Play Store is a technology platform tracked across 8 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed November 16, 2025; most recent activity May 27, 2026.
A malicious npm package named 'codexui-android' has been discovered, which masquerades as a legitimate remote UI for OpenAI Codex. This tool, downloaded approximately 27,000 times weekly, has been silently exfiltrating…
Security researchers from KU Leuven University have identified a critical vulnerability in Google's Fast Pair Bluetooth protocol, dubbed 'WhisperPair'. This flaw affects hundreds of millions of Bluetooth audio devices,…
Google has introduced an 'advanced flow' feature for sideloading Android apps, allowing users to install apps from unverified developers while implementing additional security measures to combat scams. This update…
A new variant of the ClayRat Android spyware has been identified, capable of full device takeover. Initially discovered in October 2025, this spyware targets Russian users and has expanded its capabilities to include…
Google's Threat Intelligence Group, in collaboration with industry partners, has disrupted the IPIDEA proxy network, which hijacked consumer devices such as smartphones and desktop computers. This network was used to…
A new strain of Android malware utilizing artificial intelligence has been identified, capable of ad fraud and potentially granting hackers access to users' screens. This malware, found in mobile games on unofficial app…
Google has issued a warning to Android users regarding certain apps in the Play Store that are not trustworthy and could harm devices. The warning applies to all users who are installing new applications from the Play…
Google has issued a warning to Android users regarding certain apps available in the Play Store that are deemed untrustworthy and potentially harmful to devices. This alert is directed at all users installing new…