<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Mobile Security</title><description>Cybersecurity articles tagged #Mobile Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Unisoc Modem Exploit Chain: Android Takeover via Video Call</title><link>https://runtimerebel.com/blog/unisoc-modem-exploit-chain-android-takeover-via-video-call</link><guid isPermaLink="true">https://runtimerebel.com/blog/unisoc-modem-exploit-chain-android-takeover-via-video-call</guid><description>An exploit chain targeting Unisoc modems allows remote Android device takeover through a malicious video call, requiring victim interaction.</description><pubDate>Tue, 18 Aug 2026 00:41:53 GMT</pubDate><category>Android</category><category>Mobile Security</category><category>Remote Code Execution</category><category>Exploit Chain</category><category>Unisoc</category></item><item><title>Cognyte FalcoNet: Tactical Mobile Cell-Site Simulators and IMSI Catchers</title><link>https://runtimerebel.com/blog/cognyte-falconet-tactical-mobile-cell-site-simulators-and-imsi-catchers</link><guid isPermaLink="true">https://runtimerebel.com/blog/cognyte-falconet-tactical-mobile-cell-site-simulators-and-imsi-catchers</guid><description>An analysis of the Cognyte FalcoNet cell-site simulator, a mobile surveillance tool used for indiscriminate tracking and identification of cellular devices.</description><pubDate>Mon, 27 Jul 2026 11:27:14 GMT</pubDate><category>Cognyte</category><category>Falconet</category><category>IMSI Catcher</category><category>Surveillance Tech</category><category>Mobile Security</category></item><item><title>Fake Bahrain Alert Apps Deploy Android Surveillance Malware</title><link>https://runtimerebel.com/blog/fake-bahrain-alert-apps-deploy-android-surveillance-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-bahrain-alert-apps-deploy-android-surveillance-malware</guid><description>Analyzing fake Bahrain alert apps distributing four-stage Android surveillance malware via phony app stores, exploiting geopolitical tensions for extensive data…</description><pubDate>Wed, 22 Jul 2026 21:12:30 GMT</pubDate><category>Android</category><category>Mobile Security</category><category>Spyware</category><category>Surveillance Malware</category><category>Fake Apps</category><category>Phishing</category><category>Social Engineering</category><category>Bahrain</category></item><item><title>Open-Source Android AI Agent Hijacking Leads to Host System RCE</title><link>https://runtimerebel.com/blog/open-source-android-ai-agent-hijacking-leads-to-host-system-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-source-android-ai-agent-hijacking-leads-to-host-system-rce</guid><description>Learn how invisible text exploits open-source Android AI agents to trigger malicious code execution on host PCs via indirect prompt injection.</description><pubDate>Tue, 21 Jul 2026 13:54:29 GMT</pubDate><category>Android Security</category><category>AI Agents</category><category>Prompt Injection</category><category>RCE</category><category>Mobile Security</category><category>Appagent</category></item><item><title>RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis</title><link>https://runtimerebel.com/blog/redwing-maas-android-bank-fraud-via-telegram-rental-service-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/redwing-maas-android-bank-fraud-via-telegram-rental-service-analysis</guid><description>RedWing MaaS is an Android bank fraud malware-as-a-service rented on Telegram, enabling low-skill attackers to steal banking logins and OTPs.</description><pubDate>Tue, 07 Jul 2026 18:01:20 GMT</pubDate><category>RedWing</category><category>MaaS</category><category>Android</category><category>Banking Malware</category><category>Oblivion</category><category>Telegram</category><category>Mobile Security</category></item><item><title>Pegasus Spyware Targets MEP Investigating Surveillance</title><link>https://runtimerebel.com/blog/pegasus-spyware-targets-mep-investigating-surveillance</link><guid isPermaLink="true">https://runtimerebel.com/blog/pegasus-spyware-targets-mep-investigating-surveillance</guid><description>Former European Parliament Member Stelios Kouloglou was repeatedly targeted with Pegasus spyware while investigating surveillance tools.</description><pubDate>Fri, 03 Jul 2026 14:09:22 GMT</pubDate><category>Pegasus</category><category>Spyware</category><category>Stelios Kouloglou</category><category>European Parliament</category><category>Citizen Lab</category><category>Surveillance</category><category>Mobile Security</category></item><item><title>UNC5792 &amp; UNC4221 Target US Officials via Messaging Apps</title><link>https://runtimerebel.com/blog/unc5792-unc4221-target-us-officials-via-messaging-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc5792-unc4221-target-us-officials-via-messaging-apps</guid><description>Russian state-linked groups UNC5792 and UNC4221 are actively targeting US government, military, and allied personnel through evolving messaging app attacks.</description><pubDate>Mon, 29 Jun 2026 10:10:24 GMT</pubDate><category>UNC5792</category><category>UNC4221</category><category>Russian APT</category><category>Messaging App Attacks</category><category>Government Targeting</category><category>Espionage</category><category>Mobile Security</category></item><item><title>Anthropic&apos;s Claude Cowork Mobile: Enterprise Security Implications</title><link>https://runtimerebel.com/blog/anthropic-s-claude-cowork-mobile-enterprise-security-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-s-claude-cowork-mobile-enterprise-security-implications</guid><description>Anthropic tests Claude Cowork on mobile, enabling long-running AI tasks. This analysis covers potential data, access, and shadow IT risks for security teams.</description><pubDate>Fri, 26 Jun 2026 01:02:11 GMT</pubDate><category>Anthropic</category><category>Claude</category><category>AI</category><category>Mobile Security</category><category>Enterprise AI</category><category>Data Governance</category></item><item><title>Shopify Shop App Abused for Callback Phishing Attacks</title><link>https://runtimerebel.com/blog/shopify-shop-app-abused-for-callback-phishing-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/shopify-shop-app-abused-for-callback-phishing-attacks</guid><description>Attackers are exploiting the Shopify Shop app&apos;s order tracking features to launch callback phishing attacks, tricking users into installing remote access tools.</description><pubDate>Thu, 25 Jun 2026 20:47:19 GMT</pubDate><category>Shopify</category><category>Callback Phishing</category><category>Social Engineering</category><category>Mobile Security</category></item><item><title>Rokarolla Android Malware Targets 217 Financial Apps</title><link>https://runtimerebel.com/blog/rokarolla-android-malware-targets-217-financial-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/rokarolla-android-malware-targets-217-financial-apps</guid><description>New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.</description><pubDate>Tue, 16 Jun 2026 21:08:26 GMT</pubDate><category>Rokarolla</category><category>Android Malware</category><category>Banking Trojan</category><category>Mobile Security</category><category>Financial Services</category><category>Overlay Attack</category></item><item><title>Google Gemini Indirect Prompt Injection via Malicious Notifications</title><link>https://runtimerebel.com/blog/google-gemini-indirect-prompt-injection-via-malicious-notifications</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gemini-indirect-prompt-injection-via-malicious-notifications</guid><description>Security researchers demonstrate how malicious notifications can manipulate Google Gemini&apos;s voice assistant to perform unauthorized tasks or exfiltrate data.</description><pubDate>Wed, 03 Jun 2026 13:49:53 GMT</pubDate><category>Google Gemini</category><category>Prompt Injection</category><category>LLM Security</category><category>Hiddenlayer</category><category>Mobile Security</category></item><item><title>Google Android Scam Detection: Real-Time AI Defense Against Fraud</title><link>https://runtimerebel.com/blog/google-android-scam-detection-real-time-ai-defense-against-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-android-scam-detection-real-time-ai-defense-against-fraud</guid><description>Google introduces AI-powered Scam Detection for Android, utilizing on-device Gemini Nano to identify fraud patterns and protect users from voice-based phishing.</description><pubDate>Wed, 03 Jun 2026 09:44:39 GMT</pubDate><category>Android</category><category>Google Gemini Nano</category><category>AI Deepfakes</category><category>Vishing</category><category>Mobile Security</category></item><item><title>BTMOB Android Malware: Analyzing Phishing-Driven Full Device Takeover</title><link>https://runtimerebel.com/blog/btmob-android-malware-analyzing-phishing-driven-full-device-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/btmob-android-malware-analyzing-phishing-driven-full-device-takeover</guid><description>BTMOB malware targets Android users via phishing, utilizing VNC and accessibility services to facilitate financial theft and total remote device control.</description><pubDate>Thu, 28 May 2026 13:26:29 GMT</pubDate><category>BTMOB</category><category>Android Malware</category><category>Phishing</category><category>VNC</category><category>Financial Fraud</category><category>Mobile Security</category></item><item><title>Apple&apos;s App Store Fraud Prevention: Over $11B Blocked</title><link>https://runtimerebel.com/blog/apple-s-app-store-fraud-prevention-over-11b-blocked</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-s-app-store-fraud-prevention-over-11b-blocked</guid><description>Runtime Rebel analyzes Apple&apos;s disclosure of blocking $11B in App Store fraud over six years, detailing the ongoing fight against malicious apps.</description><pubDate>Thu, 21 May 2026 20:41:16 GMT</pubDate><category>Apple</category><category>App Store</category><category>Fraud</category><category>Cybercrime</category><category>Mobile Security</category><category>Payment Fraud</category></item><item><title>Security Brief: Data Breaches, ShinyHunters Activity, and App Flaws</title><link>https://runtimerebel.com/blog/security-brief-data-breaches-shinyhunters-activity-and-app-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-brief-data-breaches-shinyhunters-activity-and-app-flaws</guid><description>Analyzes recent security events: Nvidia cloud gaming data breach, FBI warning on ShinyHunters hacking Canvas, and critical flaws in Audi mobile applications.</description><pubDate>Fri, 15 May 2026 16:42:44 GMT</pubDate><category>NVIDIA</category><category>ShinyHunters</category><category>Audi</category><category>Data Breach</category><category>Mobile Security</category><category>Cloud Gaming</category><category>FBI</category></item><item><title>Windows Phone Link Abuse: CloudZ RAT Bypasses 2FA via SMS Interception</title><link>https://runtimerebel.com/blog/windows-phone-link-abuse-cloudz-rat-bypasses-2fa-via-sms-interception</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-phone-link-abuse-cloudz-rat-bypasses-2fa-via-sms-interception</guid><description>Hackers are deploying CloudZ RAT and its Pheno plugin to exploit Windows Phone Link, enabling 2FA bypass and SMS theft. Learn to detect and mitigate this threat.</description><pubDate>Wed, 06 May 2026 16:41:34 GMT</pubDate><category>CloudZ RAT</category><category>Pheno Plugin</category><category>Windows Phone Link</category><category>2FA Bypass</category><category>SMS Interception</category><category>Mobile Security</category></item><item><title>Toronto SMS Blaster Arrests: Analyzing IMSI Catcher Smishing Risks</title><link>https://runtimerebel.com/blog/toronto-sms-blaster-arrests-analyzing-imsi-catcher-smishing-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/toronto-sms-blaster-arrests-analyzing-imsi-catcher-smishing-risks</guid><description>Law enforcement in Toronto dismantled an illicit SMS blaster operation used for high-volume smishing. Learn how these devices bypass carrier security filters.</description><pubDate>Mon, 27 Apr 2026 20:29:15 GMT</pubDate><category>Smishing</category><category>IMSI Catcher</category><category>Toronto Police</category><category>Phishing Campaign</category><category>Mobile Security</category></item><item><title>Malicious Crypto Apps on Apple App Store Target Private Keys</title><link>https://runtimerebel.com/blog/malicious-crypto-apps-on-apple-app-store-target-private-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-crypto-apps-on-apple-app-store-target-private-keys</guid><description>Dozens of fake cryptocurrency wallet applications have been found in the Apple App Store, designed to phish users&apos; recovery phrases and private keys, leading to…</description><pubDate>Tue, 21 Apr 2026 20:25:52 GMT</pubDate><category>Cryptocurrency</category><category>Malware</category><category>Phishing</category><category>Apple App Store</category><category>Mobile Security</category><category>Private Keys</category><category>Recovery Phrases</category></item><item><title>Android Dirty Stream Path Traversal: Detecting and Patching App Exploits</title><link>https://runtimerebel.com/blog/android-dirty-stream-path-traversal-detecting-and-patching-app-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-dirty-stream-path-traversal-detecting-and-patching-app-exploits</guid><description>Microsoft identifies Dirty Stream vulnerabilities in Android apps, allowing path traversal and unauthorized file manipulation. Learn how to secure your apps.</description><pubDate>Mon, 20 Apr 2026 05:08:30 GMT</pubDate><category>Android</category><category>Dirty Stream</category><category>Path Traversal</category><category>Mobile Security</category><category>Microsoft Threat Intelligence</category></item><item><title>Mirax RAT Analysis: Android Devices Targeted for Proxy Node Abuse</title><link>https://runtimerebel.com/blog/mirax-rat-analysis-android-devices-targeted-for-proxy-node-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/mirax-rat-analysis-android-devices-targeted-for-proxy-node-abuse</guid><description>Mirax RAT targets Android users in Europe via MaaS, converting infected devices into residential proxy nodes. Technical analysis of capabilities and TTPs.</description><pubDate>Wed, 15 Apr 2026 12:30:33 GMT</pubDate><category>Mirax RAT</category><category>Android Malware</category><category>Proxy Botnet</category><category>Mobile Security</category></item><item><title>Google Workspace CSE: Securing Gmail on Android and iOS</title><link>https://runtimerebel.com/blog/google-workspace-cse-securing-gmail-on-android-and-ios</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-workspace-cse-securing-gmail-on-android-and-ios</guid><description>Google introduces native client-side encryption for Gmail on Android and iOS, enabling enterprise users to control encryption keys on mobile devices.</description><pubDate>Mon, 13 Apr 2026 08:49:19 GMT</pubDate><category>Gmail</category><category>Google Workspace</category><category>Client Side Encryption</category><category>Data Sovereignty</category><category>Mobile Security</category></item><item><title>Google Gmail Client-Side Encryption for Android and iOS — Deployment Guide</title><link>https://runtimerebel.com/blog/google-gmail-client-side-encryption-for-android-and-ios-deployment-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gmail-client-side-encryption-for-android-and-ios-deployment-guide</guid><description>Google expands Gmail client-side encryption (CSE) to Android and iOS, giving enterprise users full control over encryption keys for mobile email communications.</description><pubDate>Fri, 10 Apr 2026 12:27:27 GMT</pubDate><category>Google Workspace</category><category>Gmail</category><category>Client Side Encryption</category><category>Mobile Security</category><category>S MIME</category><category>Data Privacy</category></item><item><title>EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass</title><link>https://runtimerebel.com/blog/engagelab-sdk-vulnerability-protecting-crypto-wallets-from-sandbox-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/engagelab-sdk-vulnerability-protecting-crypto-wallets-from-sandbox-bypass</guid><description>A flaw in EngageLab SDK exposed 50 million Android users to data theft. Learn how attackers bypass the Android sandbox to access private cryptocurrency keys.</description><pubDate>Fri, 10 Apr 2026 00:40:05 GMT</pubDate><category>EngageLab SDK</category><category>Android Security</category><category>Crypto Wallet Vulnerability</category><category>Microsoft Defender</category><category>Mobile Security</category></item><item><title>Android StrongBox DoS Vulnerability Patched – Update Now</title><link>https://runtimerebel.com/blog/android-strongbox-dos-vulnerability-patched-update-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-strongbox-dos-vulnerability-patched-update-now</guid><description>A critical Denial-of-Service vulnerability in Android&apos;s StrongBox keymaster and Framework component has been patched. Immediate updates are crucial for device security.</description><pubDate>Tue, 07 Apr 2026 16:29:56 GMT</pubDate><category>Android</category><category>StrongBox</category><category>DoS</category><category>Vulnerability</category><category>Patch</category><category>Mobile Security</category></item><item><title>QR Code Phishing: SMS Traffic Violation Scams Bypass Mobile Filters</title><link>https://runtimerebel.com/blog/qr-code-phishing-sms-traffic-violation-scams-bypass-mobile-filters</link><guid isPermaLink="true">https://runtimerebel.com/blog/qr-code-phishing-sms-traffic-violation-scams-bypass-mobile-filters</guid><description>Scammers are using QR codes in SMS traffic violation scams to bypass security filters and steal financial data. Learn how to identify and block quishing.</description><pubDate>Sun, 05 Apr 2026 20:11:44 GMT</pubDate><category>Quishing</category><category>Smishing</category><category>Financial Fraud</category><category>Mobile Security</category><category>Phishing Scams</category></item><item><title>Apple Patches DarkSword for iOS 18 — Security Analysis</title><link>https://runtimerebel.com/blog/apple-patches-darksword-for-ios-18-security-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-patches-darksword-for-ios-18-security-analysis</guid><description>Apple breaks precedent by patching the DarkSword mobile exploitation framework for iOS 18, addressing critical kernel-level risks and RCE vulnerabilities.</description><pubDate>Sat, 04 Apr 2026 08:18:32 GMT</pubDate><category>Apple</category><category>Ios 18</category><category>DarkSword</category><category>Mobile Security</category><category>Kernel Exploit</category></item><item><title>Recent Cyber Threats: Data Leaks, Android Malware, Critical Infra Ransomware</title><link>https://runtimerebel.com/blog/recent-cyber-threats-data-leaks-android-malware-critical-infra-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/recent-cyber-threats-data-leaks-android-malware-critical-infra-ransomware</guid><description>Analysis of a ChatGPT data leak, the emergence of an Android rootkit, and a ransomware attack impacting a water facility. Essential insights for defenders.</description><pubDate>Fri, 03 Apr 2026 16:18:10 GMT</pubDate><category>ChatGPT Data Leak</category><category>Android Rootkit</category><category>Ransomware Attack</category><category>Critical Infrastructure Security</category><category>Mobile Security</category><category>Data Protection</category></item><item><title>Shadow AI &amp; Zero-Click Exploits Expand Enterprise Mobile Attack Surface</title><link>https://runtimerebel.com/blog/shadow-ai-zero-click-exploits-expand-enterprise-mobile-attack-surface</link><guid isPermaLink="true">https://runtimerebel.com/blog/shadow-ai-zero-click-exploits-expand-enterprise-mobile-attack-surface</guid><description>Enterprises face a growing mobile attack surface from shadow AI in apps, outdated devices, and zero-click exploits, leading to unseen risks for corporate data.</description><pubDate>Fri, 03 Apr 2026 12:23:17 GMT</pubDate><category>Mobile Security</category><category>Shadow AI</category><category>Zero Click Exploits</category><category>Attack Surface Management</category><category>Enterprise Security</category><category>Mobile Device Management</category></item><item><title>Coruna: Sophisticated iPhone Hacking Toolkit Bypasses iOS Defenses</title><link>https://runtimerebel.com/blog/coruna-sophisticated-iphone-hacking-toolkit-bypasses-ios-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/coruna-sophisticated-iphone-hacking-toolkit-bypasses-ios-defenses</guid><description>Google researchers uncovered &quot;Coruna,&quot; a powerful iOS exploit kit leveraging 23 vulnerabilities to silently install malware on iPhones, likely state-sponsored.</description><pubDate>Thu, 02 Apr 2026 12:30:01 GMT</pubDate><category>Coruna</category><category>iOS</category><category>iPhone</category><category>Exploit Kit</category><category>State Sponsored</category><category>Mobile Security</category></item><item><title>iOS 18.7.7 Update Expanded to Mitigate DarkSword Exploit Kit Risks</title><link>https://runtimerebel.com/blog/ios-18-7-7-update-expanded-to-mitigate-darksword-exploit-kit-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ios-18-7-7-update-expanded-to-mitigate-darksword-exploit-kit-risks</guid><description>Apple expands iOS 18.7.7 and iPadOS 18.7.7 availability to additional devices to mitigate risks from the recently disclosed DarkSword exploit kit.</description><pubDate>Thu, 02 Apr 2026 08:27:29 GMT</pubDate><category>Apple</category><category>iOS</category><category>DarkSword</category><category>Exploit Kit</category><category>Mobile Security</category></item><item><title>NoVoice Android Malware on Google Play: 2.3 Million Devices Infected</title><link>https://runtimerebel.com/blog/novoice-android-malware-on-google-play-2-3-million-devices-infected</link><guid isPermaLink="true">https://runtimerebel.com/blog/novoice-android-malware-on-google-play-2-3-million-devices-infected</guid><description>NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.</description><pubDate>Wed, 01 Apr 2026 20:19:41 GMT</pubDate><category>Android</category><category>NoVoice</category><category>Google Play</category><category>Adware</category><category>Malware</category><category>Mobile Security</category></item><item><title>FBI Warning: Assessing Data Security Risks of Chinese Mobile Applications</title><link>https://runtimerebel.com/blog/fbi-warning-assessing-data-security-risks-of-chinese-mobile-applications</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warning-assessing-data-security-risks-of-chinese-mobile-applications</guid><description>The FBI warns against data security risks associated with foreign-developed mobile applications, particularly Chinese apps, due to potential data exfiltration.</description><pubDate>Wed, 01 Apr 2026 12:27:27 GMT</pubDate><category>Mobile Security</category><category>Data Privacy</category><category>FBI Warning</category><category>Data Exfiltration</category><category>China</category><category>Supply Chain Risk</category></item><item><title>Android Developer Identity Verification: New Google Play Mandates</title><link>https://runtimerebel.com/blog/android-developer-identity-verification-new-google-play-mandates</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-developer-identity-verification-new-google-play-mandates</guid><description>Google mandates identity verification for all Android developers to reduce malicious app distribution and improve Play Store transparency starting September.</description><pubDate>Tue, 31 Mar 2026 20:17:58 GMT</pubDate><category>Android</category><category>Google Play</category><category>Identity Verification</category><category>Mobile Security</category><category>Developer Compliance</category></item><item><title>Star Blizzard (APT28) Adopts DarkSword iOS Exploit Kit</title><link>https://runtimerebel.com/blog/star-blizzard-apt28-adopts-darksword-ios-exploit-kit</link><guid isPermaLink="true">https://runtimerebel.com/blog/star-blizzard-apt28-adopts-darksword-ios-exploit-kit</guid><description>Russian APT Star Blizzard (APT28) now uses the DarkSword iOS exploit kit to target government, finance, and academia, increasing mobile threat exposure.</description><pubDate>Mon, 30 Mar 2026 12:35:23 GMT</pubDate><category>Star Blizzard</category><category>APT28</category><category>Fancy Bear</category><category>Nobelium</category><category>DarkSword</category><category>iOS</category><category>Exploit Kit</category><category>State Sponsored</category><category>Mobile Security</category><category>Spear Phishing</category></item><item><title>Apple iOS Lock Screen Alerts Warn of Active Web-Based Exploits</title><link>https://runtimerebel.com/blog/apple-ios-lock-screen-alerts-warn-of-active-web-based-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-ios-lock-screen-alerts-warn-of-active-web-based-exploits</guid><description>Apple is now issuing direct Lock Screen notifications to warn users on outdated iOS versions about active web-based attacks and the need for urgent updates.</description><pubDate>Fri, 27 Mar 2026 20:14:32 GMT</pubDate><category>Apple</category><category>iOS</category><category>iPadOS</category><category>Web Based Attacks</category><category>Mobile Security</category><category>Patch Management</category></item><item><title>Google Play Protect Advanced Flow for Android Sideloading</title><link>https://runtimerebel.com/blog/google-play-protect-advanced-flow-for-android-sideloading</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-play-protect-advanced-flow-for-android-sideloading</guid><description>Google introduces Advanced Flow to Play Protect, enhancing security for Android sideloading to combat financial fraud and malicious APK installations.</description><pubDate>Sat, 21 Mar 2026 16:09:55 GMT</pubDate><category>Android</category><category>Google Play Protect</category><category>Sideloading</category><category>Mobile Security</category><category>Fintech Fraud</category></item><item><title>Google Android Security: 24-Hour Wait for Unverified Sideloading</title><link>https://runtimerebel.com/blog/google-android-security-24-hour-wait-for-unverified-sideloading</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-android-security-24-hour-wait-for-unverified-sideloading</guid><description>Google introduces a mandatory 24-hour cooling-off period for sideloading unverified Android applications to mitigate malware and financial scams.</description><pubDate>Fri, 20 Mar 2026 12:17:05 GMT</pubDate><category>Android</category><category>Google Play Protect</category><category>Sideloading</category><category>Malware Prevention</category><category>Mobile Security</category></item><item><title>Perseus Android Malware: Technical Analysis of Note-Stealing Tactics</title><link>https://runtimerebel.com/blog/perseus-android-malware-technical-analysis-of-note-stealing-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/perseus-android-malware-technical-analysis-of-note-stealing-tactics</guid><description>Perseus Android malware targets sensitive secrets in user notes by abusing Accessibility Services. Learn how to detect and mitigate this mobile threat.</description><pubDate>Thu, 19 Mar 2026 12:19:37 GMT</pubDate><category>Android</category><category>Perseus</category><category>Credential Theft</category><category>Mobile Security</category><category>Accessibility Services</category></item><item><title>WhatsApp View Once Bypass via Modified Clients - Meta Won&apos;t Patch</title><link>https://runtimerebel.com/blog/whatsapp-view-once-bypass-via-modified-clients-meta-won-t-patch</link><guid isPermaLink="true">https://runtimerebel.com/blog/whatsapp-view-once-bypass-via-modified-clients-meta-won-t-patch</guid><description>A new WhatsApp View Once bypass allows recipients to persist media via modified clients. Meta declines patching, citing client-side enforcement limits.</description><pubDate>Wed, 18 Mar 2026 12:24:28 GMT</pubDate><category>WhatsApp</category><category>View Once Bypass</category><category>Privacy</category><category>Meta</category><category>Mobile Security</category></item><item><title>Android 17 Restricts Accessibility API to Thwart Malware Abuse</title><link>https://runtimerebel.com/blog/android-17-restricts-accessibility-api-to-thwart-malware-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-17-restricts-accessibility-api-to-thwart-malware-abuse</guid><description>Android 17 Beta 2 introduces restrictions on the Accessibility API under Advanced Protection Mode to prevent malware from hijacking system permissions.</description><pubDate>Mon, 16 Mar 2026 08:29:09 GMT</pubDate><category>Android 17</category><category>Accessibility Api</category><category>Google Play Protect</category><category>Aapm</category><category>Mobile Security</category></item><item><title>Smartphone Phishing Bypasses Protections: AI&apos;s Role in Defense</title><link>https://runtimerebel.com/blog/smartphone-phishing-bypasses-protections-ai-s-role-in-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/smartphone-phishing-bypasses-protections-ai-s-role-in-defense</guid><description>Sophisticated Phishing attacks are increasingly bypassing smartphone protections. This analysis explores AI&apos;s potential role in defense and critical user safeguards.</description><pubDate>Fri, 13 Mar 2026 16:21:11 GMT</pubDate><category>Phishing</category><category>Mobile Security</category><category>AI</category><category>Consumer Protection</category><category>Omdia</category></item><item><title>BeatBanker Android Malware: Starlink Impersonation &amp; Device Hijack</title><link>https://runtimerebel.com/blog/beatbanker-android-malware-starlink-impersonation-device-hijack</link><guid isPermaLink="true">https://runtimerebel.com/blog/beatbanker-android-malware-starlink-impersonation-device-hijack</guid><description>New BeatBanker Android malware impersonates the Starlink app on fake app stores to hijack devices, targeting unsuspecting users. Learn detection &amp; mitigation.</description><pubDate>Wed, 11 Mar 2026 00:32:24 GMT</pubDate><category>BeatBanker</category><category>Android</category><category>Malware</category><category>Starlink</category><category>Mobile Security</category><category>Sideloading</category><category>Banking Malware</category></item><item><title>Qualcomm 0-Day and iOS Exploit Chains: Impact &amp; Mitigation Strategies</title><link>https://runtimerebel.com/blog/qualcomm-0-day-and-ios-exploit-chains-impact-mitigation-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/qualcomm-0-day-and-ios-exploit-chains-impact-mitigation-strategies</guid><description>This weekly recap details active exploitation of a Qualcomm zero-day, iOS exploit chains, and emerging &apos;AirSnitch&apos; attack methods. Learn what defenders should prioritize.</description><pubDate>Mon, 09 Mar 2026 16:32:02 GMT</pubDate><category>Qualcomm</category><category>iOS</category><category>Zero-Day</category><category>Exploit Chain</category><category>Airsnitch</category><category>Vibe Coded Malware</category><category>Mobile Security</category></item><item><title>2025 Zero-Day Exploitation Review: Enterprise &amp; OS Targets Dominate</title><link>https://runtimerebel.com/blog/2025-zero-day-exploitation-review-enterprise-os-targets-dominate</link><guid isPermaLink="true">https://runtimerebel.com/blog/2025-zero-day-exploitation-review-enterprise-os-targets-dominate</guid><description>GTIG&apos;s 2025 zero-day review reveals 90 in-the-wild exploits, with a record 48% targeting enterprise tech and a surge in OS vulnerabilities. Includes actor TTPs.</description><pubDate>Thu, 05 Mar 2026 16:27:26 GMT</pubDate><category>Zero-Day</category><category>Threat Intelligence</category><category>Enterprise Security</category><category>Mobile Security</category><category>State Sponsored Exploitation</category><category>Commercial Surveillance Vendors</category><category>PRC Nexus</category><category>Financially Motivated</category><category>CVE-2025-21590</category><category>CVE-2025-0282</category><category>CVE-2025-61882</category><category>CVE-2025-61884</category><category>CVE-2025-8088</category><category>CVE-2025-2783</category><category>CVE-2025-48543</category><category>CVE-2025-27038</category><category>CVE-2025-6558</category><category>CVE-2025-14174</category><category>CVE-2025-40602</category><category>CVE-2025-21043</category><category>CVE-2025-43300</category><category>SonicWall SMA</category><category>Oracle E Business Suite</category><category>WinRAR</category></item><item><title>BadeSaba Calendar App Compromised in State-Linked Propaganda Campaign</title><link>https://runtimerebel.com/blog/badesaba-calendar-app-compromised-in-state-linked-propaganda-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/badesaba-calendar-app-compromised-in-state-linked-propaganda-campaign</guid><description>An analysis of the BadeSaba Calendar hack, where five million Iranian users received propaganda notifications during kinetic strikes, highlighting PsyOps risks.</description><pubDate>Thu, 05 Mar 2026 12:22:03 GMT</pubDate><category>BadeSaba Calendar</category><category>Propaganda Campaign</category><category>Mobile Security</category><category>Push Notification Hack</category><category>Information Warfare</category></item><item><title>Russian Coruna iOS Exploit Kit Targets Global Users — Analysis</title><link>https://runtimerebel.com/blog/russian-coruna-ios-exploit-kit-targets-global-users-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-coruna-ios-exploit-kit-targets-global-users-analysis</guid><description>Security researchers uncover the Coruna iOS exploit kit, a nation-state tool now used in broader campaigns to deliver spyware to mobile devices.</description><pubDate>Thu, 05 Mar 2026 04:40:41 GMT</pubDate><category>Coruna</category><category>iOS Spyware</category><category>APT28</category><category>Google TAG</category><category>iVerify</category><category>Mobile Security</category></item><item><title>Coruna iOS Exploit Kit: Spyware-Grade Threat Targets Crypto</title><link>https://runtimerebel.com/blog/coruna-ios-exploit-kit-spyware-grade-threat-targets-crypto</link><guid isPermaLink="true">https://runtimerebel.com/blog/coruna-ios-exploit-kit-spyware-grade-threat-targets-crypto</guid><description>The sophisticated Coruna iOS exploit kit, leveraging 23 undocumented vulnerabilities, is now deployed in targeted espionage and crypto theft attacks.</description><pubDate>Wed, 04 Mar 2026 20:15:16 GMT</pubDate><category>Coruna</category><category>iOS</category><category>Exploit Kit</category><category>Mobile Security</category><category>Crypto Theft</category><category>Espionage</category><category>Zero-Day</category></item><item><title>NATO Approves Apple iPhone and iPad for Classified Communications</title><link>https://runtimerebel.com/blog/nato-approves-apple-iphone-and-ipad-for-classified-communications</link><guid isPermaLink="true">https://runtimerebel.com/blog/nato-approves-apple-iphone-and-ipad-for-classified-communications</guid><description>Apple iOS and iPadOS devices added to NATO’s NIAPC, authorizing their use for handling NATO Restricted level classified information and communications.</description><pubDate>Thu, 26 Feb 2026 20:15:44 GMT</pubDate><category>NATO</category><category>Apple</category><category>iOS</category><category>iPadOS</category><category>NIAPC</category><category>Mobile Security</category><category>Classified Information</category></item></channel></rss>