Mobile app permissions (still) matter more than you may think

2026-03-04T20:42:09Z9d12048658d7f74c038607ebcbdeae16eb51d8e4c42ddb80dcf69a8ab37543bc
CVE-2025-50165Android malwareDynoWiperESETLongNosedGoblinMuddyWaterPlushDaemonPromptSpySandwormWindows Imaging Componentcritical infrastructuredeepfake audiogenerative AImobile app permissionsphishingransomwareromance scamscamsspywarethreat intelligencevoice deepfakes

What happened

Collection of ESET WeLiveSecurity articles (late 2025–Feb 2026) covering multiple high-impact threats and consumer/security guidance. Highlights include PromptSpy — the first reported Android malware to incorporate generative AI into its execution; DynoWiper and a Sandworm-attributed data‑destruction incident against Poland’s power grid; a technical revisit of CVE-2025-50165 (Windows Imaging Component); discovery of APT activity (LongNosedGoblin, PlushDaemon, MuddyWater) and a targeted Android spyware campaign using a fake dating app in Pakistan. The feed also contains practical guidance on AI

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
9d12048658d7f74c038607ebcbdeae16eb51d8e4c42ddb80dcf69a8ab37543bc
Enrichment time
2026-03-04T20:42:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.