Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools
2026-07-08T14:51:49Z•1b00c3d63f128bcee30f8ca746e64fa4897f3ddd577f4d763b11a06322224c8e
AI-generated malwareAdobe ColdFusionAndroid spywareAnthropic MythosArmored LikhoCISAGiteaJanuscapeKVMKnown Exploited VulnerabilitiesRedWingTelegramTendaactive exploitationbusySnakemalware-as-a-serviceprompt injection
What happened
This feed reports multiple high-impact security events: a Telegram-hosted Android spyware service called RedWing (Oblivion-related) is being sold as a subscription; CISA added multiple flaws to its Known Exploited Vulnerabilities catalog and is using Anthropic’s Mythos AI to scan federal code; attackers are actively exploiting a critical Gitea Docker authentication-bypass (CVE-2026-20896) and a critical Adobe ColdFusion RCE (CVE-2026-48282); CERT/CC disclosed an unpatched Tenda router backdoor (CVE-2026-11405) granting admin access; a 16-year-old Linux KVM use-after-free (“Januscape”) enables·
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 1b00c3d63f128bcee30f8ca746e64fa4897f3ddd577f4d763b11a06322224c8e
- Enrichment time
- 2026-07-08T14:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.