Mantax Otax Turns Android Phones Against You
Mantax Otax is a new Android threat linked to Indonesian operators that merges extortion, espionage, and straight-up harassment after victims sideload malicious APKs.
It can swipe lock-screen PINs, OTPs, texts, web histories, locations, and secretly snap photos. Android 9 and older devices face another problem: It can encrypt files and launch an inescapable, on-screen chat interface for ransom demands. Newer Android versions limit the encryption damage, but not the surveillance.
Its second iteration introduces app lockouts, invisible touch-absorbing screens, visual jump scares, and attacker-controlled text-to-speech. Steer clear of sketchy APKs, deny weird Accessibility prompts, update your OS, and leave Play Protect on.
McKesson Leak Follows $55M Extortion Demand
Have I Been Pwned identified 6.4 million unique email addresses among the McKesson records leaked after ShinyHunters’ reported $55.2 million extortion demand.
The exposed contact, employment, and health data could help attackers create convincing phishing and impersonation scams.
Threat actors like ShinyHunters know what they’re doing and often tailor extortion demands to what they believe a victim can afford. Given how many companies the group has targeted, my bigger question is how long they can keep operating before law enforcement disrupts them.
Monitor for unusual account activity, use phishing-resistant MFA, and train employees to verify unexpected requests before sharing sensitive information.
32.8M Condé Nast Records Allegedly Up for Sale
A database allegedly containing 32.8 million Condé Nast user records has surfaced for sale on a cybercrime forum for $15,000.
No passwords or payment card data appear in the dataset, but millions of records reportedly contain personal details such as names, addresses, and birth dates.
I’d treat this dataset as reconnaissance material. Its real value to attackers may come later, when those details are combined with other stolen data to support more targeted attacks.
Treat unexpected subscription or billing messages with skepticism and access publisher accounts directly instead of using links in emails, texts, or renewal notices.
ShieldCrash Slips Past Microsoft Defender Patch
I’m following the new proof-of-concept called ShieldCrash that reportedly bypasses Microsoft’s September fix for the ShieldBreak Defender vulnerability.
The bypass allows arbitrary file reads with SYSTEM privileges on fully patched Windows systems.
This has become a back-and-forth between Microsoft’s fixes and the researcher finding new ways around them.
Keep Defender updated, maintain Tamper Protection, and monitor Microsoft guidance for additional ShieldCrash fixes or mitigations.
119K Fake Shops Target Payment Cards
Researchers uncovered DoppelCart, a network of 119,000 fake shopping domains designed to steal payment and personal data.
The operation impersonated more than 44,000 brands, using convincing storefronts and steep discounts to appear legitimate.
The scale here is what gets my attention. When more than 100,000 fake shops can be supported by a relatively small number of backends, taking down individual domains becomes a game of whack-a-mole.
Retailers should monitor lookalike domains and cloned storefronts, while shoppers should independently navigate to a retailer’s official site before entering payment information.
AI-Powered Attack Hits 440 PaperCut Servers
I’m following a campaign where attackers used hundreds of AI agents to exploit PaperCut vulnerabilities.
The campaign compromised at least 440 servers across 48 countries, including 204 at educational organizations.
The speed is what stands out to me. Compromising 11 organizations in 26 seconds shows how AI can accelerate attacks against vulnerable systems.
Review PaperCut and endpoint telemetry for prior compromise, then rotate privileged credentials if exposure cannot be ruled out.