user warnings

AppWizard
December 4, 2025
Google has introduced a new system-level metric called “excessive partial wake locks” to identify apps that prevent Android phones from entering sleep mode, which leads to unnecessary battery drain. This metric, co-developed with Samsung, will be integrated into Android's core vitals metrics to help measure app performance and efficiency. Starting March 1, 2026, apps that keep devices awake for more than two hours unnecessarily will face penalties, including reduced visibility in Play Store recommendations and potential user warnings. This initiative aims to improve transparency for users and encourage developers to optimize their apps.
Winsage
October 19, 2025
Microsoft's latest mandatory security update for Windows 11, KB5066835, has caused significant disruptions, including inoperable localhost connections and multiple installation failures. Users are experiencing issues with locally hosted applications, and the update has also affected certain Logitech peripherals and mouse and keyboard functionality in the Windows Recovery Environment (WinRE). Microsoft has acknowledged these problems and plans to release an emergency fix within 48 hours. A regression in the kernel-mode HTTP server (HTTP.sys) is responsible for the localhost connectivity issues, particularly impacting Internet Information Services (IIS). Users are advised against seeking online troubleshooting solutions, as they have proven ineffective, and some have found risky temporary workarounds.
AppWizard
September 24, 2025
A financially motivated cybercrime group has been targeting Android users in Indonesia and Vietnam by deploying banking trojans disguised as legitimate government applications. They spoof Google Play Store and App Store interfaces to deliver malicious APKs through obfuscated WebSocket connections, evading traditional security measures. Analysis of over 100 malicious domains shows they use Alibaba ISP, Gname.com for domain registration, and share-dns.net nameservers, with rapid DNS resolutions occurring within about 10.5 hours during peak daytime hours in Eastern Asia. The group's delivery mechanism utilizes the Socket.IO library for real-time WebSocket connections, allowing them to stream malicious APKs in small chunks. The downloaded file, often named IdentitasKependudukanDigital.apk, installs a variant of the BankBot trojan family. Some simpler spoofed sites offer direct download links with mixed language code strings, indicating the use of multilingual templates. Domain registration data from August 2024 to September 2025 shows these threat actors frequently reuse TLS certificates and cluster spoofed sites on identical IP addresses, primarily hosted via Alibaba and Scloud. These domains share server titles and operate on Nginx, with first-seen DNS queries typically lagging 10.5 hours behind registration times. Infections communicate with command and control domains, highlighting a coordinated infrastructure. The campaign emphasizes the need for behavioral detection and real-time traffic inspection to identify anomalous WebSocket file transfers.
AppWizard
November 25, 2024
Google Play Store is set to introduce warnings for low-quality apps, identified through a teardown of version 43.7.19-31. The warnings will indicate if an app is frequently uninstalled compared to similar apps, has limited user data, or has few active users. These warnings will appear on the app's details page, not as pop-up alerts during download. The feature aims to assist users, particularly those less tech-savvy, in navigating the app selection process. The timeline for the rollout of this feature is currently uncertain.
Search