Friday , July 31 2026
Google

CVE-2026-0073
Google Confirms Critical Android 0-Click Flaw

Google has released the May 2026 Android Security Bulletin, warning everyone about a critical remote code execution (RCE) flaw. Tracked as CVE-2026-0073, this serious flaw is found in the core part of the Android System. It lets a bad actor to get remote shell access without needing the device owner to do anything.

Threat actors can make this zero-click attack from nearby, which means they just need to be on the same local network or close to a weak mobile device.

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

Android Zero-Click Vulnerability

The main issue of CVE-2026-0073 is in the adbd part, which stands for the Android Debug Bridge daemon. Developers usually use this system service to talk to a device, run terminal commands, and change how the system works.

The flaw lets attackers run remote code as a “shell” user, so they can get around normal app security. They do not need special permissions or user action to launch their harmful programs successfully.

Imagine the adbd service as a restricted maintenance door on a secure corporate building.This flaw is like a key that opens things wirelessly, letting a bad person unlock the door and control the building’s systems without the guard seeing it.

The adbd service is part of Project Mainline and is updated through Google Play. This issue affects many recent versions of the operating system.

Android 14, Android 15, Android 16, and Android 16-QPR2 devices are currently at risk.

Google fixed this flaw in the May 1, 2026, security update explained in the Android Security Bulletin May 2026. All Android device makers were told about this issue at least a month early to help them get ready for online firmware updates.

Source code updates are also being added to the Android Open Source Project (AOSP) to keep the platform stable for everyone.

To make sure a device is safe, go to system settings and check if the security patch level is May 1, 2026, or newer. Users should also check for Google Play system updates themselves. Some devices with Android 10 or newer might get special updates this way.

Check Also

SolarWinds

SolarWinds Patches 15 Critical Serv-U Flaws

SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix …