home.social

#mobile-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mobile-security, aggregated by home.social.

fetched live
  1. Android's new Advanced Protection Mode includes Intrusion Logging, a feature designed specifically to capture events relevant to security and related to possible intrusions, with the explicit goal of enabling consensual forensic analysis. This new feature is poised to significantly improve the ability of civil society investigators to identify and investigate sophisticated attacks on Android. securitylab.amnesty.org/latest #mobilesecurity

  2. Android's new Advanced Protection Mode includes Intrusion Logging, a feature designed specifically to capture events relevant to security and related to possible intrusions, with the explicit goal of enabling consensual forensic analysis. This new feature is poised to significantly improve the ability of civil society investigators to identify and investigate sophisticated attacks on Android. securitylab.amnesty.org/latest #mobilesecurity

  3. Luma is here!

    This week at the inaugural @owasp MAScon in Vienna, NowSecure security researcher @oleavr unveiled Luma: the official #Frida GUI. Persistent sessions, an interactive REPL, frida-trace, and real-time collaborative editing, all in one native app across macOS, iOS, Linux, and Windows.

    Luma is free and open source. NowSecure is proud to sponsor the project and contribute engineering resources to its development.

    Huge congratulations to @oleavr and the entire Frida team on an incredible launch and what this release represents for the community: loom.ly/KRIF_LI

    #Luma #ReverseEngineering #MobileSecurity #DeveloperTools #OpenSource #NowSecure #OWASPMAScon

  4. Luma is here!

    This week at the inaugural @owasp MAScon in Vienna, NowSecure security researcher @oleavr unveiled Luma: the official #Frida GUI. Persistent sessions, an interactive REPL, frida-trace, and real-time collaborative editing, all in one native app across macOS, iOS, Linux, and Windows.

    Luma is free and open source. NowSecure is proud to sponsor the project and contribute engineering resources to its development.

    Huge congratulations to @oleavr and the entire Frida team on an incredible launch and what this release represents for the community: loom.ly/KRIF_LI

    #Luma #ReverseEngineering #MobileSecurity #DeveloperTools #OpenSource #NowSecure #OWASPMAScon

  5. Your phone is the primary target for modern hackers. It holds more sensitive data than your laptop, so stop treating it like a secondary device. Time to lock down your mobile perimeter before you become the next statistic. 🛡️💻

    #CyberSecurity #MobileSecurity #InfoSec

    bdking71.wordpress.com/2026/06

  6. Your phone is the primary target for modern hackers. It holds more sensitive data than your laptop, so stop treating it like a secondary device. Time to lock down your mobile perimeter before you become the next statistic. 🛡️💻

    #CyberSecurity #MobileSecurity #InfoSec

    bdking71.wordpress.com/2026/06

  7. FCC proposal would require telecoms to collect government ID, name, and address for all mobile customers under “Know-Your-Customer” rules. 📵
    Privacy advocates warn it could effectively end anonymous “burner phones,” increasing risks for journalists, survivors, and marginalized users. 🔐

    🔗 cnet.com/news/privacy/if-the-f

    #TechNews #FCC #Privacy #Surveillance #Telecom #DigitalRights #CyberSecurity #DataPrivacy #CivilLiberties #Encryption #Policy #MobileSecurity #Mobile #USA #US #Trump

  8. FCC proposal would require telecoms to collect government ID, name, and address for all mobile customers under “Know-Your-Customer” rules. 📵
    Privacy advocates warn it could effectively end anonymous “burner phones,” increasing risks for journalists, survivors, and marginalized users. 🔐

    🔗 cnet.com/news/privacy/if-the-f

    #TechNews #FCC #Privacy #Surveillance #Telecom #DigitalRights #CyberSecurity #DataPrivacy #CivilLiberties #Encryption #Policy #MobileSecurity #Mobile #USA #US #Trump

  9. GrapheneOS notes Android 17 “sort of” support, reflecting early compatibility work rather than a fully stable rollout across devices. 📱
    It tracks Android 17 privacy upgrades like stronger permissions and encryption while maintaining its hardened AOSP-based security model. 🔐

    @privacyguides
    @GrapheneOS

    🔗 privacyguides.org/news/2026/06

    #TechNews #GrapheneOS #Android #Privacy #Security #OpenSource #FOSS #Mobile #MobileSecurity #Encryption #AOSP #CyberSecurity #DataProtection #Linux #UserPrivacy

  10. GrapheneOS notes Android 17 “sort of” support, reflecting early compatibility work rather than a fully stable rollout across devices. 📱
    It tracks Android 17 privacy upgrades like stronger permissions and encryption while maintaining its hardened AOSP-based security model. 🔐

    @privacyguides
    @GrapheneOS

    🔗 privacyguides.org/news/2026/06

    #TechNews #GrapheneOS #Android #Privacy #Security #OpenSource #FOSS #Mobile #MobileSecurity #Encryption #AOSP #CyberSecurity #DataProtection #Linux #UserPrivacy

  11. Looking forward to #OWASP Global AppSec EU and the inaugural #MAScon next week. Excited for the opportunity to learn from researchers and practitioners who are pushing mobile security forward.

    Check out some of the sessions: loom.ly/qC3L65o

    @owasp #OWASPGlobalAppSec #MobileApps #MobileSecurity #SecurityResearch

  12. Looking forward to #OWASP Global AppSec EU and the inaugural #MAScon next week. Excited for the opportunity to learn from researchers and practitioners who are pushing mobile security forward.

    Check out some of the sessions: loom.ly/qC3L65o

    @owasp #OWASPGlobalAppSec #MobileApps #MobileSecurity #SecurityResearch

  13. Google is rolling out a new opt-in feature in Android that aims to help security researchers investigate spyware attacks. The feature is called “Intrusion Logging” and is part of Android’s Advanced Protection Mode, which Google launched last year.. Advanced Protection Mode is designed to counter government spyware attacks and police forensic devices that try to extract data from a person’s phone. techcrunch.com/2026/05/12/goog #mobilesecurity

  14. Google is rolling out a new opt-in feature in Android that aims to help security researchers investigate spyware attacks. The feature is called “Intrusion Logging” and is part of Android’s Advanced Protection Mode, which Google launched last year.. Advanced Protection Mode is designed to counter government spyware attacks and police forensic devices that try to extract data from a person’s phone. techcrunch.com/2026/05/12/goog #mobilesecurity

  15. 🚨 CRITICAL: CVE-2026-48745 in traccar-client <=9.7.19 allows silent GPS data redirection via crafted deep links — no user prompt, persists after restart. Update to 9.7.20 now! radar.offseq.com/threat/cve-20 #OffSeq #Infosec #MobileSecurity #CVE202648745

  16. Users worried their phone has a virus get a quick guide: signs, checks, cleanup, and prevention. Rapid battery drain, unknown apps, pop-ups, data spikes — act fast. Read more: proton.me/blog/phone-virus 🔍📱🛡️ #MobileSecurity #CyberSafety #Android #iPhone

  17. Users worried their phone has a virus get a quick guide: signs, checks, cleanup, and prevention. Rapid battery drain, unknown apps, pop-ups, data spikes — act fast. Read more: proton.me/blog/phone-virus 🔍📱🛡️ #MobileSecurity #CyberSafety #Android #iPhone

  18. I was tired of digging through endless random cybersecurity lists, so naturally I built another random cybersecurity list - just cleaner, prettier and actually organized.

    Hack Hub is a curated directory of useful security resources.

    hackhub.fyi

    #CyberSecurity #InfoSec #Hacking #EthicalHacking #Pentesting #RedTeam #BlueTeam #DFIR #OSINT #ThreatIntel #MalwareAnalysis #BugBounty #CloudSecurity #MobileSecurity #OpenSource #SecurityTools #SecurityResearch #Linux #Hackers #Tech

  19. I was tired of digging through endless random cybersecurity lists, so naturally I built another random cybersecurity list - just cleaner, prettier and actually organized.

    Hack Hub is a curated directory of useful security resources.

    hackhub.fyi

    #CyberSecurity #InfoSec #Hacking #EthicalHacking #Pentesting #RedTeam #BlueTeam #DFIR #OSINT #ThreatIntel #MalwareAnalysis #BugBounty #CloudSecurity #MobileSecurity #OpenSource #SecurityTools #SecurityResearch #Linux #Hackers #Tech

  20. Mobile apps are not “just apps” anymore!

    They’re connected platforms handling identities, payments, sessions, APIs, and critical business workflows.

    In this special episode of @sharedsecurity I talked with Joel DeStefano, Senior Product Manager at Guardsquare, about the modern mobile application threat landscape and why organizations need to rethink mobile app security.

    We covered runtime manipulation, API abuse, account takeover, fake apps, overlays, reverse engineering, iOS vs Android risk, AI-assisted attacks, and why backend-only security is not enough.

    Learn more about Guardsquare:guardsquare.com

    Watch on YouTube:
    youtu.be/C5eWp9IB30U

    Listen wherever you like to get your podcasts:
    sharedsecurity.net/2026/06/10/

    #podcast #cybersecurity #mobilesecurity

  21. Mobile apps are not “just apps” anymore!

    They’re connected platforms handling identities, payments, sessions, APIs, and critical business workflows.

    In this special episode of @sharedsecurity I talked with Joel DeStefano, Senior Product Manager at Guardsquare, about the modern mobile application threat landscape and why organizations need to rethink mobile app security.

    We covered runtime manipulation, API abuse, account takeover, fake apps, overlays, reverse engineering, iOS vs Android risk, AI-assisted attacks, and why backend-only security is not enough.

    Learn more about Guardsquare:guardsquare.com

    Watch on YouTube:
    youtu.be/C5eWp9IB30U

    Listen wherever you like to get your podcasts:
    sharedsecurity.net/2026/06/10/

    #podcast #cybersecurity #mobilesecurity

  22. 📰 Mobile Banking Malware Surges 360% as Sophisticated Trojans Target 1,243 Financial Brands

    📱 Mobile banking is under siege! Attacks are up 3.6x, with new trojans like Sturnus using 'blackout' modes to steal money while your screen is off. 1,243 financial brands are being targeted globally. 💸 #MobileSecurity #Malware #Banking

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/mo

  23. Reverse engineered the Mintegral MBridge SDK (common in gaming APKs with aggressive adv).
    The SDK assembles exfiltration endpoints at runtime via AES/XOR decryption + Android IPC Intents. No hardcoded domain in the binary. MobSF classifies the package as Advertisement and stops there. Knox and Play Protect see legitimate inter-process communication between signed components — nothing to flag.
    Extracted 6 C2/collection domains. Loaded them into AegisDNS as a SIGINT feed.
    Both Knox and Play Protect: no block, no alert.
    AegisDNS: all 6 blocked at resolution.
    The IPC obfuscation chain is effective against every on-device analysis layer. It stops at port 53 — the one operation the OS cannot perform inside the obfuscation boundary.
    Full write-up with architecture, the structural argument for perimeter DNS vs MTD, and operational trade-offs (block rate, DoH bypass mitigation via iptables, PCRE2/FFI trade-off):

    cariagiovannib.wordpress.com/2

    #dns #android #reverseengineering #infosec #mobilesecurity

  24. Reverse engineered the Mintegral MBridge SDK (common in gaming APKs with aggressive adv).
    The SDK assembles exfiltration endpoints at runtime via AES/XOR decryption + Android IPC Intents. No hardcoded domain in the binary. MobSF classifies the package as Advertisement and stops there. Knox and Play Protect see legitimate inter-process communication between signed components — nothing to flag.
    Extracted 6 C2/collection domains. Loaded them into AegisDNS as a SIGINT feed.
    Both Knox and Play Protect: no block, no alert.
    AegisDNS: all 6 blocked at resolution.
    The IPC obfuscation chain is effective against every on-device analysis layer. It stops at port 53 — the one operation the OS cannot perform inside the obfuscation boundary.
    Full write-up with architecture, the structural argument for perimeter DNS vs MTD, and operational trade-offs (block rate, DoH bypass mitigation via iptables, PCRE2/FFI trade-off):

    cariagiovannib.wordpress.com/2

    #dns #android #reverseengineering #infosec #mobilesecurity

  25. Prywatność i cyberbezpieczeństwo to nie są hobbystyczne fanaberie dla ludzi w foliowych czapeczkach. Skompromitowane urządzenie mobilne to bezpośrednie zagrożenie dla Twojego życia osobistego, finansów i spokoju psychicznego.

    Właśnie ruszyłem ze swoim blogiem, a to mój pierwszy wpis:
    🔗 meridian.bearblog.dev/droga_do

    Opisuję w nim historię z ukrytym korporacyjnym MDM na moim telefonie i to, jak techniki Incident Response oraz przejście na GrapheneOS pozwoliły mi odzyskać kontrolę.

    To mój debiut, dlatego bardzo zależy mi na Waszym feedbacku. Co myślicie o tym tekście? Dajcie znać w komentarzach, czy taka tematyka Was interesuje i czy chcecie kolejne wpisy o konfiguracji i hardeningu GrapheneOS! 🛡️📱

    #GrapheneOS #Cybersecurity #Privacy #Prywatnosc #Bezpieczenstwo #FOSS #MobileSecurity #PlFediverse #Blog

  26. Prywatność i cyberbezpieczeństwo to nie są hobbystyczne fanaberie dla ludzi w foliowych czapeczkach. Skompromitowane urządzenie mobilne to bezpośrednie zagrożenie dla Twojego życia osobistego, finansów i spokoju psychicznego.

    Właśnie ruszyłem ze swoim blogiem, a to mój pierwszy wpis:
    🔗 meridian.bearblog.dev/droga_do

    Opisuję w nim historię z ukrytym korporacyjnym MDM na moim telefonie i to, jak techniki Incident Response oraz przejście na GrapheneOS pozwoliły mi odzyskać kontrolę.

    To mój debiut, dlatego bardzo zależy mi na Waszym feedbacku. Co myślicie o tym tekście? Dajcie znać w komentarzach, czy taka tematyka Was interesuje i czy chcecie kolejne wpisy o konfiguracji i hardeningu GrapheneOS! 🛡️📱

    #GrapheneOS #Cybersecurity #Privacy #Prywatnosc #Bezpieczenstwo #FOSS #MobileSecurity #PlFediverse #Blog

  27. Android 16 introduced a bug that allows a malicious app to send traffic outside the VPN tunnel, including with “Always-On VPN” + “Block connections without VPN” turned on. At the time of publishing, this affects all VPN apps. mullvad.net/en/blog/2026/5/12/ #mobilesecurity

  28. Android 16 introduced a bug that allows a malicious app to send traffic outside the VPN tunnel, including with “Always-On VPN” + “Block connections without VPN” turned on. At the time of publishing, this affects all VPN apps. mullvad.net/en/blog/2026/5/12/ #mobilesecurity

  29. Google Gemini on Android Exposed to Notification-Based Hijacking

    Researchers have uncovered a vulnerability in Google Gemini on Android that allows hackers to hijack the assistant using a single hostile notification, no malicious app required. This shocking exploit lets anyone able to push a notification to a device deliver a payload and take control.

    osintsights.com/google-gemini-

    #AndroidSecurity #GoogleGemini #NotificationbasedHijacking #EmergingThreats #MobileSecurity

  30. Mobile malware is becoming a billing engine.
    Kern Smith of Zimperium explains how Android fraud campaigns silently subscribe victims to premium SMS services, intercept OTPs, and monetize users through carrier billing systems.
    🔶 Carrier-specific targeting
    🔶 OTP interception
    🔶 Silent subscriptions
    🔶 Automated monetization

    Read the full discussion:
    technadu.com/when-your-phone-i

    #MobileSecurity #Android #SMSFraud #CyberSecurity #ThreatResearch #Malware

  31. 🔍 HIGH-severity buffer overflow (CVE-2026-25277) in Qualcomm Snapdragon 8 Gen 2/3 & Elite. Exploitable locally for full device compromise. No patch yet — restrict local access & monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Qualcomm #MobileSecurity

  32. Data Breach Claimed on Trump Mobile Site

    Over 27,000 users' personal data may have been exposed on Donald Trump's campaign mobile site. Find out what happened and who is affected.

    #TrumpCampaign, #DataBreach, #Privacy, #MobileSecurity, #Election2026

    newsletter.tf/trump-campaign-m

  33. Personal data for 27,000 people might have been exposed on the Trump campaign mobile site. This is a significant number of individuals affected by a potential data leak.

    #TrumpCampaign, #DataBreach, #Privacy, #MobileSecurity, #Election2026
    newsletter.tf/trump-campaign-m

  34. CW: Human+AI

    I have been thinking about how much we trust our phones with our most sensitive data. Spyware is getting quieter, but it always leaves a trail. If your battery is draining fast or your data usage is spiking, it might be time to check for hidden apps. I found a great guide on how to detect spyware on your phone and stay secure.

    gwizit.com/go/pG3Ssgp

    #MobileSecurity #PrivacyTips #CyberAware

  35. Xiaomi’s HyperOS 4 next-year drops a privacy‑screen feature that limits view angles to protect your data. Following Samsung’s model, the tech blocks unapproved looks. Stay tuned for its rollout. #PrivacyTech #MobileSecurity

    🚩 #TechPrivacy #Innovation #PrivacyTech #MobileSecurity

  36. Laut aktuellen Berichten haben Cyberangriffe auf Mobilgeräte 2026 weltweit einen wirtschaftlichen Schaden von 442 Milliarden Euro verursacht. 86 % aller Phishing-Kampagnen sollen inzwischen KI-gesteuert sein, das entspricht rund 3,4 Milliarden betrügerischer Nachrichten täglich. Besonders auffällig: Banking-Trojaner wie „Mamont" und neue NFC-Angriffsvektoren zeigen, wie gezielt mobile Geräte heute angegriffen werden.
    #Cybersecurity #MobileSecurity #Phishing #DigitaleSicherheit #OpenWeb

  37. Laut aktuellen Berichten haben Cyberangriffe auf Mobilgeräte 2026 weltweit einen wirtschaftlichen Schaden von 442 Milliarden Euro verursacht. 86 % aller Phishing-Kampagnen sollen inzwischen KI-gesteuert sein, das entspricht rund 3,4 Milliarden betrügerischer Nachrichten täglich. Besonders auffällig: Banking-Trojaner wie „Mamont" und neue NFC-Angriffsvektoren zeigen, wie gezielt mobile Geräte heute angegriffen werden.
    #Cybersecurity #MobileSecurity #Phishing #DigitaleSicherheit #OpenWeb

  38. Apple Thwarts $2.2bn in App Store Fraud with AI-Driven Defenses

    Apple's AI-powered defenses have successfully blocked a whopping $2.2 billion in App Store fraud over the past year, and a staggering $11.2 billion over six years, protecting consumers and businesses from malicious actors.

    osintsights.com/apple-thwarts-

    #AppStoreFraud #AidrivenDefenses #EmergingThreats #MobileSecurity #FinancialFraud

  39. Apple Foils $11 Billion in App Store Fraud Over Six Years

    Apple's vigilant efforts have paid off, blocking a whopping $11 billion in App Store fraud over the past six years, with a staggering $2.2 billion foiled in 2025 alone. The tech giant's winning combination of human review and cutting-edge tech has kept scammers at bay.

    osintsights.com/apple-foils-11

    #AppStoreFraud #EmergingThreats #FinancialServices #FraudPrevention #MobileSecurity

  40. Stolen phones - and specifically iPhones - have robust anti-theft protections. They are worthless once they're flagged - locked to their owner. So why are millions still being stolen every year?
    In this paper, we uncover a thriving underground marketplace focused on unlocking stolen phones. It is powered by:

    Lookalike domains impersonating Apple, Xiaomi, Samsung and other brands
    Smishing campaigns targeting device owners
    Pay‑as‑you‑go “unlocking” tools sold on Telegram
    By pivoting on DNS data, we identified 10,000+ malicious domains and a growing ecosystem turning locked devices into profit at scale.

    👉 Read how this supply chain works—from theft to resale—and why it’s growing fast. infoblox.com/blog/threat-intel

    #ThreatIntel #CyberSecurity #Phishing #MobileSecurity #iOS #Smishing #dns #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel #threatintelligence #cybercrime  #infosec #infoblox #infobloxthreatintel

  41. Most people use their smartphones every day without realizing how risky some habits have become in 2026.

    Here are 10 things you should stop doing on your phone right now 👇📱

    techputs.com/things-you-should

    #Technology #PhoneTips #MobileSecurity #PrivacyTips #CyberAwareness #DigitalLife #TechPuts

  42. Most people think their phone data is safe until it’s too late. I just published a guide on common scenarios where you might lose your data and how to prevent it.

    Read it here: blog.keepita.com/phone-data-sa

    Got a scenario I missed? Drop a comment! If it’s good, I’ll add it to the article and credit you/your profile personally. Let’s build the ultimate safety guide together. 🤝

    #DataSafety #CyberSecurity #iPhone #Samsung #Android #Keepita #TechTips #Privacy #Backup #MobileSecurity #Infosec

  43. Your phone just became its own bodyguard.

    AmnyX’s new Intruder Alert 📸
    3 failed password attempts = instant email to you:
    ✓ Date & Time
    ✓ GPS Location
    ✓ IP Address
    ✓ Photo of the intruder

    Because peace of mind should be automatic.
    @AmnyX
    #AmnyX #IntruderAlert #MobileSecurity #DataPrivacy #SmartSecurity #TechNews

  44. Quick thought experiment. Pull out your phone, look at your lock screen, and ask yourself who else is reading those notification previews. The answer is stranger than you think.

    EFF just laid out what most people don't realize: push notifications usually route through Apple or Google servers before they hit your device, often with content visible in the clear. Then they get written to a local notification database that doesn't always get wiped when you swipe the alert away or even when you uninstall the app. 404 Media reported the FBI has pulled deleted Signal message text out of that database using standard forensic tools. Signal. The app you installed specifically because you didn't want this.

    🔐 Apple and Google now require a court order for push notification data, but Apple's transparency report still shows hundreds of users handed over
    📱 Lock screen previews are a free read for anyone who picks up your phone, including at a border crossing or traffic stop
    🧹 Uninstalling an app does not guarantee its notification history goes with it, and we don't know what gets backed up to iCloud or Google
    🛠️ Signal's notification setting "No Name or Content" is a 30-second fix that closes the easiest leak

    For the security folks, this is a useful reminder that end-to-end encryption ends at the endpoint, and the endpoint includes a SQLite file most users have never heard of. For the executives, this is the reason your travel security policy for high-risk regions should say more than "use Signal." The default settings on a stock iPhone leak more than the app you chose to protect you.

    eff.org/deeplinks/2026/04/how-
    #Privacy #Cybersecurity #MobileSecurity #security #cloud #infosec