<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Mobile</title><description>Mobile-platform vulnerabilities and the spyware ecosystem that exploits them — from Pegasus-class commercial surveillance tooling to opportunistic Android malware. Covers OS-level flaws in iOS and Android and the mobile-specific attack surface: baseband, MDM, and sideload channels. Combined article + CVE feed for the Mobile beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active</title><link>https://0daynews.com/articles/2026-08-23-banking-trojans-manic-grandoreiro-toxicpanda/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-23-banking-trojans-manic-grandoreiro-toxicpanda/</guid><description>Three banking trojans are active: spyware-equipped Manic, persistent Grandoreiro across Latin America and Europe, and an expanded ToxicPanda 2.0.</description><pubDate>Sun, 23 Aug 2026 04:00:00 GMT</pubDate><category>Mobile</category><category>article</category></item><item><title>Android Malware Relays NFC Cards, Takes Out Loans</title><link>https://0daynews.com/articles/2026-08-13-android-windrelay-spynote-nfc-relay-fraud/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-android-windrelay-spynote-nfc-relay-fraud/</guid><description>WindRelay, a new Android NFC relay malware, is deployed alongside SpyNote RAT to steal live card data and take out fraudulent loans in victims&apos; names.</description><pubDate>Thu, 13 Aug 2026 04:30:00 GMT</pubDate><category>Mobile</category><category>article</category></item><item><title>Flying Eagle Android RAT Source Code Leaks to Telegram</title><link>https://0daynews.com/articles/2026-07-29-flying-eagle-android-rat-telegram-leak/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-flying-eagle-android-rat-telegram-leak/</guid><description>Flying Eagle Android RAT source code is circulating on Telegram. Hunt.io traced 170 C2 servers. Block sideloading and audit your MDM policy.</description><pubDate>Wed, 29 Jul 2026 09:00:00 GMT</pubDate><category>Mobile</category><category>article</category></item><item><title>Android AI agent frameworks: overlay text pivots to host</title><link>https://0daynews.com/articles/2026-07-21-zhang-arxiv-android-mobile-agent-frameworks-overlay-adb-pivot/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-zhang-arxiv-android-mobile-agent-frameworks-overlay-adb-pivot/</guid><description>Zhang et al. published seven attacks against five open-source Android agent frameworks. 2% opacity overlay text feeds prompts to the vision model; unsanitized ADB commands pivot to the host PC.</description><pubDate>Tue, 21 Jul 2026 14:20:00 GMT</pubDate><category>Mobile</category><category>article</category></item><item><title>RedHook Android RAT pairs Wireless ADB on-device</title><link>https://0daynews.com/articles/2026-07-12-redhook-group-ib-wireless-adb-loopback-shizuku-uid-2000/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-12-redhook-group-ib-wireless-adb-loopback-shizuku-uid-2000/</guid><description>Group-IB details RedHook using Accessibility to enable Wireless Debugging, pair over loopback, and run shell as uid 2000. No CVE. Southeast Asia targeted.</description><pubDate>Sun, 12 Jul 2026 15:00:00 GMT</pubDate><category>Mobile</category><category>article</category></item><item><title>281 free Android VPN apps: 29 leak, 246 track</title><link>https://0daynews.com/articles/2026-07-11-mvpnalyzer-281-android-vpn-study-leaks-tracking/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-mvpnalyzer-281-android-vpn-study-leaks-tracking/</guid><description>MVPNalyzer, a University of Michigan / UNM / IIT Delhi tool presented at NDSS 2026, ran 281 top free Android VPN apps and found leaks, plaintext, and trackers.</description><pubDate>Sat, 11 Jul 2026 19:00:00 GMT</pubDate><category>Mobile</category><category>article</category></item><item><title>281 free Android VPNs, and a familiar audit outcome</title><link>https://0daynews.com/articles/2026-07-10-android-free-vpn-study-familiar-audit-outcome/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-android-free-vpn-study-familiar-audit-outcome/</guid><description>A new study of 281 popular free Android VPN apps found traffic leaks, missing encryption, and tracking. The category has kept failing this test for years.</description><pubDate>Fri, 10 Jul 2026 13:15:00 GMT</pubDate><category>Mobile</category><category>article</category></item><item><title>RedWing turns Android bank fraud into a Telegram rental</title><link>https://0daynews.com/articles/2026-07-08-redwing-android-maas-oblivion-telegram-zimperium/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-redwing-android-maas-oblivion-telegram-zimperium/</guid><description>Zimperium&apos;s zLabs details RedWing, an Android bank-fraud MaaS sold on Telegram — Oblivion variant, subscription tiers, prebuilt droppers, 82 target banks.</description><pubDate>Thu, 09 Jul 2026 02:00:00 GMT</pubDate><category>Mobile</category><category>article</category></item><item><title>Pegasus on the MEP investigating Pegasus</title><link>https://0daynews.com/articles/2026-07-03-pegasus-mep-kouloglou-citizen-lab-analysis/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-pegasus-mep-kouloglou-citizen-lab-analysis/</guid><description>Citizen Lab&apos;s forensic analysis found that former European Parliament member Stelios Kouloglou was repeatedly infected with NSO Group&apos;s Pegasus spyware while serving on the committee tasked with investigating that industry.</description><pubDate>Fri, 03 Jul 2026 23:15:00 GMT</pubDate><category>Mobile</category><category>article</category></item></channel></rss>