·S3 E62
Why Your Phone's Accessibility Permission Is the New Infostealer Door
Episode Description
Hosts
* Professor CyberRisk
* Cyber Cowboy
Cyber Maps
* Bitdefender Threat Map: https://threatmap.bitdefender.com/
* Checkpoint Threat Map: https://threatmap.checkpoint.com/
* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/
* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam
Episode Information
Title: Why Your Phone's Accessibility Permission Is the New Infostealer Door
Episode Number: 362
Overview
Weekly roundup of the most critical cybersecurity developments from 2026-09-13 to 2026-09-17. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.
Guest Information
None this episode
Topics Covered
* RatHat: AI-driven Android malware that serializes the accessibility tree to a commercial LLM for live device control (Zimperium zLabs, China-linked)
* Brevo supply-chain attack: stolen Cloudflare API key injected ClickFix scripts into ~100,000 customer sites
* GitLab CVE-2026-85706: CVSS 10.0 unauthenticated arbitrary file read, CISA KEV, actively exploited
* CHOSEN BRICK: Iranian state Windows spyware targeting dissidents, activists, and journalists (NCSC + FBI joint advisory)
Top Stories
1. New RatHat Android malware uses AI to automate device control - https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/
Additional Cybersecurity News – Titles and URLs
2. Brevo supply-chain attack injected ClickFix scripts on customer sites - https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/
3. GitLab CVE-2026-85706: CVSS 10.0 unauthenticated file read exploited in the wild - https://hoploninfosec.com/cve-2026-85706-gitlab-vulnerability
4. Iranian hackers use CHOSEN BRICK Windows malware to spy on targets - https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
Resources & Links
* Zimperium RatHat analysis (via BleepingComputer): https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/
* Brevo post-mortem: https://status.brevo.com/incidents/01M2QBC4EZ24ZACW6SWQYVW8N3/write-up
* Sansec Brevo supply-chain report: http://sansec.io/research/brevo-supply-chain-attack
* GitLab patch release notes (19.3.2): https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
* CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
* NCSC joint advisory (FBI) on Iranian targeting: https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists
Call to Action
* Subscribe: Stay updated on cybersecurity threats.
* Leave a Review: Let us know what you think.
* Join the Conversation: Follow our community and ask questions.
Sponsor (if applicable)
No sponsors this episode
Podcast Socials & Website
* Website: https://www.youvealreadybeenhacked.com
* X: @professorcyberrisk
* YouTube: https://www.youtube.com/@YABHPodcast
* Discord/Community Forum: https://discord.gg/cz3xdsrqAE