August 23, 2026
- Kaspersky found malware embedded in Android head-unit firmware from vehicle supplier DoFun, distributed through the units' own built-in updaters. The TWCore loader chains into ad fraud and enrols the car into a proxy botnet, with infrastructure links to the MoYu Group (Securelist, BleepingComputer). · Threat Activity
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick