Thursday , July 30 2026
ZeroDayRAT

New ‘ZeroDayRAT’ Spyware Kit Allows Full Compromise of iOS and Android Devices

ZeroDayRAT is a new mobile spyware toolkit that allows remote access to Android and iOS devices, offering features like live camera feeds, keylogging, and theft of bank and crypto information.

It is currently available via Telegram, and was first observed on February 2, 2026, and since analyzed by iVerify. It is “a complete mobile compromise toolkit” comparable to kits normally requniring nation-state resources to develop.

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

A new study from Beacom College shows that all automation scripts produced by top AI models like ChatGPT, Microsoft Copilot,...
Read More
Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

Infection requires delivery of a malicious binary. “These kits typically give the buyer a self-hosted panel and a builder,” explains Daniel Kelley, research fellow at iVerify. “The operator sets up their own server, configures the panel, then uses the builder to generate payloads that phone home to their infrastructure.”

From there, he continues, “Distribution is on the attacker: phishing links, smishing, trojanized apps on third-party stores, social engineering… whatever works. There’s an ‘exploit’ tab in the sidebar, so it’s possible it comes with some kind of exploit capability, but we can’t confirm it.”

Location tracking is provided. GPS coordinates are obtained and shown on an embedded Google Map, displaying the victim’s current and past locations.

App usage details include names and types of interactions: WhatsApp messages, Instagram notifications, missed calls, Telegram updates, YouTube alerts, and system events. It also reveals registered accounts with usernames and emails from Google, WhatsApp, Instagram, Facebook, Telegram, Amazon, and others, creating a prime target for social engineering.

The kit allows passive data collection from a victim’s device, but it also offers live surveillance features like camera streaming, screen recording, and audio feed. With GPS tracking, an operator can monitor, listen to, and track a target at the same time, according to iVerify.

iVerify warns that ZeroDayRAT is a persistent issue. It’s nearly impossible to identify and arrest the creator. The toolkit is marketed in Portuguese, Russian, Chinese, Spanish, and English.

“We’ve seen them post messages in Chinese, use a Russian domain, and target Indian victims,” says Kelley. “None of it lines up, and that looks intentional. We think they’re actively using disinformation to muddy attribution.”

Similarly, there is no central server for authorities to locate and take down. “Every operator runs their own instance, so you’re playing whack-a-mole against individual infrastructures. The Telegram sales channel is the most visible chokepoint, but Telegram takedowns are slow, and even if it happens the developers just spin up a new channel.”

Check Also

CVE-2026-20230

Cisco Unified CM flaw CVE-2026-20230 exploited in attacks

A serious SSRF flaw, called CVE-2026-20230, in Cisco Unified Communications Manager Server is now being …