Tag: mobile
-
Why Mobile Device Management Needs Its Own Threat Model
Allowing employees to use their own phones for work sounds simple. Deciding how much control IT should have… First seen on hackread.com Jump to article: hackread.com/mobile-device-management-threat-model/
-
Mobile malware warning from Ukrainian researchers includes iPhone exploit kit
‘Hit and run’ iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine’s SSSCIP. First seen on therecord.media Jump to article: therecord.media/ukraine-ssscip-mobile-malware-warning-ios-android
-
PaperPhone Cluster Shows How One Bot Operator Can Look Like Thousands of Mobile Users
A large-scale scraping cluster dubbed PaperPhone, exposing how one operator can manufacture the appearance of tens of thousands of legitimate mobile users across dozens of countries. The operation used roughly 75,000 IP addresses across 230 address blocks in 43 countries. However, browser-fingerprinting and network-analysis signals pointed to a centrally coordinated infrastructure rather than a genuinely…
-
Android Malware Turns Gemini AI Into an Assistant for On-Device Attacks
A newly documented Android banking trojan named RATHat is demonstrating how generative AI can be operationalized inside mobile malware. The threat uses Google Gemini models to navigate unfamiliar Android interfaces, while its operator panel applies AI to identify higher-value victims from stolen SMS data. The malware disguises itself as legitimate applications, then relies on social…
-
Authorizer: Open-source authentication and authorization for your apps
Authorizer is an open-source server for sign-in and access control in web and mobile apps. Teams run it on their own infrastructure and keep user accounts in a database they … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/authorizer-open-source-authentication-server/
-
RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials
A newly uncovered Android banking trojan dubbed RemControl is targeting customers of more than 30 financial institutions across Europe, the Middle East, and Canada. The malware combines fake Google Play pages, Android Accessibility Service abuse, credential-stealing overlays, real-time screen streaming, and remote-control functions to compromise mobile banking sessions. The company tracks the operator behind the…
-
Russia’s internet shutdowns disrupt warnings about incoming drone attacks
Russia’s growing restrictions on mobile internet and cellular service are making it harder for people to receive warnings about incoming Ukrainian drone and missile attacks. First seen on therecord.media Jump to article: therecord.media/russia-internet-shutdowns-disrupt-warnings-about-drone-attacks
-
NTU uses AI agents to uncover flaws in mobile networks
Nanyang Technological University’s agentic AI tool checks mobile core network code against 3GPP specifications and has found 84 vulnerabilities, including one that lets an attacker hijack a subscriber’s internet session First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650777/NTU-uses-AI-agents-to-uncover-flaws-in-mobile-networks
-
Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
A large-scale SMS phishing campaign is impersonating T-Mobile and warning recipients that their “rewards points” are about to expire, using fabricated balances, urgent deadlines, and lookalike redemption links to steal sensitive information. Security researchers have tracked the operation since early May 2026 and continue to observe new message variants despite a decline from its peak…
-
Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities
Apple has released iOS 27 and iPadOS 27, delivering one of its largest mobile security update batches to date. The release addresses approximately 126 vulnerabilities within the operating system, including flaws affecting the kernel, sandboxing mechanisms, WebKit, authentication services, and other security-sensitive components. Released on September 14, 2026, iOS 27 is available for the iPhone…
-
‘Cheap iPhone deal’: warning over scam sites selling latest Apple mobiles
Criminals exploit demand for iPhone 18 Pro and foldable Duo to trick people eager to get their hands on oneApple has just launched a range of new iPhones, including a foldable handset, just as you decide it is time to replace your own ageing mobile. But you balk at the £1,199 price tag for the…
-
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint mobile threat defence is included in appropriate Defender licensing, which means many organizations already own it. Best detection: Zimperium, with fully on-device analysis. Best for Apple estates on Jamf: Jamf. Best privacy positioning: Pradeo and Zimperium, both of which can analyse without shipping your traffic to a cloud.…
-
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint mobile threat defence is included in appropriate Defender licensing, which means many organizations already own it. Best detection: Zimperium, with fully on-device analysis. Best for Apple estates on Jamf: Jamf. Best privacy positioning: Pradeo and Zimperium, both of which can analyse without shipping your traffic to a cloud.…
-
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint mobile threat defence is included in appropriate Defender licensing, which means many organizations already own it. Best detection: Zimperium, with fully on-device analysis. Best for Apple estates on Jamf: Jamf. Best privacy positioning: Pradeo and Zimperium, both of which can analyse without shipping your traffic to a cloud.…
-
The 12 Best Mobile Device Management (MDM) Solutions, Compared and Priced
Best value overall: Microsoft Intune, included in Microsoft 365 E3 and E5. Best Apple pricing: Mosyle, with a free tier that genuinely works. Best Apple depth: Jamf. Best published mid-market pricing: ManageEngine, Hexnode, and Scalefusion. Best rugged: SOTI. Deploying dedicated MDM allows organizations to enforce policy baseline compliance and device health verification within a […]…
-
The 12 Best Unified Endpoint Management (UEM) Solutions, Compared and Priced
Best value overall: Microsoft Intune, included in Microsoft 365 E3 and E5, which means most organizations reading this already own it. Best published pricing: ManageEngine. Best Apple depth: Jamf. Best rugged and purpose-built devices: SOTI and 42Gears. Best cross-platform enterprise: Omnissa. Unified endpoint management platforms allow security and IT teams to govern mobile devices, […]…
-
Using AI, Calif Creates Demo WeChat Exploit that Spreads Through Phone Calls
Researchers with Calif used AI to detect a security flaw in the WeChat app and then create a demo worm exploit that can be spread quickly through mobile phones. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/using-ai-calif-creates-demo-wechat-exploit-that-spreads-through-phone-calls/
-
Daily OT Security News: September 08, 2026
Today’s verified developments cover critical vulnerabilities, exploit chains, AI-assisted PLC research, federal incident-reporting fragmentation, and a major mobile security release, items that affect IoT, OT, ICS, CPS, industrial and critical”‘infrastructure operations, and connected devices. N-able Patches Critical Zero-Day in… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-08-2026/
-
WhatsApp Testing Guest Calls for People Without a WhatsApp Account
WhatsApp is developing a guest-call feature that would let people without a WhatsApp account join encrypted calls through a web link. This capability would extend WhatsApp’s existing Call Links feature to include guests, letting invited participants join calls directly from a browser without installing the mobile app or creating an account. Currently, the feature is…
-
CISA Warns SonicWall SMA1000 Flaws Are Actively Exploited in Attacks
Tags: access, attack, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, mobile, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting SonicWall SMA1000 appliances to its Known Exploited Vulnerabilities (KEV) Catalog, warning that these flaws are actively being exploited in real-world attacks. The vulnerabilities, identified as CVE-2026-83548 and CVE-2026-83549, affect SonicWall’s Secure Mobile Access (SMA1000) remote-access appliances. CISA Warns SonicWall SMA1000 Flaws CISA…
-
CISA Warns SonicWall SMA1000 Flaws Are Actively Exploited in Attacks
Tags: access, attack, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, mobile, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting SonicWall SMA1000 appliances to its Known Exploited Vulnerabilities (KEV) Catalog, warning that these flaws are actively being exploited in real-world attacks. The vulnerabilities, identified as CVE-2026-83548 and CVE-2026-83549, affect SonicWall’s Secure Mobile Access (SMA1000) remote-access appliances. CISA Warns SonicWall SMA1000 Flaws CISA…
-
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.The vulnerabilities, discovered internally by SonicWall’s William Perry and Adam Babis, are listed below – CVE-2026-83548 (CVSS score: 10.0) – A pre-authentication SSRF vulnerability in the Appliance First seen…
-
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.”The injected code runs two operations against a site’s visitors: a mobile ad-fraud and…
-
CIAM gewinnt an Bedeutung durch Cyberrisiken, DSGVO/PSD2 und wachsende Omnichannel-Erwartungen
Die Art, wie Unternehmen heute mit ihren Kunden interagieren, hat sich in den vergangenen Jahren grundlegend verändert. Waren es vor zwei Jahrzehnten noch überwiegend persönliche Gespräche, Telefonate und handschriftliche Aufträge, laufen geschäftliche Interaktionen heute größtenteils digital über Websites, Mobile Apps und Self-Service-Portale ab. Mit dieser Transformation ist eine neue Herausforderung entstanden: die sichere Verwaltung von……
-
13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds
13 malicious Composer theme packages on Packagist that turn Vietnamese movie and comic streaming websites into delivery points for iPhone spyware, gambling redirects, ad fraud, and cryptocurrency-wallet theft. Once an operator installs one of the trojanized themes through Composer, the bundled front-end JavaScript is served to every visitor. Mobile users are selectively targeted, while iPhone…
-
What your vendor says about PQC tells you if they are ready
Tags: mobileIn this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/yaakov-stein-allot-telecom-pqc-migration/
-
What your vendor says about PQC tells you if they are ready
Tags: mobileIn this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/yaakov-stein-allot-telecom-pqc-migration/
-
External input cannot be trusted: input validation and encoding strategies
External data should be treated as hostile until it has been checked, constrained, and transformed for the specific place it will be used. That applies whether the data comes from a browser form, a mobile app, an API client, a file upload, an integration partner, or another internal service. In practice, many security issues start……
-
AI Shopping Assistant Vulnerabilities Enable Remote Code Execution on Retailer’s Servers
Security researchers have demonstrated how flaws in the AI shopping assistant of a major unnamed U.S. retailer could be exploited to enable remote code execution (RCE) on the company’s backend infrastructure through its public-facing mobile application. Netanel Rubin, co-founder and CTO of Rein Security, along with researcher Dan Avraham, presented their findings during a Black…
-
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication
Tags: access, android, authentication, control, cve, cvss, cyber, flaw, microsoft, mobile, open-source, vulnerabilityA critical vulnerability in Microsoft’s open-source UFO Desktop AgentOS could allow remote attackers to access and control Android devices connected via the platform’s Mobile Model Context Protocol (MCP) servers without requiring authentication. This vulnerability is tracked as CVE-2026-73296 and GHSA-24fq-m9rr-g3mm, carrying a CVSS v3.1 score of 9.4. It affects UFO versions up to and including…

