< ciso
brief />
Tag Banner

All news with #mobile security tag

246 articles · page 2 of 13

ToxicPanda 2.0 and GoldDigger Expand Global Targeting

🛡️ Zimperium zLabs and IBM Trusteer detail updated Android banking trojans: ToxicPanda 2.0 and a new GoldDigger campaign. ToxicPanda now includes 167 remote commands, enhanced PIN-harvesting for over 140 banking and crypto apps, and ADB-based escalation techniques. GoldDigger leverages sophisticated packing and accessibility abuse to drive fraud, with active campaigns in South Africa and the U.K.
read more →

Manic Android malware steals data via nearby devices

🛡️ Manic is a multifaceted Android malware active since at least February that combines spyware, banking fraud, and remote-control features, primarily targeting users in Ukraine and across Europe. It abuses Android Accessibility and notification access to capture PINs, SMS codes, credentials, files, and location, and uses transparent overlays to log keypad input. When direct C2 access is unavailable, Manic can exfiltrate encrypted data through nearby compromised devices over Wi‑Fi Direct or Bluetooth, using multi‑hop relays. Users should avoid installing APKs from untrusted sources, deny Accessibility permissions to untrusted apps, and run Play Protect scans.
read more →

ToxicPanda 2.0 Expands Targeting of Financial Apps

🔒 Security researchers at zLabs discovered ToxicPanda 2.0, an Android banking Trojan that now targets 140 banking and cryptocurrency apps and uses overlay-based credential theft against 349 financial institutions. The variant abuses the Android Accessibility Service to enable wireless debugging and attempts to obtain shell access via ADB, bypassing runtime prompts and enforcing persistence. New capabilities include stealing device lock credentials through screen overlays. Recommended defenses include blocking sideloading, treating accessibility grants as privileged events, and alerting on developer options or wireless debugging via MDM.
read more →

UNISOC modem isolation flaw risks kernel RCE

🔒 SSD Secure Disclosure researchers revealed a UNISOC modem firmware vulnerability that lets modem-level code execution reach Android kernel space by exploiting improper isolation between modem and kernel memory. The team demonstrated a full exploit chain, including a VoLTE-triggered final stage, and tested it on devices such as the Realme C33. No vendor firmware fix from UNISOC has been reported, leaving OEM updates as the primary mitigation.
read more →

Unisoc modem exploit chain risks Android kernel

🔒 SSD Secure Disclosure detailed a two-stage exploit chain that yields full Android kernel access via Unisoc modem firmware when a victim answers a malicious VoLTE video call. The advisory, published August 17, 2026, follows an earlier March 2026 remote code execution disclosure and requires control of a private 4G network plus a modem foothold. Affected chipsets include Unisoc T606, T612, and T7250 in multiple device brands, and no vendor patch is yet available.
read more →

QR code phishing risks and corporate defenses

🛡️ QR codes have become ubiquitous in daily life and are increasingly used in email-based attacks known as "quishing." These attacks encode malicious URLs in QR images to bypass traditional email filters and move victims from managed corporate devices to less-protected personal phones. Threat actors exploit brand impersonation and urgency to harvest credentials, bypass app stores, push fraudulent payments, or capture MFA tokens. Organizations should combine user training, email and mobile security, phishing-resistant MFA, MDM, and incident response planning to reduce risk.
read more →

Apple Alerts Users of Mercenary Spyware in 110 Countries

🔔 Apple has sent fresh threat notifications to an unspecified number of customers it suspects were targeted by mercenary spyware in 110 countries, adding to over 150 countries notified since late 2021. The company characterizes these as high-confidence alerts for individuals likely singled out due to their roles, such as journalists, activists, politicians, and diplomats. Apple declined to attribute the attacks to specific actors and cautioned that sharing diagnostic details could help attackers refine tactics. It provides notifications via iPhone alerts, email from "threat-notifications@email.apple[.]com," and a banner on the user's Apple Account page, and recommends security steps including updating software, enabling 2FA, and using Lockdown Mode.
read more →

Apple issues new threat notifications over spyware

🔔 Apple sent a fresh batch of threat notifications on August 13 alerting select iPhone users to suspected mercenary spyware attacks. These high-confidence alerts, issued since 2021, target a small set of users such as journalists and activists and do not name specific spyware or attribution. Apple warns users to verify genuine messages via account.apple.com and avoid links or requests for credentials, recommending Lockdown Mode and expert help if affected.
read more →

AmnesiaStealer targets macOS Chromium sessions

🛡️ Researchers disclosed a new Rust-based macOS infostealer, AmnesiaStealer, delivered via a fake GitHub “Download for macOS” page that tricks users into pasting a Base64 command into Terminal. The multi-stage dropper retrieves a password-protected ZIP and executes a Rust payload that harvests Keychain items, browser data, Apple Notes, Telegram, and files, while using the captured system password for privileged access. A second-stage remote_stream module enables operator-driven browser control over Chromium-family browsers via the Chrome DevTools Protocol to steal live sessions and evade detection.
read more →

WindRelay NFC Android Relay Malware Emerges

🔒 WindRelay is a new Android NFC relay malware deployed alongside the SpyNote RAT to enable contactless payment fraud. First observed in August 2025, it captures live card data via NFC and streams it in real time to fraudsters. Attackers use personalized social engineering and remote access to sideload the NFC reader covertly, turning the victim's phone into a payment proxy. The scheme pairs a victim-side reader with an attacker-side emulator and a shared C2 channel to relay EMV commands and enable card-present cashouts.
read more →

WhatsApp launches on-device scam alert beta

🔔 WhatsApp has started a limited beta for an optional Scam Alert that runs an on-device machine learning model to warn users of likely scam messages. The feature analyzes linguistic signals and conversational structure for messages from non-contacts, displaying a chat warning that suggests blocking, reporting, or continuing. No message content or the model leaves the device; users can mark chats as trusted or opt to share recent messages to improve accuracy. Scam Alert complements existing security updates aimed at preventing account takeover and spyware attacks.
read more →

Malicious SIMs can remotely commandeer cellular modules

🔒 Researchers from the University of Birmingham and Fuzzware demonstrate that a hostile SIM card can use the SIM's standard proactive commands (RUN AT) to instruct modems to execute AT commands, enabling code execution on affected devices. They tested 26 devices and found nine accepted the command, including several Quectel modules in EV chargers, industrial routers, and car telematics units. Vendors including Qualcomm and Quectel have responses in progress, but no public advisories have been broadly published.
read more →

Prosecution Over Phone Wipe Raises Border Search Questions

🔐 The prosecution of an American who provided a code that wiped his GrapheneOS-powered Pixel phone highlights tensions at the U.S. border. The feature in GrapheneOS deliberately erases device contents when a specific passcode is entered, and the defendant’s phone ran this OS. The case probes constitutional protections at the border and the government’s stance that border zones are not subject to the same rights until entry is authorized. GrapheneOS maintains the feature is legal and constitutionally protected.
read more →

Source Code Leak Exposes Flying Eagle Android RAT

🛡️ Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels, with Hunt.io and researcher NetAskari tracing matching control panels and certificates to 170 internet servers. The toolkit is linked to a fake Chinese Public Security app that can capture payments, keystrokes, record screens, use cameras, and display phishing prompts for finance and government services. Chinese authorities urged removal, password changes, and reporting while investigators note the server count does not prove active infections.
read more →

Managing risks of AI-powered smart glasses in enterprises

🕶️ As AI-powered smart glasses from Samsung and others enter workplaces, CISOs and IT leaders must weigh enterprise restrictions against enforcement and accessibility challenges. Device settings are controlled by individual wearers and AI guardrails can fail, making policy enforcement difficult. Experts recommend tiered policies, targeted bans in sensitive spaces, and robust user education rather than blanket prohibitions to balance security and accessibility.
read more →

Google phone verification and RCS privacy risks

📱 Google’s phone number verification notifies users when their SIM is confirmed and links that number to all Google accounts on the device. The feature supports RCS messaging and fraud protection but can surface hidden verification SMS or metadata collection. Verification runs by default, may use carrier APIs or hidden SMS, and can attach identifiers like ICCID/IMSI. Users can opt out per account but may lose RCS and risk re-enablement.
read more →

LG to ban residential proxies from smart TV apps

🛡️ LG Electronics USA will suspend smart TV apps that convert televisions into always-on residential proxy nodes, following research showing over 42% of webOS apps contain such proxy SDKs. The company is working with developers to remove the option and will suspend noncompliant apps, while tightening its app evaluation process. Spur’s research also found similar proxy components in Samsung’s Tizen apps, and proxy providers such as Bright Data were commonly identified. LG emphasized ongoing platform reviews to protect users.
read more →

Gemini lock-screen flaw lets messages be sent

🔒 Google is fixing a vulnerability that lets an attacker with physical access to a locked Android 16 device use Gemini to send SMS and WhatsApp messages without entering a PIN. Reports since May show the bypass exploits Gemini's Deep Research and a specific multi-touch gesture to circumvent authentication. Google says a patch is imminent; meanwhile, users should restrict Gemini's lock-screen access to limit exposure.
read more →

Smashing Security podcast episode 476 recap

🎧 In episode 476 of the Smashing Security podcast Graham Cluley and Geoff White discuss Geoff's new podcast season on the Conti ransomware gang, personal scam attempts, and a startling prank targeting e-rickshaws in India. They describe how an app called BatBMS — intended for battery management — has been misused to remotely disable electric rickshaws, creating safety and livelihood risks for drivers. The hosts also cover sponsors and lighthearted anecdotes about smartphone pranks.
read more →

RedHook Android Malware Abuses Wireless ADB

🛡️ Researchers at Group-IB describe a new RedHook Android malware variant that abuses Wireless ADB to gain shell-level (UID 2000) privileges without a wired computer connection. The malware tricks victims into granting Accessibility permissions to enable Developer Options and Wireless Debugging, retrieves the pairing code, and connects via the loopback interface. It leverages a Shizuku-based framework to execute shell commands, silently install apps, modify protected settings, and perform RAT functions like screen streaming and keystroke interception. Distribution relies on social engineering directing victims to fake Play stores; users are urged to install apps only from official sources, review permissions, and enable Play Protect.
read more →