Help AG’s Managed Security Services (MSS) team delivers 24x7x365 monitoring across complex enterprise environments, providing continuous visibility into emerging cybersecurity threats across the region.
Fake Google Gemini Download Tricks Users Into Installing Malware
A malware campaign has been identified using a fake Google Gemini download to trick users into installing the Vidar information stealer.
The attack can begin with something as simple as searching online for Google Gemini software. Instead of reaching an official download source, users are directed through a legitimate Google Colab page to a fake website called “Windows Software Hub”, where they are prompted to download what appears to be a Gemini installer for Windows.
The download then instructs users to run the file with administrator privileges and add it to their antivirus exclusions, helping the malware avoid security controls.
Once installed, Vidar connects to attacker-controlled systems and attempts to steal browser credentials and other sensitive information from the device.
Recommendations
- Block identified malicious domains, Internet Protocol (IP) addresses and file hashes across relevant security controls.
- Restrict software downloads to approved and trusted sources.
- Block or investigate unauthorised executables masquerading as AI applications.
- Monitor endpoints for suspicious files being executed from user download folders.
- Monitor unusual outbound connections following the installation or execution of newly downloaded software.
- Prevent users from adding unauthorised files or applications to antivirus exclusion lists.
- Limit local administrator privileges to users who genuinely require them.
- Monitor access to newly registered or suspicious software download domains.
- Use application allowlisting, where feasible, to prevent unauthorised software from running.
- Educate users to verify AI applications through the vendor’s official website before downloading or installing them.
ToxicPanda 2.0 Expands Attacks on Banking and Financial Applications
ToxicPanda 2.0 is an updated Android banking Trojan with expanded capabilities for credential theft, remote control and financial fraud. It can execute 167 different commands and targets hundreds of banking, cryptocurrency, e-wallet and other financial applications across 16 countries, including the United Arab Emirates.
The malware uses Android Accessibility Services to monitor activity on a user’s device and deploy phishing overlays, where fake screens are displayed over legitimate applications. This allows attackers to capture banking Personal Identification Numbers (PINs), login details and device-lock credentials, while also changing security settings.
ToxicPanda can also enable Android Wireless Debugging and use the Android Debug Bridge (ADB) to gain greater control over the device. This can allow it to grant additional permissions, weaken security restrictions and strengthen persistence, helping it maintain access for longer.
The campaign uses Amazon Web Services (AWS) infrastructure to deliver the malware and encrypted WebSocket connections to communicate with command-and-control (C2) servers. The latest version also introduces capabilities such as unauthorised device administrator access, fake system-update screens and dynamic PIN targeting, increasing its ability to steal credentials, maintain access and carry out financial fraud.
Recommendations
- Block known ToxicPanda C2 infrastructure and malware-delivery indicators.
- Restrict the installation of Android applications from unknown or untrusted sources.
- Deploy mobile threat defence controls capable of detecting ToxicPanda and related malware.
- Monitor suspicious or unexpected use of Android Accessibility Services.
- Monitor unauthorised activation of Developer Options and Wireless Debugging.
- Disable or restrict Android Debug Bridge (ADB) and Wireless Debugging on managed devices where they are not required.
- Monitor for applications obtaining unauthorised Device Administrator privileges.
- Detect suspicious overlays targeting banking and financial applications.
- Educate users not to grant Accessibility, Virtual Private Network (VPN) or administrator permissions to untrusted applications.
- Keep Android devices and mobile security software up to date.
- Investigate devices displaying unexpected system-update screens or unusual permission requests.
VMware Fixes Micrometer Vulnerability That Could Cause Application Crashes
VMware (Broadcom) has released a security update for CVE-2026-59295, a medium-severity vulnerability affecting Micrometer Core (micrometer-core).
The vulnerability affects applications that use Micrometer with Apache HttpAsyncClient. When an online request fails, for example because of a connection reset or timeout, information used to track that request may remain in the application’s memory instead of being removed.
If requests continue to fail, this information can accumulate and take up more and more memory. This is known as an unbounded memory leak.
Eventually, the application can run out of available heap memory, which is the memory it uses to store and process information while running. This can result in an OutOfMemoryError, causing the application to crash and potentially disrupting services.
Recommendations
- Ensure all affected systems are patched and updated.
Microsoft Fixes High-Severity UFO Vulnerability That Could Allow Command Execution
Microsoft has released a security update for CVE-2026-62316, a high-severity vulnerability affecting UFO, its open-source framework for intelligent automation across devices and platforms.
In versions before 3.0.8, UFO’s Linux Model Context Protocol (MCP) server does not properly validate where certain browser requests are coming from. This could allow an attacker to use a malicious web page to reach the MCP server running locally on a user’s device.
The attack uses a technique called Domain Name System (DNS) rebinding, which can make a malicious website appear as though it is communicating with a trusted local service. Through this, an attacker could access UFO’s local /mcp endpoint and identify the tools and commands available to it.
If the attacker also has a valid UFO MCP Application Programming Interface (API) key, they could use the execute_command function to read local files or run permitted operating system commands using the user’s existing privileges.
Microsoft has addressed the vulnerability in UFO version 3.0.8.
Recommendations
- Ensure all affected systems are patched and updated.
Google Chrome Fixes Five High-Severity Security Vulnerabilities
Google has released security updates addressing five high-severity vulnerabilities in Google Chrome, affecting versions prior to 151.0.7922.173.
If exploited, these vulnerabilities could allow an attacker to bypass browser security controls, run unauthorised code or gain higher levels of access to a user’s system. Some could also allow code to escape Chrome’s sandbox, the security layer designed to isolate browser activity from the rest of the device.
The vulnerabilities include:
- CVE-2026-76019 – Incorrect authorisation in Workers: A security control issue affecting Chrome’s background processing functionality.
- CVE-2026-76022 – Buffer overflow in Network: A memory-handling issue where more data can be written to memory than the allocated space can safely hold.
- CVE-2026-76020 – Race condition in V8: A timing issue in Chrome’s V8 JavaScript engine, where operations occurring in an unexpected order could lead to unintended behaviour.
- CVE-2026-76017 – Use-after-free in Chromoting: A memory issue where Chrome may attempt to access memory after it has already been released. This vulnerability is rated Critical by Chromium.
- CVE-2026-76018 – Privilege elevation in Import: A vulnerability that could allow an attacker to gain higher permissions or access than normally allowed.
Recommendations
- Ensure all affected systems are patched and updated.
References
https://www.darktrace.com/blog/when-ai-becomes-the-lure-a-fake-gemini-installer-delivers-vidar
https://github.com/spring-projects/security-advisories/security/advisories/GHSA-747c-jhq3-w433
https://spring.io/security/cve-2026-59295
https://github.com/microsoft/UFO/commit/3851c5d4e17c2865c56a94a6530692bf6e7a9b02
https://github.com/microsoft/UFO/releases/tag/v3.0.8
https://github.com/microsoft/UFO/security/advisories/GHSA-vf4c-mf32-gf2h
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html
https://issues.chromium.org/issues/539032888
https://issues.chromium.org/issues/543798025
https://issues.chromium.org/issues/541837151
https://issues.chromium.org/issues/522819252
https://issues.chromium.org/issues/513757918









