SlowMist and OKX security teams discovered that FomoPeek App versions 1.1–1.2 contain malicious code including an iOS kernel exploitation framework capable of escaping sandboxes and accessing private keys and sensitive data. The affected iOS versions range from 12.0–18.7 and 26.0–26.1, with users advised to check accounts, create new wallets, and stop using the app immediately.
Lily is an automated approach that detects code-level backdoors in open-source software by integrating backdoor detection into CI pipelines and release vetting workflows. It uses enhanced fuzzing to identify suspicious behavior triggers and combines code analysis with fuzzing data to pinpoint malicious code regions, achieving high detection accuracy while resisting adversarial evasion attempts.
Google's threat intelligence team infiltrated the hacker group TeamPCP with an undercover analyst from Mandiant, monitoring their supply-chain attacks on hundreds of open-source programs and over 1,000 companies. Two alleged members were arrested in Australia in a joint FBI investigation after Google identified operational security mistakes and shared intelligence with law enforcement. The group deployed malware and a self-spreading worm called Mini Shai-Hulud to compromise developer accounts and breach major targets including OpenAI and Github.
RatHat, a new Android malware linked to Chinese threat actors, uses AI to automate remote device control by serializing the accessibility tree into XML and leveraging an AI assistant for intelligent interface navigation. Distributed via malvertising and phishing, it abuses Accessibility permissions and enables Developer Options to gain shell-level execution, deploying Go-based agents for persistence and credential theft from banking and cryptocurrency apps.
ThinkNode M9 units shipped with infected MicroSD cards containing a worm virus that exploits Windows Autorun features. The virus remains dormant on the card and poses no risk to the device itself, but can infect Windows PCs if activated. Affected customers can replace their device, remove the virus manually, or request a refund.
Researchers present ALIBI, an attack that injects false security narratives into binaries to deceive LLM-based malware analyzers into misclassifying malicious samples as benign. The attack successfully flips verdicts on major models like Gemini and GPT, highlighting the need for provenance verification in LLM malware analysis systems.