Tag: mobile
All entries tagged mobile.
- CVE-2026-58704, Google Pixel: zero-click privilege escalation out of the cellular modem sandbox, exploited in limited, targeted attacks
- WeWorm: an AI-assisted zero-click worm demonstrates full WeChat account takeover on Android and iOS from a single unanswered call
- WindRelay, a purpose-built Android NFC-relay malware installed silently by a companion remote-access trojan during the fraud call itself, with per-victim app names carrying the victim's own name
- CERT-UA: Sandworm subcluster UAC-0145 pairs ClickFix fake-CAPTCHA with Ethereum-smart-contract C2 resolution and a Signal-delivered Android backdoor
- RedHook Android RAT abuses ADB Wireless Debugging to self-grant shell (uid 2000) privileges without an exploit
- ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers
- Citizen Lab: a European Parliament spyware-inquiry member was himself infected twice with Pegasus
- Citizen Lab: Cellebrite UFED used by Russian authorities three months after the vendor's Russia pull-out
- FBI/CISA: Russian intelligence now phishing Signal Backup Recovery Keys for persistent account takeover
- usbliter8, a permanent SecureROM boot-chain exploit for Apple A12/A13 silicon
- Zimperium: Rokarolla Android banking trojan targets 217 apps with full device takeover
- Meta files contempt complaint against NSO Group over fresh WhatsApp spyware phishing
- FIFA World Cup 2026 pre-event threat cluster: Android banking trojans in pirated streaming apps, plus a 13,000-domain fraud layer, ahead of the 11 June kick-off
- Enclave: a single debug flag left on in six Microsoft 365 Android apps allowed silent OAuth-token theft
- CVE-2025-48595, Android Framework: actively-exploited integer-overflow privilege escalation
- Italy's low-cost commercial spyware economy: Accessibility-API abuse as the cheap alternative to zero-days
- "Signal Support" impersonation phishing harvests cloud-backup recovery keys from high-value users
- WatchGuard documents Grandoreiro's Delphi-DLL-side-loading + WebSocket/STUN C2 against Portuguese & Spanish banks; ESET maps parallel Android BTMOB MaaS
- Wiz CIRT names JINX-0164, LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD
- TrickMo "TrickMo C", Android banking trojan migrates C2 to The Open Network blockchain, adds SOCKS5 / SSH device-as-pivot
- SMS-blaster smishing establishing itself in Switzerland, portable IMSI-catchers force 2G downgrade, bypass operator SMS filtering