:

TOXICPANDA MALWARE EXPANDS WITH VPN ABUSE

SECURITY DESK1 MIN READ
MON, AUG 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

ToxicPanda Android malware has evolved to target 349 applications and support 167 remote commands. The malware exploits VPN permissions to block Google Play access on infected devices.

Security researchers have identified significant upgrades to ToxicPanda, an Android malware strain that leverages system permissions to disable security mechanisms. The malware uses VPN permissions as a vector to prevent users from accessing Google Play Store, cutting off a primary update channel for security patches. This capability effectively traps affected devices on older Android versions and prevents installation of legitimate security updates. The expanded attack surface now encompasses 349 applications across multiple categories. ToxicPanda's command infrastructure has grown to support 167 distinct remote commands, enabling operators to execute varied malicious actions on compromised devices. Experts recommend users avoid sideloading applications from untrusted sources and monitor permission requests during installation. Users should verify app legitimacy through official channels and maintain updated device security patches when available.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to bypass network protections and expose devices on private networks to the internet. The flaw affects routers deployed by multiple U.S. broadband providers.

10H AGOSecurity Desk

Cody Wilson, creator of the first 3D-printed gun, says he's developed software to bypass government-mandated blocks on 3D printers making firearms. The claim marks the start of an escalating regulatory battle over ghost guns.

11H AGOIndustry Desk

Hackers are exploiting critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The flaws allow attackers to forge SAML responses and gain administrator access.

11H AGOSecurity Desk

Microsoft's Paint and Photos applications automatically embed invisible GUIDs into locally generated images, according to reverse engineering analysis. The watermarks persist even when files are created entirely offline.

12H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.