RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

2026-07-07T19:24:10Zb2f3d435acfdf753360f27ec16ce1126b426b764de423d717eeacb39bb44d6a1
android-malwarebank-fraudbeyondtrustdevice-code-flowdialogflow-cxfatfsgiteagithub-agentic-workflowskernel-vulnerabilitykvm-escapemaasmicrosoft-365nation-state-activityphishingroundcubesession-isolationsupply-chaintelegramtendawriter-ai

What happened

A broad set of active threats and high‑severity vulnerabilities was reported, spanning mobile banking malware-as-a-service (RedWing) sold on Telegram, multiple critical product flaws (Google Dialogflow CX code‑block isolation, Writer AI cross‑tenant session isolation), and sophisticated phishing abusing Microsoft device‑code flow to hijack M365 accounts. There are also several high‑impact infrastructure and supply‑chain issues: active exploitation probes against Gitea Docker (CVE-2026-20896), a hidden administrative backdoor in Tenda firmware (CVE-2026-11405), critical BeyondTrust auth‑bypasss

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b2f3d435acfdf753360f27ec16ce1126b426b764de423d717eeacb39bb44d6a1
Enrichment time
2026-07-07T19:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.