phone calls

AppWizard
July 29, 2026
Android users experiencing unexpected ads after phone calls are encountering a form of ad fraud linked to applications on the Google Play Store that utilize a tactic called AfterCall. These applications, often benign utility apps, request overlay permissions to display ads over the Android interface. They can launch full-screen advertisements disguised as call information screens after detecting the end of a call. Overlay permissions are categorized as "special permissions" and require users to enable them in system settings, rather than through typical installation pop-ups. Users are advised to check for apps with overlay permissions by navigating to Settings > Apps > Special app access and uninstall any unfamiliar applications. Regular audits of these permissions are recommended to disable unnecessary ones. While these apps primarily serve as an annoyance, they can waste advertising dollars and potentially harm brand reputations.
AppWizard
July 23, 2026
GitHub will reject command-line support bundle uploads from outdated versions of GitHub Enterprise Server lacking security patches starting August 18, 2026. The npm package @copilot-mcp/apex has been identified as a post-install dropper that installs a macOS infostealer, phishing for sensitive information and maintaining a connection to an attacker's server. A rogue extension on the Microsoft Visual Studio Code marketplace, "Markdown All Pro," impersonates a legitimate tool and opens a backdoor after installation. A phishing campaign targeting Portuguese users delivers the Lampion banking malware, which has been active since 2019. DoubleVerify reports a rise in "AfterCall" apps that exploit user permissions for ad fraud. The GhostCommit attack method hides malicious instructions within PNG images in pull requests. The U.S. government has updated its advisory on Iranian-affiliated cyber activity targeting operational technology devices. An Android app posing as a civil defense alert system has been found to contain malware for data harvesting. An Iranian threat actor is distributing MarkiRAT malware through fake applications. An analysis of 28 AI-coded applications revealed 434 vulnerabilities, prompting Cisco to introduce Antares to identify vulnerabilities in codebases. A Russian-speaking threat actor is dismantling guardrails on AI models to create offensive tools.
AppWizard
July 2, 2026
Pixel users are experiencing a "missing incoming call" bug that prevents notifications for incoming calls across various Pixel devices. This issue is linked to the Google Phone app and has persisted for several months, affecting users even after updates, including those on the Android 17 QPR1 Beta 5. Reports indicate that some users have resolved the issue by disabling the Call Screen feature. Android Central has noted the problem and reached out to Google for clarification.
AppWizard
June 23, 2026
Google is developing a feature called "Audio Memory" for its Pixel phones, which aims to enhance user experience by capturing music and significant conversations, potentially transcribing them for future reference. This feature will allow users to recall music they've encountered and may transcribe important discussions to create notes. The discovery of Audio Memory was made during an exploration of the latest Android System Intelligence for Pixel devices, enhancing the existing "Music Recognition" capability. Google envisions Audio Memory as a tool to track what users hear throughout the day, although details on its application remain uncertain. Additionally, Google has introduced memory features in its Gemini app that leverage users' personal context to recall previous discussions. Concerns about privacy are anticipated, and Google is expected to implement controls for managing what devices remember.
AppWizard
June 10, 2026
A 21-year-old woman shared her story on Reddit about developing a relationship with her brother's best friend after bonding over Minecraft. Initially, she thought her feelings were unreciprocated, but their gaming sessions led to increased communication and a coffee date, where they both expressed mutual feelings. They have been dating for three months, and her brother supports their relationship. The post received over 22,000 upvotes and sparked more than 900 comments from the Reddit community, celebrating their connection.
AppWizard
June 8, 2026
New variants of the NFCShare Android malware are disguised as fake updates for legitimate banking applications and are targeting customers of various banks in Europe through a phishing campaign to steal sensitive payment card data. The malware prompts victims to place their cards near the NFC chip of their mobile devices, using Android’s IsoDep interface to read card information, including card number, type, expiry date, and a 4-digit PIN. The stolen data is exfiltrated to the attacker’s command-and-control host via a WebSocket channel. Recent attacks began on May 14, with victims directed to a phishing site that impersonates a legitimate bank and then to a GitHub repository hosting a malicious APK file. The repository has hosted 56 unique APKs impersonating banking applications primarily from Italy and Spain. The malware has evolved from initially targeting Deutsche Bank in Germany to a broader range of banks. The latest version features malformed APK packaging to complicate automated analysis. Users are advised to download banking applications only from Google Play and to be cautious of verification requests that ask for NFC card scans.
Search