Mobile app permissions (still) matter more than you may think
2026-03-04T20:42:09Z•9d12048658d7f74c038607ebcbdeae16eb51d8e4c42ddb80dcf69a8ab37543bc
CVE-2025-50165Android malwareDynoWiperESETLongNosedGoblinMuddyWaterPlushDaemonPromptSpySandwormWindows Imaging Componentcritical infrastructuredeepfake audiogenerative AImobile app permissionsphishingransomwareromance scamscamsspywarethreat intelligencevoice deepfakes
What happened
Collection of ESET WeLiveSecurity articles (late 2025–Feb 2026) covering multiple high-impact threats and consumer/security guidance. Highlights include PromptSpy — the first reported Android malware to incorporate generative AI into its execution; DynoWiper and a Sandworm-attributed data‑destruction incident against Poland’s power grid; a technical revisit of CVE-2025-50165 (Windows Imaging Component); discovery of APT activity (LongNosedGoblin, PlushDaemon, MuddyWater) and a targeted Android spyware campaign using a fake dating app in Pakistan. The feed also contains practical guidance on AI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 9d12048658d7f74c038607ebcbdeae16eb51d8e4c42ddb80dcf69a8ab37543bc
- Enrichment time
- 2026-03-04T20:42:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.