RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
2026-07-07T19:24:10Z•b2f3d435acfdf753360f27ec16ce1126b426b764de423d717eeacb39bb44d6a1
android-malwarebank-fraudbeyondtrustdevice-code-flowdialogflow-cxfatfsgiteagithub-agentic-workflowskernel-vulnerabilitykvm-escapemaasmicrosoft-365nation-state-activityphishingroundcubesession-isolationsupply-chaintelegramtendawriter-ai
What happened
A broad set of active threats and high‑severity vulnerabilities was reported, spanning mobile banking malware-as-a-service (RedWing) sold on Telegram, multiple critical product flaws (Google Dialogflow CX code‑block isolation, Writer AI cross‑tenant session isolation), and sophisticated phishing abusing Microsoft device‑code flow to hijack M365 accounts. There are also several high‑impact infrastructure and supply‑chain issues: active exploitation probes against Gitea Docker (CVE-2026-20896), a hidden administrative backdoor in Tenda firmware (CVE-2026-11405), critical BeyondTrust auth‑bypasss
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b2f3d435acfdf753360f27ec16ce1126b426b764de423d717eeacb39bb44d6a1
- Enrichment time
- 2026-07-07T19:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.