With the new Advanced Flow for sideloading being rolled out, it's time to discuss what sideloading is and how to do it more safely.

Google has begun rolling out an "Advanced Flow" feature designed to enhance the safety of installing Android applications from developers who have not completed the platform's identity verification process. This new security measure aims to mitigate risks associated with "sideloading," the practice of installing apps from sources other than the Google Play Store.
Sideloading allows Android users to install applications from various sources, including a developer's website, alternative app marketplaces, enterprise portals, or directly shared files. This flexibility is a core strength of Android, enabling access to apps unavailable in certain regions, open-source software, beta versions, or specialized enterprise tools. However, it also introduces significant security risks, as these apps bypass some of the vetting and safeguards present in official app stores.
While the Google Play Store employs review processes, policy enforcement, developer controls, and Google Play Protect to reduce risks, it is not entirely immune to threats. Google reported blocking over 1.75 million policy-violating apps and banning more than 80,000 developer accounts in 2023. Despite these efforts, malicious apps can still appear, including Trojans disguised as utilities or games, adware, subscription traps, data-harvesting apps, and "sleeper apps" that change behavior after initial review. Google Play Protect scans both Play Store apps and sideloaded applications, but it serves as one layer of defense, not a complete solution.
The primary difference between installing from a recognized store and sideloading an APK lies in the chain of trust. When sideloading, users may have fewer assurances regarding the app's creator, whether the file has been tampered with, the legitimacy of the download site, the authenticity of future updates, and whether they are being manipulated by scammers. Social engineering is a significant factor, with attackers often impersonating banks, delivery services, government agencies, or recruiters to pressure victims into installing malicious apps or disabling security features. Legitimate organizations should not instruct users to install APKs or weaken Android security settings via unexpected calls or messages.
To sideload more safely, users are advised to proceed only when they have a specific, self-initiated reason. It is crucial to download apps directly from the developer's official website, avoiding sponsored search results, random download portals, links from strangers, or lookalike domains. Independent verification of the developer through their official website, documentation, public code repositories, and trusted community channels is recommended. Preferring established third-party repositories with strong reputations for provenance and signature verification is also beneficial. Advanced users can compare an APK's signing certificate or cryptographic hash against values published by the developer to detect fakes.
Crucially, users should never install apps under pressure. Any urgent, secretive, or financially incentivized request to install an app, especially from a claimed bank, government, or employer, should be treated as suspicious. Maintaining Google Play Protect as enabled is important, as it scans apps during and after installation. Users should also carefully review app permissions both before and after installation, exercising caution if an app requests excessive access to sensitive features like accessibility services, SMS messages, notifications, device administration, contacts, or screen recording. Keeping Android and all applications updated with the latest security fixes and using reputable mobile security software can provide additional protection. Regularly removing permissions and uninstalling unused or untrusted apps is also a good practice.
Google's new Advanced Flow specifically targets social engineering tactics. Instead of a simple one-tap override, it requires users to enable developer mode in system settings, complete a quick safety check to ensure they are not being coerced, and restart their device to disrupt any active remote access or phone calls from scammers. A key component is a one-day delay, after which users must confirm the change using biometrics or their device PIN. This delay is designed to break the urgency relied upon by scammers, providing time for reflection. Once the process is completed, users can choose to allow installs from unverified developers for seven days or indefinitely.
While developer verification establishes accountability by linking an app to a verified identity, it does not guarantee an app's benign nature or suitability for all users. The ultimate responsibility lies with the user to scrutinize app sources, understand requested permissions, and refuse installation if rushed or pressured by an external party, regardless of whether the app originates from the Google Play Store or an external source.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed