Android 17 adds OS-wide ECH, Local Network Protection, CT by default, and carrier 2G-off defaults
Security Tool/Service
Summary
Hide ▲
Show ▼
Android 17 adds OS-wide network protections that reduce traffic metadata exposure and limit local-network and cellular attack surfaces. The update brings Encrypted Client Hello (ECH), enables ECH GREASE by default, enforces Local Network Protection, and turns on Certificate Transparency by default. Participating carriers can also default 2G off, cutting downgrade paths, rogue base-station exposure, and SMS blaster risk.
Related Happenings
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score29
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
Qualcomm/Quectel SIM proactive AT interface code execution flaw (CVE-2026-57550)
Vulnerability
H score10
First: 11.08.2026 15:05
Last: 11.08.2026 15:05
Sources 1
About this happening:
CVE-2026-57550 tracks a SIM proactive AT interface flaw in Qualcomm/Quectel cellular modules that lets a hostile SIM push commands into modem firmware and reach code...
Qualcomm/Quectel SIM proactive AT interface code execution flaw (CVE-2026-57550)
VulnerabilityAbout this happening: CVE-2026-57550 tracks a SIM proactive AT interface flaw in Qualcomm/Quectel cellular modules that lets a hostile SIM push commands into modem firmware and reach code...
RedHook Android malware abuses Wireless ADB for shell access
Malware Activity
H score26
First: 12.07.2026 17:27
Last: 12.07.2026 17:27
Sources 1
About this happening:
The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedHook Android malware abuses Wireless ADB for shell access
Malware ActivityAbout this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
Google Play Protect adds warnings and app disabling for compromised SDK abuse
Security Tool/Service
H score11
First: 03.07.2026 12:35
Last: 03.07.2026 12:35
Sources 1
About this happening:
Google Play Protect was updated in July 2026 to warn Android users automatically and disable apps tied to compromised SDKs, limiting abuse of consumer devices...
Google Play Protect adds warnings and app disabling for compromised SDK abuse
Security Tool/ServiceAbout this happening: Google Play Protect was updated in July 2026 to warn Android users automatically and disable apps tied to compromised SDKs, limiting abuse of consumer devices...
Timeline
-
28.08.2026 19:20 2 articles · 5h ago
Android 17 adds OS-wide ECH, Local Network Protection, CT by default, and 2G-off defaults
Initial DisclosureGoogle announced Android 17 network security protections that expand Encrypted Client Hello (ECH) across the operating system, enable ECH GREASE by default, enforce Local Network Protection so apps must ask before scanning or connecting to devices on a local network, turn on Certificate Transparency (CT) by default, and let participating carriers default 2G off to reduce downgrade attacks, rogue base station exposure, and SMS blaster risk.
Show sources
- Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers — thehackernews.com — 28.08.2026 19:20
- Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers — thehackernews.com — 28.08.2026 19:20