A new Android malware called Manic is targeting users across multiple European countries and uses a novel data exfiltration method through nearby infected devices.
Manic represents a notable shift in Android malware tactics. Rather than relying solely on direct network connections to exfiltrate stolen data, the malware leverages infected devices in close proximity to relay information.
This mesh-like propagation method makes detection and interception more difficult, as data can hop between devices before reaching external servers. The malware primarily targets European users, though security researchers suggest the technique could be adapted for broader distribution.
The fallback mechanism indicates developers anticipating network restrictions or monitoring on primary exfiltration channels. Victims may not realize their device is part of a data relay network, potentially spreading the malware's reach without their knowledge.
Security firms recommend users in affected regions update Android devices immediately, disable Bluetooth when not in use, and review app permissions carefully. The malware's ability to weaponize device-to-device communication highlights evolving threats to Android security infrastructure.
AliExpress deploys silent WebAudio fingerprinting on its website that interferes with Bluetooth multipoint functionality on user devices. The script runs without explicit user consent.
Citrix has issued an urgent warning for administrators to patch two vulnerabilities affecting NetScaler Gateway and NetScaler ADC appliances. The flaws pose immediate security risks to remote access and networking infrastructure.
The Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies that threat actors are actively exploiting a critical vulnerability in MLflow, an open-source AI engineering platform.
Security defenses effectively block known attack methods but often fail against behavioral variants that achieve the same objectives through different techniques, according to Picus Security's Blue Report 2026.