Google Play Protect is a technology platform tracked across 9 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed November 9, 2025; most recent activity July 11, 2026.
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
A security researcher discovered a publicly accessible database containing 86,859 images linked to a prominent European celebrity, revealing private messages, photos, and phone activity. The data was collected through…
A sophisticated spyware named Landfall targeted Samsung Galaxy phones for nearly a year, exploiting a zero-day vulnerability in Samsung's image processing library. Discovered by Palo Alto Networks' Unit 42, the malware…
Cellik, a new Android malware-as-a-service, allows attackers to create trojanized versions of legitimate apps from the Google Play Store. This malware can evade Play Protect defenses and offers capabilities such as…
A new variant of the ClayRat Android spyware has been identified, capable of full device takeover. Initially discovered in October 2025, this spyware targets Russian users and has expanded its capabilities to include…
Landfall, a sophisticated Android spyware, targeted Samsung Galaxy phones for nearly a year, exploiting a zero-day vulnerability (CVE-2025-21042) in Samsung's image-processing library. The campaign, uncovered by Palo…
State-backed hackers from China, Iran, North Korea, and Russia are utilizing Google's Gemini AI model to facilitate various stages of cyberattacks, including reconnaissance and post-compromise actions. Notably, the…
Google has issued a warning to Android users regarding certain apps in the Play Store that are not trustworthy and could harm devices. The warning applies to all users who are installing new applications from the Play…
Google has issued a warning to Android users regarding certain apps available in the Play Store that are deemed untrustworthy and potentially harmful to devices. This alert is directed at all users installing new…