RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

2026-09-18T07:24:01Z•ba9e117210975dc2b161d17d49e020f730ae1ec80888630f4fcbb9deb2b5dd0f
CVE-2026-5430CVE-2026-58704CVE-2026-76460CVE-2026-77179CVE-2026-81642CVE-2026-87886CVE-2026-89026active-exploitationadb-persistenceai-securityandroidauthentication-bypasscloud-securitydata-breachddosdns-securitymacosmalwarephishingprivilege-escalationremote-code-executionstate-sponsored-threatssupply-chain-compromiseunauthenticated-accesswordpresszero-day

What happened

The feed reports multiple critical, actively exploited vulnerabilities and major cyber threats, including unauthenticated remote code execution in Check Point, Unbound, Issabel, WooCommerce, and WSO2 products; a maximum-severity Cisco ISE authentication bypass exploited in the wild; Android malware using ADB persistence; targeted state-linked backdoors; AI assistant and coding-session compromise; phishing, data breaches, DDoS services, and privilege-escalation flaws. Immediate patching and incident review are warranted for affected products, especially vulnerabilities with confirmed active or.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ba9e117210975dc2b161d17d49e020f730ae1ec80888630f4fcbb9deb2b5dd0f
Enrichment time
2026-09-18T07:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.