RedHook Android malware now uses Wireless ADB for shell access

2026-07-12T19:23:35Ze650b5e96d426a238831183446b44b89d368f2346154e946fc904704713c8a1c
ACSCAI agentsAndroid MalwareCMS exploitationDocker imageGhostcommitGiteaGitea exploitInjectiveProgress SoftwareRedHookRyukShareFileStorage Zone ControllerU-BootWireless ADBXSSZimbraauth bypassfirmware vulnerabilitiesnpmprompt injectionransomwaresupply chainwallet stealer','cryptocurrency theft'

What happened

Multiple high-risk security developments: a new RedHook Android variant now abuses Android Wireless Debugging (Wireless ADB) to achieve shell-level access without a computer; the Australian Cyber Security Centre warns of a global campaign exploiting vulnerable CMS platforms and plugins; researchers disclosed 'Ghostcommit'—a prompt-injection technique hidden in PNGs that can trick AI code reviewers/agents into exfiltrating repo secrets; six U-Boot bootloader vulnerabilities could enable stealthy firmware compromise and persistent malware; active exploitation of a critical authentication-bypass/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
e650b5e96d426a238831183446b44b89d368f2346154e946fc904704713c8a1c
Enrichment time
2026-07-12T19:23:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · RedHook Android malware now uses Wireless ADB for shell access · Baitaphish