Millions of Android Devices Vulnerable Out of the Box

In an article published on wired.com, they say that security meltdowns on your smartphone are often self-inflicted: You clicked the wrong link, or installed the wrong app. But for millions of Android devices, the vulnerabilities have been baked in ahead of time, deep in the firmware, just waiting to be exploited. Who put them there? Some combination of the manufacturer that made it, and the carrier that sold it to you.

Although the article refers to US carriers, it is likely that it applies to most carriers.

Android apps infected with Windows malware

Security researchers have found 145 Android apps infected with Windows malware, suggesting they were created on compromised Windows machines.
The issue does not directly affect the Android device as the malware is for Windows.
Android vendors fail to install security patches

Devices lie and claim to be fully patched.

Security Research Labs analysed a large number of devices running Google's Android operating system, and found that some vendors fail to apply critical and high severity security patches.

Best to always check.

RedDrop nasty infects Androids via adult links, records sound, and fires off premium-rate texts

A newly discovered strain of Android malware makes live recordings of ambient audio around an infected device.
The RedDrop nasty also harvests and uploads files, photos, contacts, application data, config files and Wi-Fi information from infected kit. Both Dropbox and Google Drive are being used as temporary storage by the attackers.

