Advertisement
Unisoc Modem Exploit Chain: Android Takeover via Video Call
An exploit chain targeting Unisoc modems allows remote Android device takeover through a malicious video call, requiring victim interaction.
Cognyte FalcoNet: Tactical Mobile Cell-Site Simulators and IMSI Catchers
An analysis of the Cognyte FalcoNet cell-site simulator, a mobile surveillance tool used for indiscriminate tracking and identification of cellular devices.
Fake Bahrain Alert Apps Deploy Android Surveillance Malware
Analyzing fake Bahrain alert apps distributing four-stage Android surveillance malware via phony app stores, exploiting geopolitical tensions for extensive data…
Open-Source Android AI Agent Hijacking Leads to Host System RCE
Learn how invisible text exploits open-source Android AI agents to trigger malicious code execution on host PCs via indirect prompt injection.
RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis
RedWing MaaS is an Android bank fraud malware-as-a-service rented on Telegram, enabling low-skill attackers to steal banking logins and OTPs.
Pegasus Spyware Targets MEP Investigating Surveillance
Former European Parliament Member Stelios Kouloglou was repeatedly targeted with Pegasus spyware while investigating surveillance tools.
Advertisement
UNC5792 & UNC4221 Target US Officials via Messaging Apps
Russian state-linked groups UNC5792 and UNC4221 are actively targeting US government, military, and allied personnel through evolving messaging app attacks.
Anthropic's Claude Cowork Mobile: Enterprise Security Implications
Anthropic tests Claude Cowork on mobile, enabling long-running AI tasks. This analysis covers potential data, access, and shadow IT risks for security teams.
Shopify Shop App Abused for Callback Phishing Attacks
Attackers are exploiting the Shopify Shop app's order tracking features to launch callback phishing attacks, tricking users into installing remote access tools.
Rokarolla Android Malware Targets 217 Financial Apps
New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.
Google Gemini Indirect Prompt Injection via Malicious Notifications
Security researchers demonstrate how malicious notifications can manipulate Google Gemini's voice assistant to perform unauthorized tasks or exfiltrate data.
Google Android Scam Detection: Real-Time AI Defense Against Fraud
Google introduces AI-powered Scam Detection for Android, utilizing on-device Gemini Nano to identify fraud patterns and protect users from voice-based phishing.
BTMOB Android Malware: Analyzing Phishing-Driven Full Device Takeover
BTMOB malware targets Android users via phishing, utilizing VNC and accessibility services to facilitate financial theft and total remote device control.
Apple's App Store Fraud Prevention: Over $11B Blocked
Runtime Rebel analyzes Apple's disclosure of blocking $11B in App Store fraud over six years, detailing the ongoing fight against malicious apps.
Security Brief: Data Breaches, ShinyHunters Activity, and App Flaws
Analyzes recent security events: Nvidia cloud gaming data breach, FBI warning on ShinyHunters hacking Canvas, and critical flaws in Audi mobile applications.
Windows Phone Link Abuse: CloudZ RAT Bypasses 2FA via SMS Interception
Hackers are deploying CloudZ RAT and its Pheno plugin to exploit Windows Phone Link, enabling 2FA bypass and SMS theft. Learn to detect and mitigate this threat.
Toronto SMS Blaster Arrests: Analyzing IMSI Catcher Smishing Risks
Law enforcement in Toronto dismantled an illicit SMS blaster operation used for high-volume smishing. Learn how these devices bypass carrier security filters.
Malicious Crypto Apps on Apple App Store Target Private Keys
Dozens of fake cryptocurrency wallet applications have been found in the Apple App Store, designed to phish users' recovery phrases and private keys, leading to…
Android Dirty Stream Path Traversal: Detecting and Patching App Exploits
Microsoft identifies Dirty Stream vulnerabilities in Android apps, allowing path traversal and unauthorized file manipulation. Learn how to secure your apps.
Mirax RAT Analysis: Android Devices Targeted for Proxy Node Abuse
Mirax RAT targets Android users in Europe via MaaS, converting infected devices into residential proxy nodes. Technical analysis of capabilities and TTPs.
Google Workspace CSE: Securing Gmail on Android and iOS
Google introduces native client-side encryption for Gmail on Android and iOS, enabling enterprise users to control encryption keys on mobile devices.
Google Gmail Client-Side Encryption for Android and iOS — Deployment Guide
Google expands Gmail client-side encryption (CSE) to Android and iOS, giving enterprise users full control over encryption keys for mobile email communications.
EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass
A flaw in EngageLab SDK exposed 50 million Android users to data theft. Learn how attackers bypass the Android sandbox to access private cryptocurrency keys.
Android StrongBox DoS Vulnerability Patched – Update Now
A critical Denial-of-Service vulnerability in Android's StrongBox keymaster and Framework component has been patched. Immediate updates are crucial for device security.