Advertisement
QR Code Phishing: SMS Traffic Violation Scams Bypass Mobile Filters
Scammers are using QR codes in SMS traffic violation scams to bypass security filters and steal financial data. Learn how to identify and block quishing.
Apple Patches DarkSword for iOS 18 — Security Analysis
Apple breaks precedent by patching the DarkSword mobile exploitation framework for iOS 18, addressing critical kernel-level risks and RCE vulnerabilities.
Recent Cyber Threats: Data Leaks, Android Malware, Critical Infra Ransomware
Analysis of a ChatGPT data leak, the emergence of an Android rootkit, and a ransomware attack impacting a water facility. Essential insights for defenders.
Shadow AI & Zero-Click Exploits Expand Enterprise Mobile Attack Surface
Enterprises face a growing mobile attack surface from shadow AI in apps, outdated devices, and zero-click exploits, leading to unseen risks for corporate data.
Coruna: Sophisticated iPhone Hacking Toolkit Bypasses iOS Defenses
Google researchers uncovered "Coruna," a powerful iOS exploit kit leveraging 23 vulnerabilities to silently install malware on iPhones, likely state-sponsored.
iOS 18.7.7 Update Expanded to Mitigate DarkSword Exploit Kit Risks
Apple expands iOS 18.7.7 and iPadOS 18.7.7 availability to additional devices to mitigate risks from the recently disclosed DarkSword exploit kit.
Advertisement
NoVoice Android Malware on Google Play: 2.3 Million Devices Infected
NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.
FBI Warning: Assessing Data Security Risks of Chinese Mobile Applications
The FBI warns against data security risks associated with foreign-developed mobile applications, particularly Chinese apps, due to potential data exfiltration.
Android Developer Identity Verification: New Google Play Mandates
Google mandates identity verification for all Android developers to reduce malicious app distribution and improve Play Store transparency starting September.
Star Blizzard (APT28) Adopts DarkSword iOS Exploit Kit
Russian APT Star Blizzard (APT28) now uses the DarkSword iOS exploit kit to target government, finance, and academia, increasing mobile threat exposure.
Apple iOS Lock Screen Alerts Warn of Active Web-Based Exploits
Apple is now issuing direct Lock Screen notifications to warn users on outdated iOS versions about active web-based attacks and the need for urgent updates.
Google Play Protect Advanced Flow for Android Sideloading
Google introduces Advanced Flow to Play Protect, enhancing security for Android sideloading to combat financial fraud and malicious APK installations.
Google Android Security: 24-Hour Wait for Unverified Sideloading
Google introduces a mandatory 24-hour cooling-off period for sideloading unverified Android applications to mitigate malware and financial scams.
Perseus Android Malware: Technical Analysis of Note-Stealing Tactics
Perseus Android malware targets sensitive secrets in user notes by abusing Accessibility Services. Learn how to detect and mitigate this mobile threat.
WhatsApp View Once Bypass via Modified Clients - Meta Won't Patch
A new WhatsApp View Once bypass allows recipients to persist media via modified clients. Meta declines patching, citing client-side enforcement limits.
Android 17 Restricts Accessibility API to Thwart Malware Abuse
Android 17 Beta 2 introduces restrictions on the Accessibility API under Advanced Protection Mode to prevent malware from hijacking system permissions.
Smartphone Phishing Bypasses Protections: AI's Role in Defense
Sophisticated Phishing attacks are increasingly bypassing smartphone protections. This analysis explores AI's potential role in defense and critical user safeguards.
BeatBanker Android Malware: Starlink Impersonation & Device Hijack
New BeatBanker Android malware impersonates the Starlink app on fake app stores to hijack devices, targeting unsuspecting users. Learn detection & mitigation.
Qualcomm 0-Day and iOS Exploit Chains: Impact & Mitigation Strategies
This weekly recap details active exploitation of a Qualcomm zero-day, iOS exploit chains, and emerging 'AirSnitch' attack methods. Learn what defenders should prioritize.
2025 Zero-Day Exploitation Review: Enterprise & OS Targets Dominate
GTIG's 2025 zero-day review reveals 90 in-the-wild exploits, with a record 48% targeting enterprise tech and a surge in OS vulnerabilities. Includes actor TTPs.
BadeSaba Calendar App Compromised in State-Linked Propaganda Campaign
An analysis of the BadeSaba Calendar hack, where five million Iranian users received propaganda notifications during kinetic strikes, highlighting PsyOps risks.
Russian Coruna iOS Exploit Kit Targets Global Users — Analysis
Security researchers uncover the Coruna iOS exploit kit, a nation-state tool now used in broader campaigns to deliver spyware to mobile devices.
Coruna iOS Exploit Kit: Spyware-Grade Threat Targets Crypto
The sophisticated Coruna iOS exploit kit, leveraging 23 undocumented vulnerabilities, is now deployed in targeted espionage and crypto theft attacks.
NATO Approves Apple iPhone and iPad for Classified Communications
Apple iOS and iPadOS devices added to NATO’s NIAPC, authorizing their use for handling NATO Restricted level classified information and communications.