Undetected Android Trojan Expands Attack on Iranian Banks

A campaign targeting major Iranian banks has been discovered, involving an Android mobile banking Trojan that steals login credentials, credit card information, and intercepts SMS for one-time password codes, with new app variants and capabilities being identified.

Design Flaw in Google Workspace Puts Data at Risk

Cybersecurity company Hunters’ Team Axon discovers a vulnerability in Google Workspace and the Google Cloud Platform (GCP) known as “DeleFriend,” allowing threat actors to manipulate existing delegations and potentially exfiltrate sensitive data.