A new Android malware strain named Manic has been identified, exhibiting capabilities of both banking Trojans and spyware. It targets financial institutions, government services, and messaging applications across Ukraine, Russia, and Europe. A unique feature allows infected devices to relay stolen data through other compromised devices via Wi-Fi Direct, Bluetooth, or BLE, even if the initial device lacks internet access.

A newly identified Android malware, dubbed Manic, has been observed exfiltrating sensitive data from compromised devices, even when those devices are offline. This sophisticated strain combines characteristics typically associated with banking Trojans and spyware, indicating a broad scope of malicious activity. The malware has been detected targeting users in Ukraine, Russia, and various European countries.
Manic's primary targets include applications related to financial institutions, government services, and popular messaging platforms. This suggests an intent to harvest a wide array of personal and financial information, as well as potentially intercept communications. The dual nature of the malware, encompassing both financial fraud and espionage capabilities, makes it a significant threat to user privacy and security.
The most notable technical innovation reported for Manic is its ability to bypass traditional network connectivity requirements for data exfiltration. If an infected device lacks internet access, Manic can leverage nearby compromised devices to relay stolen data. This is achieved through short-range wireless communication protocols such as Wi-Fi Direct, Bluetooth, and Bluetooth Low Energy (BLE). This mechanism effectively creates a mesh network of compromised devices, allowing data to hop from an offline device to an online one, and subsequently to the attackers' command-and-control infrastructure.
This capability significantly broadens the attack surface and makes detection and mitigation more challenging. Traditional network-based security monitoring might fail to detect exfiltration from an offline device, as the initial data transfer occurs over local wireless links. Products in this category commonly exploit vulnerabilities in Android's permission model or social engineering tactics to gain necessary access to device data and communication interfaces.
Users can mitigate the risk of such infections by adhering to standard security practices. This includes downloading applications only from trusted sources like the Google Play Store, carefully reviewing requested permissions during app installation, and keeping the Android operating system and all applications updated to their latest versions. Employing reputable mobile security solutions can also provide an additional layer of defense against known malware strains.
The emergence of Manic highlights an evolving trend in mobile malware, where attackers are developing more resilient and stealthy exfiltration methods. The use of short-range wireless protocols for data relay represents a significant advancement in evading detection and ensuring data delivery, even under challenging network conditions. This development underscores the ongoing need for robust mobile security strategies and user vigilance in the face of increasingly sophisticated threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed