Google's Android developer verification starts September 30 in Brazil, Indonesia, Singapore and Thailand, covering apps from any channel on certified devices. Developers shipping outside Play, F-Droid included, now need a plan for verified identity in those markets.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives35
- Confidence40
RatHat's malware console now feeds stolen texts to Google's Gemini to estimate each victim's bank balance and rank who to rob first, security firm Cleafy says. Cleafy has traced nearly 100 deployments since April 2026 and found nothing that moves money.
Reality
- Evidence55
- Adoption25
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Synthient says residential proxy traffic it observed in May 2026 touched about 9.2 million domains through household IPs that real users also share. Its answer is to timestamp each proxy sighting and set friction by what the session is trying to do.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives85
- Confidence45
Zimperium says the Android banking Trojan now abuses Accessibility to switch on wireless debugging and run commands through the ADB daemon. The target list is the smaller half of the story.
Perspective Coverage
6 publishers
- Builder
- Builder 28%
- Operator
- Operator 67%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+12
- Incentives55
- Confidence64
Zimperium says RatHat uses an accessibility grant to switch on Wireless Debugging and read its own 6-digit pairing code, leaving native daemons at shell privilege that keep answering after the app is removed.
Perspective Coverage
6 publishers
- Builder
- Builder 32%
- Operator
- Operator 63%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence66
A developer rented boxes in Frankfurt, New York and Singapore, told nobody the addresses, and counted the knocks. One host on Korea Telecom's network sent nearly half the packets, so the background rate only appears once you subtract it.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives18
- Confidence55
Zimperium zLabs says the trojan needs two taps from the user, then drives Android settings itself to pair with the local ADB daemon. No root, no CVE, and PC endpoint tooling sees none of it.
Reality
- Evidence54
- Adoption
- Insufficient
- Hype gap+9
- Incentives68
- Confidence56