Google released the second beta of Android 17 with new privacy-focused platform behaviors and APIs aimed at reducing unnecessary access to sensitive data. Changes include a system-level Contacts Picker that grants apps only temporary access to user-selected contacts (including across personal/work profiles), a new ACCESS_LOCAL_NETWORK runtime permission to control discovery/connection to LAN devices (with an alternative path via system-mediated device pickers), and expanded safeguards for SMS one-time passwords by delaying most apps’ programmatic access to OTP messages for three hours (with exemptions for default SMS and approved companion apps, and guidance to use SMS Retriever/SMS User Consent APIs).
Microsoft is testing Windows 11 security and performance improvements for batch/CMD script execution in Insider Preview builds by adding an optional “secure processing mode” that prevents batch files from being modified while running. Administrators can enable it via the LockBatchFilesInUse registry value under HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor or via the LockBatchFilesWhenInUse application manifest control, reducing repeated signature validation when code integrity is enabled. Separately, commentary on Windows telemetry reiterates that Microsoft collects diagnostic data and suggests users can inspect telemetry themselves, but it does not describe a specific new security incident or vulnerability disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft released new Windows 11 Insider Preview builds in the Beta and Dev channels that introduce a more secure batch/CMD processing mode to prevent batch files from being modified while running. The feature can be enabled through a registry setting or application manifest control and is intended to improve security and performance in enterprise scripted workflows.
Google published the second beta of Android 17, adding privacy-focused platform changes including a system-level Contacts Picker, a new ACCESS_LOCAL_NETWORK runtime permission, an EyeDropper API, and delayed third-party access to SMS one-time passcodes. The update also requires apps targeting API level 37 and above to comply with the new permission model.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.