Why Your Phone's Accessibility Permission Is the New Infostealer Door

September 20
37 mins

Episode Description

Hosts

* Professor CyberRisk

* Cyber Cowboy


Cyber Maps

* Bitdefender Threat Map: https://threatmap.bitdefender.com/

* Checkpoint Threat Map: https://threatmap.checkpoint.com/

* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


Episode Information

Title: Why Your Phone's Accessibility Permission Is the New Infostealer Door

Episode Number: 362

Overview

Weekly roundup of the most critical cybersecurity developments from 2026-09-13 to 2026-09-17. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


Guest Information

None this episode


Topics Covered

* RatHat: AI-driven Android malware that serializes the accessibility tree to a commercial LLM for live device control (Zimperium zLabs, China-linked)

* Brevo supply-chain attack: stolen Cloudflare API key injected ClickFix scripts into ~100,000 customer sites

* GitLab CVE-2026-85706: CVSS 10.0 unauthenticated arbitrary file read, CISA KEV, actively exploited

* CHOSEN BRICK: Iranian state Windows spyware targeting dissidents, activists, and journalists (NCSC + FBI joint advisory)


Top Stories

1. New RatHat Android malware uses AI to automate device control - https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/


Additional Cybersecurity News – Titles and URLs

2. Brevo supply-chain attack injected ClickFix scripts on customer sites - https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/

3. GitLab CVE-2026-85706: CVSS 10.0 unauthenticated file read exploited in the wild - https://hoploninfosec.com/cve-2026-85706-gitlab-vulnerability

4. Iranian hackers use CHOSEN BRICK Windows malware to spy on targets - https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/


Resources & Links

* Zimperium RatHat analysis (via BleepingComputer): https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/

* Brevo post-mortem: https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up

* Sansec Brevo supply-chain report: http://sansec.io/research/brevo-supply-chain-attack

* GitLab patch release notes (19.3.2): https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/

* CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

* NCSC joint advisory (FBI) on Iranian targeting: https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists


Call to Action

* Subscribe: Stay updated on cybersecurity threats.

* Leave a Review: Let us know what you think.

* Join the Conversation: Follow our community and ask questions.


Sponsor (if applicable)

No sponsors this episode


Podcast Socials & Website

* Website: https://www.youvealreadybeenhacked.com

* X: @professorcyberrisk

* YouTube: https://www.youtube.com/@YABHPodcast

* Discord/Community Forum: https://discord.gg/cz3xdsrqAE


See all episodes