ESET researchers uncovered PromptSpy, the first known Android malware to integrate generative AI into its execution flow. By prompting Google’s Gemini to guide malicious UI interactions, the malware achieves persistence and can capture lockscreen data, block uninstalls, gather device info, take screenshots, and record screen activity. The finding marks a new milestone in mobile threat tradecraft, where AI is used operationally rather than just for payload generation.
Source: ESET Blog
Ivanti exploitation surges; zero-day activity traced back to July 2025
Security researchers report a sharp rise in exploitation of Ivanti flaws, with evidence that zero-day activity dates to July 2025. Attackers have been using the bugs to deliver shells, conduct reconnaissance, and download malware—underscoring the need for thorough log review and post-patch compromise checks in environments that exposed affected devices.
Source: SecurityWeek
Critical Grandstream VoIP flaw enables RCE and call interception (CVE-2026-2329)
A critical vulnerability in Grandstream VoIP phone web APIs allows remote attackers to take full control of devices and intercept calls. Rapid7 attributes the bug to improper bounds checking in a default-accessible management endpoint, creating a stealthy foothold risk on corporate networks that rely on these phones.
Source: Help Net Security
Microsoft discloses Windows Admin Center privilege escalation (CVE-2026-26119)
Microsoft has publicly acknowledged a high-severity privilege-escalation flaw in Windows Admin Center, widely used to manage Windows servers, clusters, and AD-joined systems. Though patched in December 2025 (WAC v2511), the late disclosure signals long-tail risk for unpatched deployments and emphasizes updating management planes as a priority.
Source: Help Net Security
France’s national bank account registry breached; 1.2M accounts exposed
France’s Ministry of Economy confirmed unauthorized access to the FICOBA registry, exposing data related to approximately 1.2 million bank accounts. Attackers reportedly used stolen credentials belonging to an authorized civil servant to browse the database, accessing account details and associated personal information.
Source: SecurityWeek
FBI warns of ATM jackpotting spike: $20M lost in 2025
The FBI says more than 700 ATM jackpotting incidents occurred last year, causing over $20 million in losses, and confirms the decade-old Ploutus malware remains active in the wild. Since 2020, at least 1,900 such incidents have been recorded, highlighting the need for aggressive physical and logical controls across ATM fleets.
Source: SecurityWeek
Malvertising on Facebook pushes fake Windows 11 downloads to steal creds and crypto
Malwarebytes warns that adversaries are weaponizing Facebook ads to distribute password-stealing malware disguised as Windows 11 downloads. The campaigns target both consumer and enterprise users, aiming to siphon credentials and cryptocurrency wallets via convincing lures that bypass casual scrutiny.
Source: Malwarebytes Blog
You May Also Be Interested In...
CISA alerts to critical auth bypass in Honeywell CCTVs (CVE-2026-1670)
German Rail Giant Deutsche Bahn hit by large-scale DDoS attack
Windows Notepad RCE via malicious Markdown links (CVE-2026-20841)