Ein Konfigurationsfehler legt die komplette .de-Zone lahm. Drei Linux-Kernel-Exploits zielen auf dasselbe Angriffsmuster. Und Daniel Stenberg beschreibt, wie KI-generierte Bug-Reports curl gleichzeitig besser und anstrengender machen.
 
Unser aktueller Security Digest ordnet ein, was die letzten Wochen wirklich relevant war:
🔐 Copy Fail, Dirty Frag, Dirty Pipe: Local Privilege Escalation bleibt eine der häufigsten Schwachstellenklassen im Linux-Kernel. Unser Take: SELinux ist kein Nice-to-have, sondern die wirksamste Gegenmaßnahme. Nicht-privilegierte Accounts sollten nicht unter unconfined_u laufen. Punkt.
🌐 DNSSEC-Ausfall der .de-Zone: Ein Signierfehler bei der DENIC hat am 05.05. gezeigt, wie fragil zentralisierte DNS-Infrastruktur sein kann.
🤖 KI und Open Source: curl erlebt nach der AI-Slop-Welle jetzt hochwertige Meldungen. Gleichzeitig steigt die Last für Maintainerinnen und Maintainer massiv.
📱 Android Intrusion Logging: Google liefert mit dem Advanced Protection Mode endlich eine echte Datenquelle für mobile Forensik. Wir empfehlen die Aktivierung für exponierte Personen und Organisationen mit erhöhtem Schutzbedarf.
 
Das Security-Modell aus dem Mobilbereich wird zunehmend zum Vorbild für Desktop und Server. Wer heute noch ohne Mandatory Access Control arbeitet, liefert eine Angriffsfläche, die sich mit wenigen Konfigurationsschritten deutlich reduzieren ließe. Den vollständigen Digest mit allen Quellen und unserer Einordnung finden Sie hier: https://research.hisolutions.com/2026/05/
 
Wie gehen Sie in Ihrer Organisation mit SELinux um? Und nutzt jemand von Ihnen bereits Android Intrusion Logging in der Vorfallsbehandlung?
 
#Cybersecurity #SELinux #DNSSEC #AndroidSecurity #OpenSource @brahms @jrt

Google Bolsters Android Security to Counter Spyware Vendors

Google's new Intrusion Logging feature is a game-changer in the fight against spyware, helping digital forensics researchers uncover sophisticated attacks on Android devices. By recording security incidents like device unlocking and spyware installation, it provides crucial evidence to investigate and take down these threats.

https://osintsights.com/google-bolsters-android-security-to-counter-spyware-vendors?utm_source=mastodon&utm_medium=social

#AndroidSecurity #Spyware #IntrusionLogging #DigitalForensics #AdvancedProtectionMode

Google Bolsters Android Security to Counter Spyware Vendors

Learn how Google's new Intrusion Logging feature enhances Android security against spyware vendors and supports digital forensics - read the full details now.

OSINTSights

TCLBanker is targeting Android users with banking trojan capabilities - stealing credentials, intercepting messages, and abusing trust at scale. Mobile is still prime territory. 📱💸 #BankingTrojan #AndroidSecurity

https://thehackernews.com/2026/05/tclbanker-banking-trojan-targets.html

TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms

TCLBANKER targets 59 financial platforms using WhatsApp worms and Outlook phishing, increasing banking credential theft risks. (

The Hacker News

🎯 Google mette in palio $1,5 Milioni per bucare Android! Prova a superare la sfida. #HackerChallenge #AndroidSecurity ⚔️💰

🔗 https://www.tomshw.it/smartphone/google-android-premi-exploit

Google paga 1,5 milioni per bucare Android

Google alza i premi per gli exploit Android più difficili: fino a 1,5 milioni di dollari per catene zero-click sui Pixel.

Tom's Hardware

Last seats for our #TyphoonCon 2026 training in Seoul! 🇰🇷

𝗗𝗲𝗲𝗽 𝗗𝗶𝘃𝗲 𝗶𝗻𝘁𝗼 𝗔𝗻𝗱𝗿𝗼𝗶𝗱 𝗕𝗶𝗻𝗱𝗲𝗿
🗓️ May 27 - 29
Register for this training and get a FREE main conference pass! Reply to claim.

🔗 http://www.eventbrite.com/e/1968561639857/?discount=eShard_sponsors
#reverseengineering #AndroidSecurity #cybersecurity

TyphoonCon 2026

TyphoonCon is an all Offensive Security Training & Conference focused on offensive security, vulnerability discovery and reverse engineering

Eventbrite

GrapheneOS Prioritizes Security Over Speed in Latest Release

GrapheneOS 2026042100 fixes a webcam crash, updates system components, and reinforces its philosophy: stronger data protection in memory, even if it costs some speed.

https://yoota.it/en/grapheneos-prioritizes-security-over-speed-in-latest-release/

Concluding the session was Khatun et al.'s "AndroByte: LLM-Driven Privacy Analysis through Bytecode Summarization and Dynamic Dataflow Call Graph Generation," an AI-driven approach to explainable Android privacy leak detection. (https://www.acsac.org/2025/program/final/s435.html) 6/6
#AndroidSecurity
Next in the session was Moghimi et al.'s "DROIDCCT: Cryptographic Compliance Test via Trillion-Scale Measurement" revealing cryptographic flaws at massive Android scale. (https://www.acsac.org/2025/program/final/s267.html) 4/6
#AndroidSecurity #SideChannel

Google Fortifies Ad Ecosystem, Cracks Down on 8.3B Policy-Violating Ads

Google is taking a giant leap in protecting user privacy and cracking down on fraud, having blocked over 8.3 billion ads and suspended 24.9 million accounts in a single year. This bold move is part of a broader effort to reshape how apps handle sensitive data, with a focus on transparency and security.

https://osintsights.com/google-fortifies-ad-ecosystem-cracks-down-on-83b-policy-violating-ads?utm_source=mastodon&utm_medium=social

#AdEcosystem #OnlineAdvertising #PolicyEnforcement #PrivacyUpdates #AndroidSecurity

Google Fortifies Ad Ecosystem, Cracks Down on 8.3B Policy-Violating Ads

Discover how Google cracked down on 8.3B policy-violating ads and strengthened user privacy with new Play policy updates and Android 17 changes - learn more now.

OSINTSights

Mirax Android RAT:
• 220K users via Meta ads
• Full RAT + SOCKS5 proxy
• Residential IP abuse
• Multi-stage evasion
Devices now double as infra.

💬 Detection strategies?

Source: https://thehackernews.com/2026/04/mirax-android-rat-turns-devices-into.html

🔁 Share
🔔 Follow @technadu

#Infosec #AndroidSecurity #ThreatIntel