Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools

2026-07-08T14:51:49Z1b00c3d63f128bcee30f8ca746e64fa4897f3ddd577f4d763b11a06322224c8e
AI-generated malwareAdobe ColdFusionAndroid spywareAnthropic MythosArmored LikhoCISAGiteaJanuscapeKVMKnown Exploited VulnerabilitiesRedWingTelegramTendaactive exploitationbusySnakemalware-as-a-serviceprompt injection

What happened

This feed reports multiple high-impact security events: a Telegram-hosted Android spyware service called RedWing (Oblivion-related) is being sold as a subscription; CISA added multiple flaws to its Known Exploited Vulnerabilities catalog and is using Anthropic’s Mythos AI to scan federal code; attackers are actively exploiting a critical Gitea Docker authentication-bypass (CVE-2026-20896) and a critical Adobe ColdFusion RCE (CVE-2026-48282); CERT/CC disclosed an unpatched Tenda router backdoor (CVE-2026-11405) granting admin access; a 16-year-old Linux KVM use-after-free (“Januscape”) enables·

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
1b00c3d63f128bcee30f8ca746e64fa4897f3ddd577f4d763b11a06322224c8e
Enrichment time
2026-07-08T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.