Enabling sideloading of apps from unverified devs will soon require a 24-hour waiting period, but there's a way to skip it.
Malicious JavaScript code delivered by the AppsFlyer Web SDK hijacked cryptocurrency, potentially in a supply-chain attack.