Skip to content
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Swati KhandelwalSep 24, 2026Vulnerability / Mobile Security A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained… 

AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

Ravie LakshmananSep 24, 2026Hacking News / Cybersecurity News This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked… 

Ring’s popular Indoor Cam is down to , matching its all-time low

Ring’s popular Indoor Cam is down to $25, matching its all-time low

MATCHES LOWEST PRICE Ring Indoor Security Camera View Deal (function () { document.querySelector(“#sticky-promo-block a”).addEventListener(“click”, function(e) { const debug = document.location.host.search(/lndo.site|go-vip.net/) !== -1; const text = this.closest(“#sticky-promo-block”).querySelector(“p.promo-title”).textContent; const data = { event: “stickyConversionUnitClick”, eventCategory: “Sticky Conversion”,… 

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The “third-party[.]com” domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. “third-party[.]com has been a generic documentation placeholder for… 

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. “When a visitor interacts with…