Android banking Trojan ToxicPanda 2.0 expands from consumer fraud to enterprise risk with 167 remote commands and targeting of 349 finance apps across 16 countries.[4][6][9]
Check Point Research shows Microsoft Defender's BTR.sys boot-time driver can be repurposed to wipe AV and EDR before startup, with no CVE or patch planned.
Microsoft warns that CVE-2026-69836, a CVSS 10.0 remote code execution flaw in Entra ID, has been exploited in the wild but says it is already fully mitigated.
Microsoft's August 2026 Patch Tuesday ships 400+ fixes, including an exploited WinSock zero-day and critical flaws across Windows, Azure and Microsoft 365.
Delta is probing a rogue in-flight Wi-Fi network on a post-DEF CON flight, spotlighting how spoofed hotspots can expose airline passengers to credential theft.