Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

2026-08-20T20:51:39Z0b5396ea6a802229c95e4924183f70383d92aba7779fa47244e8151709850fb8
CVE-2026-33824CVE-2026-64849active-exploitationai-assisted-attacksandroid-malwareapi-key-exposurebanking-trojanbluetooth-exfiltrationcisa-kevcredential-theftcritical-infrastructuredahua-camerasdata-breachicsinfostealeriotiranian-cyber-espionagemacsync-stealermalware-deliverymanic-malwaremlflowscadasiemens-s7spywaressrfstripewordpress-compromise

What happened

Security Affairs RSS feed covering major cybersecurity developments, including the Manic Android malware, active attacks against Siemens S7 PLCs, CISA KEV additions, Iranian cyber-espionage indictments, large-scale WordPress and Dahua camera compromises, MacSync Stealer activity, exposed Stripe secrets, and a breach affecting 1.2 million Heights Finance customers. The feed includes one explicitly identified critical, actively exploited MLflow SSRF vulnerability, CVE-2026-64849, plus additional CISA-listed vulnerabilities referenced without complete CVE details.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0b5396ea6a802229c95e4924183f70383d92aba7779fa47244e8151709850fb8
Enrichment time
2026-08-20T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.