Monthly Archive: September 2025

Google Shifts Android Security Updates to a Risk-Based System

Google has altered its approach to Android security updates, breaking with a decade-long tradition of monthly vulnerability disclosures. In the July 2025 bulletin, the company reported no vulnerabilities whatsoever—a first in 120 publications. Yet...

The SlopAds Operation: A New Level of Ad Fraud

A sprawling advertising-fraud operation known as SlopAds hid behind a storefront of hundreds of seemingly innocuous Android apps and ballooned into a global enterprise. Researchers at Satori (HUMAN) recently described how 224 programs amassed...

New FileFix Attack: Hiding Malware in Plain Sight

Acronis researchers have reported a fresh campaign that employs a modified FileFix technique to deliver the StealC data stealer. The attackers staged a convincing, multilingual phishing operation that forges pages for various services —...

Poisoned Packages: A New Attack Hits the npm Ecosystem

Researchers at Socket have disclosed a new attack against the npm ecosystem, in which more than 40 packages were discovered to be laced with embedded malicious code. The compromise mechanism was meticulously engineered: it...