal requires a factory reset of the device.
Tech Optimizer
September 21, 2026
The landscape of computer security has changed significantly over the past two decades. In 2026, antivirus protection remains important, but the need for separate third-party programs has decreased for many users due to the built-in Microsoft Defender in Windows 11, which is activated by default and effectively blocks 100% of common malware samples according to independent testing by AV-TEST. Windows 11 also includes additional protective features like SmartScreen and a robust Firewall. While dedicated security suites from companies like Norton and Bitdefender offer advanced functionalities, many users may find adequate protection with the built-in tools. Research from AV-Comparatives indicates that performance varies among security programs, particularly against real-world attacks. Phishing attacks accounted for approximately 60% of initial access points in incidents examined by the ENISA Threat Landscape report from 2025, highlighting that user behavior is a significant vulnerability. Modern web browsers and operating systems have enhanced their security measures, with Google Chrome, Microsoft Edge, macOS, and Android incorporating features to protect users from harmful websites and downloads. For the average Windows 11 user who keeps their system updated and practices safe browsing, built-in protection is generally sufficient, though paid antivirus options can provide additional tools.
AppWizard
September 19, 2026
A new Android malware called RatHat has emerged, analyzed by researchers from Zimperium's zLabs. It spreads through deceptive smishing texts and malicious ads that lead users to counterfeit download pages for popular apps. Once installed, it manipulates Android's Accessibility Service to gain elevated access by enabling Wireless Debugging and retrieving authentication codes without user intervention. RatHat targets finance and banking apps to steal user IDs, passwords, and MFA codes, using techniques to obtain touch coordinates for PIN recovery. It can intercept SMS messages, gain limited control of the device, and reinstall itself. Users are advised against sideloading apps and granting unnecessary accessibility permissions. Google's Advanced Protection Mode and Malwarebytes for Android can help mitigate risks associated with RatHat.
AppWizard
September 19, 2026
Security researchers have identified an Android banking Trojan named RatHat, which utilizes artificial intelligence, accessibility features, and Android Debug Bridge (ADB) to steal financial credentials, PINs, and one-time passcodes. Unlike traditional malware, RatHat employs a live AI assistant that interacts with the Android accessibility tree, allowing it to make real-time decisions based on the victim's screen content. The infection typically starts with social-engineering tactics, leading victims to counterfeit download pages where they are tricked into sideloading a malicious APK. Once installed, RatHat prompts users to enable Android Accessibility Service permissions, which it exploits to navigate Developer Options and enable Wireless Debugging. This grants it shell-level ADB access, allowing it to bypass application sandbox restrictions. RatHat deploys two native binaries for executing commands and maintaining a connection to the attacker's infrastructure. It targets banking applications through credential-stealing overlays and can intercept SMS messages for transaction verification codes. Additionally, it can record touch coordinates to reconstruct PINs and unlock patterns. RatHat includes persistence mechanisms to restore itself after removal, and users are advised to perform a factory reset if they suspect compromise. To reduce infection risk, users should avoid sideloading apps from unknown links, deny unnecessary Accessibility Service requests, and refrain from enabling Developer Options or Wireless Debugging for unfamiliar applications.
Winsage
September 19, 2026
Windows XP was released in two versions: Retail for individual consumers and Volume for Microsoft's partners and OEMs. The product key FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8 became widely recognized due to a potential leak by an insider at a major OEM, which was then spread by the pirate group Devils0wn. The Volume version's activation system required a unique key, but the FCKGW key was incompatible with the standard installation CD. To verify the legitimacy of Volume discs, the activation system searched for a secret 10MB binary blob exclusive to the Volume media. Microsoft blacklisted the FCKGW key with Service Pack 1 and implemented further security measures with Service Pack 2, restricting access to certain updates. Contrary to prior beliefs, the key's functionality was not due to a simple key generation algorithm but was designed by skilled engineers.
AppWizard
September 17, 2026
Security researchers at Zimperium have identified a new strain of Android malware called RatHat, which is linked to threat actors from China and is designed to steal sensitive credentials and banking information. RatHat infiltrates devices through phishing sites, malvertising, and SMS phishing (smishing), tricking users into downloading malicious Android package kits (APKs). The malware uses a dropper to activate its payload, which is hidden in encrypted assets, and employs techniques to bypass Android's security measures. RatHat consists of three main components: a malicious Android application, a Go agent (liblocal-service.so), and an FRP client (libmedia_codec.so). The app collects sensitive information such as banking credentials, notifications, 2FA codes, OTP keys, and screen inputs. It features a generative AI user interface-automation engine that communicates in Mandarin and can perform various tasks like determining screen coordinates and issuing navigation commands. The Go agent acts as a command-and-control executor, executing commands to bypass app-level security and manage system-level tasks. The FRP client maintains a secure reverse tunnel to the attacker's server, allowing ongoing remote access to the device. The architecture of RatHat demonstrates the inadequacy of traditional mobile security measures against such advanced threats.
AppWizard
September 17, 2026
On September 15, 2026, Google released the beta OS update "Android 17 QPR2 Beta 5" for Google Pixel devices in the Android Beta Program. This update includes support for new Pixel devices: "Pixel 11," "Pixel 11 Pro," "Pixel 11 Pro XL," and "Pixel 11 Pro Fold," while excluding "Pixel 6" and "Pixel 6 Pro." The update is distributed via Over-the-Air (OTA) to 23 models, including "Pixel 6a," "Pixel 7," and "Pixel 8 Pro." Key features include "Call Forwarding Hardening," which restricts access to call-forwarding USSD codes to enhance security against scams. The update also includes eight bug fixes, addressing issues with Bluetooth device type display, unexpected reboots, volume slider UI, text rendering, Private Space unlocking, HDR mode, Camera app crashes, and Bluetooth audio distortion. The build number changes to "CP41.260828.004.A8" or "CP41.260828.005.A6," with the Android security patch level updated to "August 5, 2026," and "Google Play services" upgraded to version 26.28.33 or later.
AppWizard
September 16, 2026
A new feature called "expert mode" is being introduced to enhance the "Advanced Protection" framework for Android users, allowing them to toggle specific security features individually. Users will be able to manage six distinct items within the Advanced Protection suite: Intrusion logging, USB protection, Block auto-connection to unsecured Wi-Fi, Unknown apps, Spam filter, and Suspicious links in Google Messages. The "expert features" will not replace "Advanced Protection" but will provide users with the option to enable all protections at once or selectively activate specific features. While "Block auto-connection to unsecured Wi-Fi" will debut with "expert features," the inclusion of "Unknown apps," "Spam filter," and "Suspicious links in Google Messages" in the final version remains uncertain. The relevant resource for updates is the "Google Play services" app, version v26.36, released on September 15, 2026.
Tech Optimizer
September 15, 2026
In 2026, McAfee introduced its AI-powered Scam Detector as part of the McAfee+ suite, which includes antivirus protection, identity monitoring, privacy tools, VPN services, and financial safeguards. The McAfee+ Advanced tier is available for .99 for the first year, reduced from 9.99, and a family plan for up to six members is priced at 9.99, down from 9.99. Each plan includes a 30-day money-back guarantee. Research shows Americans receive an average of 14 scam messages daily, with one in three falling victim to online scams, losing an average of ,160. The Scam Detector identifies threats such as suspicious texts, emails, deepfake videos, and risky websites, and includes a QR code safety check. It is included in all McAfee core plans at no additional cost.
Search