security restrictions

AppWizard
September 17, 2026
Security researchers at Zimperium have identified a new strain of Android malware called RatHat, which is linked to threat actors from China and is designed to steal sensitive credentials and banking information. RatHat infiltrates devices through phishing sites, malvertising, and SMS phishing (smishing), tricking users into downloading malicious Android package kits (APKs). The malware uses a dropper to activate its payload, which is hidden in encrypted assets, and employs techniques to bypass Android's security measures. RatHat consists of three main components: a malicious Android application, a Go agent (liblocal-service.so), and an FRP client (libmedia_codec.so). The app collects sensitive information such as banking credentials, notifications, 2FA codes, OTP keys, and screen inputs. It features a generative AI user interface-automation engine that communicates in Mandarin and can perform various tasks like determining screen coordinates and issuing navigation commands. The Go agent acts as a command-and-control executor, executing commands to bypass app-level security and manage system-level tasks. The FRP client maintains a secure reverse tunnel to the attacker's server, allowing ongoing remote access to the device. The architecture of RatHat demonstrates the inadequacy of traditional mobile security measures against such advanced threats.
AppWizard
August 17, 2026
Google has rolled out Android 17 QPR2 Beta 3 for enrolled Pixel testers, introducing significant security measures against call-forwarding fraud. The update is available for Pixel 6a, Pixel 7, 7 Pro, 7a, Pixel Fold, and Pixel Tablet users, who will receive version vCP41.260731.005.A2, while other users will be on version vCP41.260731.005.B1. The beta addresses bugs such as "visual corruption" and unexpected device restarts, and resolves misleading battery capacity warnings. New security restrictions include API restrictions and an OS-level confirmation dialog for call-forwarding commands. The Quick Settings layout has been revamped, allowing users to customize their arrangement of key buttons. The Pixel 6 and Pixel 6 Pro have been removed from the Android beta program, and the focus will now be on devices starting from the Pixel 6a. The Pixel 11 series has officially debuted with pre-order deals available.
Winsage
February 12, 2025
Microsoft's February Patch Tuesday update addresses 61 vulnerabilities, including 25 critical Remote Code Execution (RCE) vulnerabilities. Three of these are zero-days, actively exploited before the update: 1. CVE-2023-24932: Secure Boot security feature bypass requiring physical access or administrative rights. 2. CVE-2025-21391: Windows Storage elevation of privilege vulnerability that could lead to data deletion. 3. CVE-2025-21418: Vulnerability in Windows Ancillary Function Driver for WinSock allowing privilege escalation. Critical vulnerabilities include: - CVE-2025-21376: Windows LDAP RCE vulnerability. - CVE-2025-21379: RCE vulnerability in DHCP Client Service. - CVE-2025-21381: RCE vulnerability in Microsoft Excel. The update also addresses additional vulnerabilities related to remote code execution, elevation of privilege, denial of service, security feature bypass, spoofing, and information disclosure across various Microsoft products. Microsoft advises immediate application of the updates to mitigate risks.
Winsage
August 19, 2024
A security vulnerability in Microsoft Windows, identified as CVE-2024-38193, has been exploited by the Lazarus Group, a state-sponsored entity linked to North Korea. This privilege escalation bug, categorized within the Windows Ancillary Function Driver (AFD.sys) for WinSock, has a CVSS score of 7.8. Microsoft stated that successful exploitation could grant SYSTEM privileges. The flaw was discovered by researchers Luigino Camastra and Milánek from Gen Digital, who reported that it allowed unauthorized access to sensitive system areas. The attacks utilized a rootkit named FudModule, which evades detection, and were delivered through a remote access trojan known as Kaolin RAT. This incident follows a similar vulnerability, CVE-2024-21338, also exploited by the Lazarus Group, which involved the AppLocker driver (appid.sys) and allowed arbitrary code execution.
Winsage
July 3, 2024
Windows 11 has increased its market share to 29.71% as of June 2024, while Windows 10's market share has dropped to 66.04%. Windows 10's support will end in 15 months, leading to unsupported PCs unless users pay for ESU packages. PCs without a TPM 2.0 chip will not qualify for the free upgrade to Windows 11. The notoriety of Windows 11's features, including system-wide ads and the Recall feature, may slow adoption. Some users may be waiting for Windows 12 to launch.
Search