The Chonkerton

This Week in Security: Android Malware, VOIP Hijack, Signal Contact Discovery, and TeamPCP Arrests

tech

Hackaday's weekly security roundup covers a researcher who bought a thirty-dollar Android streaming box and found it pre-loaded with malware. The malware, which matches the Vo1d botnet, hooks into every app, runs hidden ad-click fraud, and includes a root backdoor. In another story, a researcher registered expired domains that controlled a forgotten phone-number-to-DNS protocol, gaining the ability to intercept calls to military bases. The domains were eventually transferred to the UK's National Cyber Security Centre. Hackaday also notes that AliExpress has been caught using hidden audio fingerprinting to identify users, a technique Firefox mitigated three years ago. Finally, researchers found two vulnerabilities in Signal's contact discovery system that could let a malicious host extract contact lists, but both were fixed before public disclosure.

Source: https://hackaday.com/2026/08/28/this-week-in-security-and...

Listen to this story

Hear this and more stories in a personalized audio briefing.

Open The Chonkerton