A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]

A new Android malware combination, featuring the WindRelay NFC relay tool and the SpyNote remote administration tool (RAT), has been observed by cybersecurity firm Group-IB in attacks designed to steal credit card data and facilitate fraudulent loans. This sophisticated toolkit allows attackers to gain remote control over a victim's device and relay live NFC payment card exchanges, including transaction-specific authentication data.
In a specific incident investigated by Group-IB, a fraudster impersonated a bank employee and contacted a victim, claiming there was an issue with their payment card. During the call, the attacker instructed the victim to sideload a malicious SpyNote RAT application, disguised as a legitimate bank app and personalized with the victim's name. The victim was then prompted to grant Accessibility Service permissions, which provided the attacker with remote access to the Android device.
Once SpyNote was installed and access was established, the attacker remotely installed WindRelay without further interaction from the victim. The attacker then used the victim's banking app to take out a loan in their name. Additionally, the victim was instructed to tap their payment card against the phone and enter their PIN. WindRelay transformed the phone into a fraudulent contactless reader, relaying the live NFC exchange, including the card's transaction-specific authentication data, to the attacker's device. This enabled the attacker to use the stolen card data for purchases at a genuine payment terminal. Group-IB reported that the entire fraudulent activity, including the loan and card transactions, occurred within a 13-minute phone call, with transactions approved using the PIN provided by the victim.
The researchers note that this combination of SpyNote and WindRelay suggests a comprehensive toolkit for attackers, providing both remote access for banking transactions and a direct channel for cashing out. Unlike many modern Android malware strains that rely on live screen sharing or VNC features, this particular attack chain achieved its objectives primarily through social engineering conducted over the phone.
Android NFC malware is an increasing concern, with other families like NFCShare, NGate, SuperCard X, and RelayNFC demonstrating similar capabilities. Typically, these attacks involve the victim installing a malicious app and granting it NFC access. Attackers then socially engineer victims into tapping their payment cards against the compromised phone, which captures and transmits the card data to an attacker-controlled device for fraudulent use or financial theft.
The SpyNote RAT and its variants, such as SpyMax and CypherRAT, have been active since at least 2021. Detections of these RATs saw a notable increase in late 2022 and early 2023, following the public leak of the malware's source code. SpyNote is capable of stealing banking information, Facebook and Google account credentials, Google Authenticator codes, GPS tracking data, and SMS messages. It can also activate the device microphone and camera, and intercept keystrokes.
Group-IB has identified nearly two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026. These samples communicated with four distinct command-and-control IP addresses. Based on the organizations impersonated and the languages used in the attacks, targeting appears to be concentrated in Czechia, Slovakia, and Slovenia.
To mitigate such threats, Android users are strongly advised to avoid installing APK packages from sources other than Google Play, unless they have complete trust in the publisher. Extreme caution should be exercised with any app that requests NFC access or other potentially dangerous permissions. If contacted by a bank and asked to take urgent action, it is recommended to end the call, dial the official number listed on the bank's website, and request to speak with the same support agent.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed