Latest
Android flaw lets hackers unlock phones in under a minute
Your phone lock screen is supposed to be your last line of defense. If your device gets lost or stolen, that PIN or passcode should keep strangers out of your photos, messages and financial apps. But researchers have found a serious flaw that can break through those protections on certain Android phones in less than a minute.
Once exploited, attackers can recover your phone’s PIN, unlock encrypted storage and even extract sensitive data such as cryptocurrency wallet seed phrases. Security researchers estimate that roughly one in four Android phones could be affected, particularly budget phones.
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily. Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
ANDROID FIXES 129 SECURITY FLAWS IN MAJOR PHONE UPDATE
A newly disclosed vulnerability, tracked as CVE-2026-20435 in the National Vulnerability Database, affects some Android phones powered by MediaTek, a major smartphone chip maker based in Taiwan that competes with companies like Qualcomm. These phones use a security component called Trustonic’s Trusted Execution Environment (TEE), which is designed to keep sensitive data, such as encryption keys, protected from the rest of the system.
It stores cryptographic keys that help keep your device encrypted and secure, even if someone tries to tamper with it. However, security analyses of the vulnerability indicate that these protections may be bypassed on affected devices.
By connecting a phone to a computer using a USB cable, an attacker with physical access may be able to exploit the flaw during the early boot process, potentially exposing sensitive data before full security protections are enforced. Think of it like accessing the master key before the safe door even closes. Once attackers gain access to these low-level components, they may be able to access encrypted storage without needing your PIN.
In a worst-case scenario, this type of access could allow attackers to extract highly sensitive information, including personal photos, stored passwords, private messages, financial data, and crypto wallet credentials. If seed phrases for crypto wallets are exposed, attackers could drain funds permanently.
There’s limited action manufacturers can take on their own since the issue originates at the processor level, which is manufactured by MediaTek. The company says it has released a firmware patch addressing the vulnerability. However, the update must still be distributed by individual phone manufacturers through security updates. Depending on the device and whether it is still supported, that update could arrive quickly or not at all.
The good thing is that this attack requires physical access to the phone and a USB connection to a computer. That means it cannot be done remotely over the internet. However, if your phone is stolen, briefly confiscated, or even taken during a repair, the attacker could potentially extract sensitive information.
If you’re not sure whether this vulnerability affects your mobile device, you can look up your phone on a platform like GSMArena or your vendor’s website to see which SoC it uses, then cross-check it with MediaTek’s March security bulletin under CVE-2026-20435. You can log onto corp.mediatek.com/product-security-bulletin/March-2026 to review the list of affected chipsets and confirm whether your device may be at risk.
CyberGuy reached out to MediaTek for comment, but did not hear back before our deadline.
NEW ANDROID ATTACK TRICKS YOU INTO GIVING DANGEROUS PERMISSIONS
So how do you know if your phone is actually at risk? Not every Android phone is vulnerable. The issue primarily affects devices that use certain MediaTek processors. Here’s how to check your phone:
Go to Settings > About phone and look for your exact model name.
Search your phone model on a site like GSMArena or your manufacturer’s website to find the processor (also called the SoC).
If your phone uses a MediaTek chip, it may be affected. Devices with Qualcomm Snapdragon or Google Tensor chips are not part of this specific issue.
Check your phone’s system update settings and install any available updates from your manufacturer. Go to Settings > Software update and install any available updates. MediaTek has already released a fix, but phone makers must distribute it. Installing updates quickly ensures you receive the firmware patch if your device manufacturer has released it.
If your phone uses one of the affected chips, a few simple precautions can help reduce the chances of someone accessing your data if the device ever falls into the wrong hands.
A security app cannot fix this processor-level flaw. However, it can still help protect your phone from other threats that often follow stolen or compromised devices. It will not stop this specific exploit, but it can detect malicious apps, spyware, and suspicious activity that attackers may install after gaining access. That extra layer of monitoring can help stop additional data theft if your device ever falls into the wrong hands. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
If you store things like cryptocurrency wallet seed phrases, recovery codes, or sensitive documents in notes apps or screenshots, consider moving them to a secure offline location. If someone extracts your phone’s data through this vulnerability, that information could be exposed.
This exploit requires someone to physically connect your phone to a computer. Do not leave your device unattended in public places, and be cautious when handing it to repair shops or unknown technicians. Physical access dramatically increases the risk.
While the vulnerability bypasses encryption on affected devices, strong lock settings still protect against many other threats. Use a longer PIN or passcode instead of simple patterns, and enable automatic locking after short periods of inactivity.
Even if attackers gain access to data on your phone, two-factor authentication (2FA) can stop them from logging into your online accounts. Enable it for email, banking apps, cloud storage, and social media wherever possible.
A password manager stores your login credentials in a secure, encrypted vault instead of leaving them scattered across apps and notes. If someone compromises your device, the password manager still protects your accounts with strong encryption, forcing attackers to break through another security layer before they can access your logins. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com
Some Android devices limit USB data access when locked. Turning on this setting can reduce the risk of unauthorized data extraction through a wired connection, especially in situations where someone briefly gains physical access to your phone. On Samsung phones running the latest software:
Settings may vary slightly depending on your Samsung model and software version.
Go to Settings
Tap Lock screen
Then, tap Secure lock settings
Enter your current PIN, then tap Continue
Enable “Lock network and security” (or a similarly named option) to help block USB data access while your device is locked.
This vulnerability exposes a deeper issue with the Android ecosystem. Even when chipmakers release a fix, millions of phones depend on manufacturers to deliver updates that may never arrive, especially for cheaper devices that lose support quickly. We often assume our lock screen and encryption will protect our data if a phone is lost or stolen. However, incidents like this show that protection is only as strong as the update policies behind it. When devices stop receiving security patches, those protections quietly weaken over time.
Should phone manufacturers be required to guarantee security updates for several years if their devices contain critical encryption vulnerabilities? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily. Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Latest
Swalwell attorney denies misconduct, says congressman took accountability for ‘lapses in judgment’
Rep. Eric Swalwell’s attorney, Elias Dabaie, stated that the California congressman denies allegations of sexual misconduct, while acknowledging “lapses in judgment,” as multiple women have come forward and Swalwell’s biggest endorsements continued to be rescinded.
“We take these allegations very seriously,” Dabaie said. “The congressman categorically denies any misconduct took place, and we intend to vindicate his rights in court.” The attorney made the comments during a Saturday interview on CNN’s “The Story Is” with Elex Michaelson
Dabaie’s remarks came as Michaelson pressed him on why Swalwell declined to appear on the program after posting a video response online and as questions mount over the allegations, which surfaced weeks before the gubernatorial election.
“The congressman takes accountability for potential lapses in judgment, but again, categorically denies any wrongdoing,” Dabaie said, declining to elaborate further on what those lapses entailed.
When asked directly whether Swalwell admitted to cheating on his wife but not breaking the law, Dabaie said, “I’m not going to get into the details of that. Our investigation is ongoing. A lot of it is privileged.”
Dabaie also questioned the credibility and timing of the allegations, noting their proximity to the election.
“I have to question the timing of these allegations… 25 days out from an election,” he said. “From my perspective, looking at the facts, I do have to question the credibility of these allegations.”
As Michaelson cited evidence presented in reporting, including medical documentation and contemporaneous messages, Dabaie declined to engage in specifics.
“I prefer not to get into those details at this time,” he said. “The investigation is ongoing, and I do plan on vindicating the congressman’s rights.”
Dabaie further stated that the campaign would continue despite calls from Sens. Adam Schiff, D-Calif., and Ruben Gallego, D-Ariz., among other Democratic allies, to withdraw.
SWALWELL FACES EXPULSION EFFORT FOLLOWING BOMBSHELL ASSAULT ALLEGATIONS
“As of this moment, yes, he intends to continue his campaign,” Dabaie said.
“The notion that all these people pulled their support, I suspect that there are political machinations behind the scenes explaining why the Democratic Party has decided to try to consolidate the vote in order to make sure that a Democratic candidate makes it past the primary. So I’m not surprised to see that.”
Dabaie said the legal team is evaluating next steps after sending cease-and-desist letters to some of the accusers.
“We believe that these claims are false,” he said. “Once we had enough information to determine who was making them, we sent cease-and-desist letters. And we’re now looking at all available legal options.”
“I haven’t seen any evidence that that ever took place.”
Fox News Digital reached out for additional comment to Swalwell’s office and his gubernatorial campaign.
Latest
Tax day is this week: Avoid these 5 common mistakes that can cost you money
With Tax Day arriving this week, millions of filers are rushing to submit returns—often increasing the chances of simple but costly mistakes. Even minor errors, like incorrect personal details or overlooked income, can delay refunds, trigger IRS notices, or lead to penalties that take time and money to fix.
The good news is that most of these issues are entirely avoidable with both extra attention and preparation.
Here are five common filing missteps to watch out for and how to avoid them:
Your filing status is one of the most important choices on your tax return because it helps determine your tax rate, your standard deduction, and which credits you may be eligible to claim. Pick the wrong one, and you could end up paying more than you owe, getting a smaller refund or triggering delays if the IRS flags the return for review.
For many taxpayers, the confusion comes from life changes that happened during the year, like getting married or divorced, having a child, moving in with a partner, supporting an aging parent or sharing custody. Even if your situation feels straightforward, the IRS rules can be less intuitive, especially for taxpayers who aren’t sure whether they qualify as “head of household” or whether they can still file as a “qualifying surviving spouse” after a spouse has died.
BEWARE OF THESE TAX SCAMS AS THE FILING DEADLINE APPROACHES, CONGRESS WARNS
Head of household, in particular, can be costly to get wrong. It typically comes with a larger standard deduction and more favorable tax brackets than filing as single, but it has strict requirements tied to paying more than half the cost of keeping up a home and having a qualifying dependent. If you don’t meet the rules and claim it anyway, you may have to pay back tax benefits later, plus penalties and interest.
When in doubt, the IRS has an online filing-status tool, and many tax software programs will walk you through the questions to help you choose the right category.
An extension can buy you time to file your paperwork, but it doesn’t give you extra time to pay. For most taxpayers, the IRS deadline to pay what you owe is April 15, 2026 — even if you request an extension to file later.
“Remember that even if you claim an extension, the money is owed on April 15,” said Mike Faulkender, co-chair of American Prosperity at the America First Policy Institute.
RETIRED? HERE’S WHEN THE IRS MIGHT TAKE A CLOSER LOOK AT YOUR FINANCES
Faulkender, a former Treasury official and IRS commissioner, said taxpayers who need more time should still estimate their bill and pay by the filing deadline to help avoid added costs.
“You have to actually send in a check or have the payment deducted from your account by the filing deadline,” he said.
If you can’t pay in full by April 15, pay what you can to help limit penalties and interest that accrue on top of your tax bill.
One of the biggest and most expensive tax-season mistakes is failing to claim every credit or deduction you qualify for. That can mean a smaller refund or a higher bill.
“I think the top mistake people make is not fully understanding or taking the time to really research what are all the different deductions and the ways that you can put a little bit of extra money in your pocket that are available to you,” said Bill Sweeney, senior vice president of government affairs at AARP.
WHAT TRUMP’S NEXT PICK TO LEAD THE FEDERAL RESERVE MEANS FOR YOUR WALLET
Sweeney also warned taxpayers not to rely on last year’s return as a blueprint for filing because of recent changes to the tax code from the One Big Beautiful Bill Act.
“This would be a good year given that there are these changes to the tax code, to make sure not to assume that what you did last year will convey over to this year. Really take a fresh look at your tax situation and see if there’s money that you’re leaving on the table,” he said.
Timing matters when it comes to filing your taxes. Submitting your return before you’ve received all your key paperwork, like W-2s or 1099s, can lead to errors, missing income or a return you have to amend later.
Faulkender said there’s a simple way to double-check what’s been reported under your name before you file.
“One of the things that I learned last year when I was IRS commissioner was that if you create an account on irs.gov, you can see everything that’s been filed under your tax ID,” he said.
“We’re supposed to receive all of our W-2s and our 1099 forms in the mail in January and February. But if you’re missing one, or you misplaced it, rather than requesting it again, you can actually go and see what was filed under your taxpayer identification number if you create an account on IRS.gov.”
If you choose direct deposit for your refund, the IRS relies on the routing and account numbers you provide. One wrong digit can lead to delays.
If you pay what you owe by direct debit, incorrect banking details can also lead to a rejected payment and potentially result in penalties and interest.
Filing late can also cost you extra money, especially if you owe. The goal is to wait until you have what you need, then file as soon as you’re ready, without rushing prematurely.
Latest
Trump orders a blockade in the Strait of Hormuz as tensions with Iran soar
President Donald Trump said the U.S. Navy will begin a blockade of the Strait of Hormuz and interdict vessels that have paid a toll to Iran, after U.S. peace talks with Tehran ended in a stalemate.
“Effective immediately, the United States Navy, the Finest in the World, will begin the process of BLOCKADING any and all ships trying to enter or leave the Strait of Hormuz,” Trump posted on Truth Social. “At some point, we will reach an ‘ALL BEING ALLOWED TO GO IN, ALL BEING ALLOWED TO GO OUT’ basis, but Iran has not allowed that to happen… THIS IS WORLD EXTORTION.”
He said the U.S. would deny safe passage to vessels that paid the toll and begin clearing mines.
“I have also instructed our Navy to seek and interdict every vessel in international waters that has paid a toll to Iran,” he wrote. “No one who pays an illegal toll will have safe passage… We will also begin destroying the mines… Any Iranian who fires at us… will be BLOWN TO HELL!”
WHY THE STRAIT OF HORMUZ MATTERS AS TRUMP ISSUES FRESH ULTIMATUM TO IRAN
Iran’s closure of the strait has triggered global economic turmoil, and reopening it was a key condition in U.S. efforts to reach a deal.
In a second post, Trump reiterated the demand: “They better begin… getting this INTERNATIONAL WATERWAY OPEN AND FAST!”
Trump’s warning raises the stakes in the narrow but vital waterway, a critical artery for global energy supplies.
The strait, which lies between Iran, Oman and the United Arab Emirates, is one of the world’s most critical energy choke points, carrying roughly 20 million barrels of oil a day along with about one-fifth of global liquefied natural gas.
The strait is also a vital artery for refined fuels, including products like jet fuel.
The latest threat builds on a pattern of deadlines Trump has imposed on Tehran over the strait. Here is a timeline of those demands:
In a Truth Social post, Trump declared that if Iran did not “FULLY OPEN” the strait within 48 hours, the United States would “obliterate their various POWER PLANTS, STARTING WITH THE BIGGEST ONE FIRST!”
Ali Mousavi, Iran’s permanent representative to the International Maritime Organization, responded by saying that the Strait of Hormuz was “open to everyone” except Tehran’s enemies. Meanwhile, other Iranian officials warned that attacks on energy infrastructure would amount to an attack on the Iranian people and would be met with retaliation.
SAN FRANCISCO BECOMES FIRST US CITY WHERE DIESEL PRICES TOP $8 A GALLON
Two days later, Trump wrote in a Truth Social post that the U.S. had had “productive” conversations with Iran and that he had ordered the Pentagon to delay any strikes on Iranian power plants and energy infrastructure for five days.
Iranian officials publicly denied that any talks were taking place.
Trump again extended his deadline — this time by 10 days, to April 6 at 8 p.m. Eastern — saying in a social media post that he was “pausing the period of Energy Plant destruction” at the Iranian government’s request.
WHERE GAS PRICES ARE RISING FASTEST AS TRUMP ISSUES FRESH WARNING TO IRAN
Trump wrote in a Truth Social post that “great progress” had been made in negotiations to end the conflict. At the same time, he warned that if a deal was not reached and the Strait of Hormuz was not “immediately” opened, the United States would destroy Iran’s power plants, oil wells, Kharg Island — the country’s main oil export hub — and “possibly all” desalination plants.
Trump said Iran requested a ceasefire, a claim Iran’s foreign ministry spokesperson called “false and baseless,” according to the state news agency IRIB.
In a social media post, Trump said the United States would consider a ceasefire only once the strait was “open, free and clear,” adding: “Until then, we are blasting Iran into oblivion or, as they say, back to the Stone Ages!!!”
WHERE GAS PRICES ARE RISING FASTEST AS TRUMP ISSUES FRESH WARNING TO IRAN
Trump warned in a Truth Social post that “time is running out — 48 hours before all Hell will reign down on them.”
The post followed several conflicting statements in previous days, in which he alternately criticized allies for not acting to reopen the strait and suggested it would reopen on its own.
In a profanity-laced post on Truth Social on Sunday, Trump wrote: “Tuesday will be Power Plant Day, and Bridge Day, all wrapped up in one, in Iran.
“There will be nothing like it!!! Open the F—–’ Strait, you crazy b——-, or you’ll be living in Hell – JUST WATCH! Praise be to Allah.”
“Tuesday, 8:00 P.M. Eastern Time!” he wrote in a second post.
Two days later, Trump issued a fresh ultimatum to Iran, demanding that it allow all vessels to transit the Strait of Hormuz or face strikes on critical infrastructure. The warning came after weeks of escalating threats and missed deadlines.
“A whole civilization will die tonight, never to be brought back again. I don’t want that to happen, but it probably will,” Trump wrote in a Truth Social post. “We will find out tonight — one of the most important moments in the long and complex history of the world,” he added, referencing his 8 p.m. ET deadline for Iran to agree to a ceasefire and reopen the strait.
A ceasefire was called a few hours before the 8 p.m. deadline.
-
Politics3 weeks agoPentagon targets Iran-linked militias in Iraq as Hegseth vows ‘we will finish this’ for fallen US troops -
News3 weeks agoInside Joe Kent’s abrupt fall as GOP backlash grows over antisemitism accusations, FBI probe
-
Entertainment9 years ago9 Celebrities who have spoken out about being photoshopped
-
News2 days agoAll Hell Breaks Loose On Fox When Jesse Watters Asks Fetterman One Question
-
News5 days agoJD Vance Sparks Frenzy After His Jaw-Dropping Take On Trump’s Iran War
-
News2 weeks agoTop Democrat Arrested By Capitol Police – Dragged Out In Handcuffs
-
News2 weeks agoALERT: Entire Election Just FLIPPED!
-
Latest3 weeks ago
Chicago police detail how illegal immigrant accused of killing college student was caught: arrest report
