home.social

#mobilesecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mobilesecurity, aggregated by home.social.

  1. Android Malware Mantax Otax Encrypts Devices, Steals Data, and Harasses Victims

    Beware of Mantax Otax, a sneaky Android malware that's encrypting devices, swiping sensitive data, and even harassing victims - all thanks to clever tricks by Indonesian operators who are using sideloaded APKs to spread the threat.

    osintsights.com/android-malwar

    #AndroidMalware #MantaxOtax #EmergingThreats #MobileSecurity #MalwareOperations

  2. Bedtime Bug Hunting at BSides Belfast 🐛

    A magic-link login, one badly timed Back button and a very unexpected result.

    No fancy tools—just curiosity, testing assumptions and thinking like a real user.

    Thanks to everyone who came along and to the BSides Belfast team. Recording coming soon.

    bsidesbelfast.org/schedule/

    #BSidesBelfast #CyberSecurity #AppSec #MobileSecurity #ResponsibleDisclosure

  3. Google Play Exposed to Deceptive App Abuse

    A sneaky app, "Vice Streets: Open World", racked up over 1 million downloads on Google Play without a single public review or rating, taking advantage of the platform's Early Access feature. This feature, meant to help developers gather feedback, can also shield them from criticism - and warn signs - that might scare off users.

    osintsights.com/google-play-ex

    #DeceptiveApp #GooglePlay #MobileSecurity #EmergingThreats #AppAbuse

  4. Gigabud Trojan Exploits Android Work Profiles to Evade Banking App Malware Checks

    The sneaky Gigabud Trojan is exploiting Android work profiles to slip past banking app security checks, allowing it to secretly tamper with transactions and drain accounts. By creating a separate work profile, Gigabud can hide in plain sight and facilitate fraudulent payments that appear legitimate.

    osintsights.com/gigabud-trojan

    #AndroidBankingMalware #GigabudTrojan #RemoteAccessTrojan #Indonesia #MobileSecurity

  5. MantaxOtax Malware Targets Android Devices with Ransomware and Spyware

    Meet MantaxOtax, a sneaky malware that's putting Android users on high alert with its potent mix of ransomware and spyware, allowing hackers to hold your device hostage and snoop on your personal life. This hybrid threat can encrypt your files, track your location, and even siphon off sensitive info like contacts, call logs, and…

    osintsights.com/mantaxotax-mal

    #AndroidMalware #Ransomware #Spyware #EmergingThreats #MobileSecurity

  6. Calif demonstrated a zero-click worm that takes over WeChat accounts on iOS and Android via an incoming call, with no user interaction. It requires the caller to be a contact, enabling self-propagation through compromised address books. Tencent says the vector is now mitigated. #WeChat #ZeroClick #MobileSecurity

    cyberworldops.eu/en/wechat-zer

  7. После очередного видео о том, как проходить границу РФ (хотя сам я этого делать не собираюсь), решил разобраться, как именно работают комплексы вроде «Мобильного криминалиста» / Cellebrite UFED.

    Оказалось, всё довольно плохо: уязвимы практически любые телефоны — и Android, и iPhone, — пока они просто заблокированы, а не выключены.

    a7.eww.monster/cellebrite-defe

    #Cellebrite #MobileSecurity #infosec #privacy #Android #iPhone #GrapheneOS #DigitalForensics #Андроид #слежка

  8. هجوم AnonyMousKIT على مستخدمي iPhone

    هجوم AnonyMousKIT على مستخدمي iPhone – 2026 تفاصيل الهجوم : كشفت تقارير أمنية في عام 2026 عن منصة احتيالية تُعرف باسم AnonyMousKIT، طورتها جهات إجرامية لاستهداف أصحاب أجهزة iPhone المفقودة أو المسروقة. تعتمد المنصة على التصيد الاحتيالي (Phishing) والهندسة الاجتماعية (Social Engineering) لخداع مالك الجهاز […]

    cybercases8.wordpress.com/2026

  9. 📱 Porto, ready for some mobile hacking? 🇵🇹

    🔥 4h hands-on Android & iOS workshop with Abraham Aranguren at AppSec Days Portugal.

    ⚔️ Real attacks. Real pentest cases. Practical exercises.

    🎟️ appsecdays.pt/trainings/mobile

  10. That answered VoLTE video call might be more dangerous than it looks.

    Researchers demonstrated an attack chain that can reach Android’s deepest system level on certain devices using Unisoc chips, including the Motorola E13, Realme C33 and Xiaomi Redmi A5.

    The attacker needs a private 4G network—but there’s still no official patch available.

    Find out how the chain works.

    en.hacks.gr/kindynos-gia-ekato

    #Cybersecurity #MobileSecurity #Android #Unisoc

  11. Un nombre « sans précédent » d'utilisateurs Apple ont reçu une alerte spyware. Le terme est fort — mais ce qui compte ici, c'est la surface d'attaque : des appareils grand public ciblés par des outils jusqu'ici réservés à des cibles très précises. La démocratisation du spyware commercial, c'est peut-être ça le vrai signal. #infosec #spyware #mobilesecurity
    techcrunch.com/2026/08/17/unpr

  12. Losing your phone is no longer just an annoyance.
    Read the blog: marshsecurity.org/protecting-a

    Losing your phone when it contains access to your email, Microsoft 365, MFA, corporate data, personal accounts, banking, photos and potentially your entire digital identity is a little more serious than "annoyance".

    I’ve published a new post looking at what you can do to reduce the impact of a lost or stolen mobile device, both from a personal perspective and also within a business. This blog covers some of the practical protections available through Microsoft and modern device management, as well as the steps worth taking before a device disappears.

    Because realistically, the best time to think about how you’d respond to a lost phone probably isn’t five minutes after realising it’s no longer in your pocket.

    Read the blog: marshsecurity.org/protecting-a

    Tags:
    #Microsoft #Security #Cyber #Tech #Technology #CyberSecurity #MicrosoftSecurity #MicrosoftIntune #Intune #Microsoft365 #EntraID #IdentitySecurity #MobileSecurity #InformationSecurity #DataProtection

  13. 🏆 Congratulations to COSIC researcher Tim Vlummens and co-authors!
    Their paper, "Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost", received the Internet Defense Prize 2026 at #USENIX Security Symposium and was also selected as a Distinguished Paper.
    Their research revealed how Meta and Yandex used localhost communication on Android to link web browsing data to app identities, bypassing privacy protections designed to separate web and app contexts.
    #Privacy #MobileSecurity

  14. AI-driven Mobile Anti-Scam tools are becoming essential for protecting users and businesses alike. This short read explains the latest advancements for Android and iOS and why integrating intelligent detection is critical for reducing fraud risk. wix.to/FuGmL6X

    #AI
    #Infosec
    #Cybersecurity
    #MobileSecurity
    #FraudPrevention

  15. Can privacy tools become evidence?

    Episode 445 of Shared Security looks at the GrapheneOS phone-wipe case and the bigger privacy concern: when strong security tools get reframed as suspicious behavior. Tom and Scott discuss airport searches, duress codes, and practical threat-modeling for anyone traveling with sensitive data.

    Full episode: youtu.be/Cch3pG2EO-g

    #SharedSecurity #Cybersecurity #Privacy #GrapheneOS #MobileSecurity #InfoSec

  16. Einordnung: Zero-Click-Lücken sind für Nutzer besonders unangenehm, weil man eben nichts »falsch anklicken« muss. Der Fall zeigt, wie viel Angriffsfläche schon entsteht, wenn ein Gerät eingehende Inhalte automatisch verarbeitet. Regelmäßige Sicherheitsupdates bleiben hier praktisch die einzige realistische Verteidigung.

    2/2

    #Android #ZeroClick #MobileSecurity #KuketzAugust

  17. Stolen phones - and specifically iPhones - have robust anti-theft protections. They are worthless once they're flagged - locked to their owner. So why are millions still being stolen every year?
    In this paper, we uncover a thriving underground marketplace focused on unlocking stolen phones. It is powered by:

    Lookalike domains impersonating Apple, Xiaomi, Samsung and other brands
    Smishing campaigns targeting device owners
    Pay‑as‑you‑go “unlocking” tools sold on Telegram
    By pivoting on DNS data, we identified 10,000+ malicious domains and a growing ecosystem turning locked devices into profit at scale.

    👉 Read how this supply chain works—from theft to resale—and why it’s growing fast. infoblox.com/blog/threat-intel

    #ThreatIntel #CyberSecurity #Phishing #MobileSecurity #iOS #Smishing #dns #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel #threatintelligence #cybercrime  #infosec #infoblox #infobloxthreatintel

  18. Greek police arrested scammers using a fake cell tower for SMS phishing.

    Phones were forced onto insecure 2G networks to harvest data and send bank-themed smishing.

    technadu.com/greek-police-arre

    Thoughts?

    #Smishing #MobileSecurity #InfoSec

  19. Join Jeroen Beckers at OWASP Global AppSec EU 2025 in Barcelona on May 29!

    🔗 Register: owasp.glueup.com/event/123983/

    From secure coding practices to the impact on SAST, DAST, and manual testing, this talk is a must for anyone securing modern mobile apps across platforms.

    Learn how to embed security into every phase of mobile app development—see you there!

    #OWASP #AppSecEU2025 #MobileSecurity #Flutter #ReactNative #CrossPlatform #SecureDev #Barcelona #OWASPMobile