Researchers have demonstrated that open-source Android AI agent frameworks are vulnerable to a novel attack chain where invisible screen text can lead…
An open-source framework for AI agents on Android. Vulnerable to command injection and screenshot tampering attacks as demonstrated in recent research.
An open-source Android AI agent framework with over 25,000 GitHub stars. Vulnerable to multiple attacks including broadcast interception and command injection.
An open-source Android AI agent framework that streams screenshots over exec-out, avoiding file race conditions, but still vulnerable to other attack vectors.
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
COWARDDUCK is a full-featured Android backdoor distributed via messaging apps, disguised as security tools. It exfiltrates contacts, files, and geolocation using Dropbox…
The European Commission has issued binding specification decisions under the Digital Markets Act, ordering Google to grant rival AI assistants the same…