A new Android spyware operation called RedWing, linked to Russian threat actors, is being offered as a subscription service on Telegram. This Malware-as-a-Service (MaaS) product requires no coding skills and allows attackers to rent tools for stealing credentials, intercepting SMS messages, recording audio and video, and even launching DDoS attacks. RedWing relies on social engineering and user-granted permissions rather than exploiting device vulnerabilities.

Researchers have discovered RedWing, an Android spyware operation being sold as a subscription service via Telegram, with suspected ties to Russian threat actors. This sophisticated Malware-as-a-Service (MaaS) product lowers the barrier to entry for novice attackers, providing documentation, tutorial videos, and a bot that customizes and builds malicious applications on demand. The entire process, from app customization to building, can be managed through Telegram.
Infection typically begins with a phishing link that directs users to a fake app store page, designed to mimic legitimate stores like Google Play, Samsung Galaxy Store, or Huawei's AppGallery, complete with fake ratings and reviews. Once installed, the malware guides the user through a series of permission requests, including disabling battery optimization for persistent background operation, setting itself as the default SMS handler to intercept two-factor authentication codes, and gaining access to notifications.
With these permissions, RedWing gains extensive control over the device. It can display fake login screens over legitimate banking and cryptocurrency applications to steal credentials. Furthermore, it leverages Android's Accessibility Service to capture PINs, card numbers, and CVV values directly from the screen as they appear. The malware can also silently enable call forwarding using a hidden carrier code, redirecting all incoming calls to an attacker-controlled number, thereby disabling phone-based two-factor authentication and fraud prevention calls.
The spyware's surveillance capabilities extend to remotely activating the device's camera and microphone. Attackers can send commands to capture images or record ambient audio for configurable durations, managed entirely from the remote server. Additional features include live screen streaming via VNC, a real-time keylogger, access to all files on the device, contact lists, call logs, and location tracking.
RedWing's architecture suggests that specific target lists for overlays can be updated remotely, while the applications it monitors through Accessibility are compiled into each custom APK. Researchers identified 82 targeted institutions, with a notable focus on Russian financial firms. The operation does not exploit any Android vulnerabilities, relying instead on users installing apps from unofficial sources and granting excessive permissions.
Beyond espionage and data theft, RedWing can transform compromised Android devices into a botnet capable of launching coordinated Distributed Denial of Service (DDoS) attacks. Attackers can command multiple infected phones simultaneously to flood target websites or servers with traffic, disrupting their availability.
Given that operators can easily reskin the app and change its targets, focusing on the app's name is less effective than observing its behavior. The rise of MaaS operations like RedWing highlights the ease with which attackers can weaponize legitimate Android components for full device compromise through social engineering and the abuse of critical system permissions.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed