A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]

A new Android malware, dubbed Manic, has been identified with a unique data exfiltration method that utilizes nearby infected devices when a direct connection to its command-and-control (C2) server is unavailable. This sophisticated malware has been active since at least February and combines capabilities for spyware, banking fraud, and remote control.
Manic primarily targets users in Ukraine, but its reach extends to other European countries, including the U.K., and Russia. It is designed to compromise at least 169 different applications, encompassing banking, government/eID, payment, cryptocurrency wallet, messaging, and two-factor authentication (2FA) services.
Upon gaining Android Accessibility and notification access permissions, Manic can capture a victim's lock PIN or password, intercept SMS messages and notifications, collect location data and files, and monitor the device screen. It also allows remote operators to control the compromised device via WebRTC sessions. The malware categorizes the stolen information, distinguishing between lock-screen input, recovery phrases, four-to-six-digit SMS codes, passwords, email logins, long messages, and general text, making the data more readily exploitable.
A key feature of Manic is its use of transparent overlays on legitimate application keypads to capture user taps. This method allows the malware to reproduce these taps through Android Accessibility, ensuring the legitimate applications continue to function normally while user input is recorded.
The most notable aspect of Manic is its fallback data exfiltration mechanism. If a compromised device cannot establish a connection with its C2 server, the malware encrypts the collected data and attempts to transfer it via nearby infected devices using Wi-Fi Direct or Bluetooth. The malware first tries to use an existing Wi-Fi Direct peer, then queries Bluetooth and Bluetooth Low Energy (BLE) peers to check for internet connectivity. It can also establish multi-hop routes, with new data items configured to traverse a maximum of four relay hops by default. This enables data exfiltration even from offline devices, provided another infected device is within Wi-Fi or Bluetooth range.
The exact initial infection vector for Manic remains unconfirmed. However, researchers observed in late May the use of a wrapper to deliver the main payload, followed by an expansion of the malware's infrastructure. By July, an updated wrapper with enhanced anti-analysis checks and in-memory DEX loading was noted in attacks, alongside the deployment of a new panel and API.
Android users are advised to exercise caution by avoiding the download of APKs from unofficial or obscure sources. They should also be wary of granting Accessibility permissions unless absolutely necessary for a trusted application and regularly utilize Play Protect scans to detect and remove known malware.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a