🟠 High  |  Source: The Hacker News


This week’s threat roundup covers a broad range of attack vectors including Android spyware disguised as legitimate apps, prompt injection via AI-processed images, malicious browser extensions enabling remote access, and attacks targeting industrial PLCs. The common thread is adversaries abusing trusted surfaces — app stores, AI pipelines, and open systems — to deliver malicious payloads. The variety and sophistication of these threats highlights how quickly attack surface is expanding across both enterprise and operational technology environments.

Security Architect’s Take: Review your AI agent pipelines for prompt injection controls, particularly where agents process external images or documents; implement strict input validation and sandboxing. Separately, audit any OT/ICS environments for PLC exposure and ensure Android device management policies block sideloading and enforce app vetting.

Original advisory: ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories