Threat Brief — 2026-09-13 — Yandex's undeletable assistant
Today's feed intake is dominated by re-reports of stories already covered this week — including the AOMEI UEFI driver exploit, Mantax Otax Android ransomware, passkey-themed phishing against M365, and quantum magnetic navigation — none of which show new developments. The one genuinely fresh security-relevant finding concerns Yandex's "Alice" voice assistant, which users reportedly cannot fully remove from their devices. Yandex is disputing the characterization.
Top items
- Yandex "Alice" assistant resists deletion. Reports indicate that the Yandex Alice voice assistant may persist on user devices even after attempted removal, raising questions about user control and data retention. Yandex has publicly challenged the interpretation that the assistant is "undeletable." This is a consumer-privacy and platform-control concern rather than an active exploit, but it touches on the broader issue of pre-installed assistant software that resists uninstallation. (src: securitylab-ru)
Themes
Persistent software and user control. The Yandex Alice item echoes a recurring pattern this week of software that resists user removal or oversight — from OnePlus's nine-month-unfixed pre-installed session-hijacking app to Discord's mandatory age-estimation system. Pre-installed or deeply integrated software that cannot be cleanly removed creates an ongoing attack surface that users cannot remediate themselves.
