home.social

#mobilesecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mobilesecurity, aggregated by home.social.

  1. Citizen Lab and SHARE Foundation confirmed Pegasus compromised a Serbian student activist's iPhone via a zero-click iMessage exploit in Dec 2025-Jan 2026. Patched in iOS 18.4.1, it confirms continued use of mercenary spyware against civil society. #Pegasus #ZeroClick #ThreatIntel #MobileSecurity

    cyberworldops.eu/en/pegasus-hi

  2. Citizen Lab and SHARE Foundation confirmed Pegasus compromised a Serbian student activist's iPhone via a zero-click iMessage exploit in Dec 2025-Jan 2026. Patched in iOS 18.4.1, it confirms continued use of mercenary spyware against civil society. #Pegasus #ZeroClick #ThreatIntel #MobileSecurity

    cyberworldops.eu/en/pegasus-hi

  3. После очередного видео о том, как проходить границу РФ (хотя сам я этого делать не собираюсь), решил разобраться, как именно работают комплексы вроде «Мобильного криминалиста» / Cellebrite UFED.

    Оказалось, всё довольно плохо: уязвимы практически любые телефоны — и Android, и iPhone, — пока они просто заблокированы, а не выключены.

    a7.eww.monster/cellebrite-defe

    #Cellebrite #MobileSecurity #infosec #privacy #Android #iPhone #GrapheneOS #DigitalForensics #Андроид #слежка

  4. هجوم AnonyMousKIT على مستخدمي iPhone

    هجوم AnonyMousKIT على مستخدمي iPhone – 2026 تفاصيل الهجوم : كشفت تقارير أمنية في عام 2026 عن منصة احتيالية تُعرف باسم AnonyMousKIT، طورتها جهات إجرامية لاستهداف أصحاب أجهزة iPhone المفقودة أو المسروقة. تعتمد المنصة على التصيد الاحتيالي (Phishing) والهندسة الاجتماعية (Social Engineering) لخداع مالك الجهاز […]

    cybercases8.wordpress.com/2026

  5. 📱 Porto, ready for some mobile hacking? 🇵🇹

    🔥 4h hands-on Android & iOS workshop with Abraham Aranguren at AppSec Days Portugal.

    ⚔️ Real attacks. Real pentest cases. Practical exercises.

    🎟️ appsecdays.pt/trainings/mobile

  6. That answered VoLTE video call might be more dangerous than it looks.

    Researchers demonstrated an attack chain that can reach Android’s deepest system level on certain devices using Unisoc chips, including the Motorola E13, Realme C33 and Xiaomi Redmi A5.

    The attacker needs a private 4G network—but there’s still no official patch available.

    Find out how the chain works.

    en.hacks.gr/kindynos-gia-ekato

    #Cybersecurity #MobileSecurity #Android #Unisoc

  7. Un nombre « sans précédent » d'utilisateurs Apple ont reçu une alerte spyware. Le terme est fort — mais ce qui compte ici, c'est la surface d'attaque : des appareils grand public ciblés par des outils jusqu'ici réservés à des cibles très précises. La démocratisation du spyware commercial, c'est peut-être ça le vrai signal. #infosec #spyware #mobilesecurity
    techcrunch.com/2026/08/17/unpr

  8. Losing your phone is no longer just an annoyance.
    Read the blog: marshsecurity.org/protecting-a

    Losing your phone when it contains access to your email, Microsoft 365, MFA, corporate data, personal accounts, banking, photos and potentially your entire digital identity is a little more serious than "annoyance".

    I’ve published a new post looking at what you can do to reduce the impact of a lost or stolen mobile device, both from a personal perspective and also within a business. This blog covers some of the practical protections available through Microsoft and modern device management, as well as the steps worth taking before a device disappears.

    Because realistically, the best time to think about how you’d respond to a lost phone probably isn’t five minutes after realising it’s no longer in your pocket.

    Read the blog: marshsecurity.org/protecting-a

    Tags:
    #Microsoft #Security #Cyber #Tech #Technology #CyberSecurity #MicrosoftSecurity #MicrosoftIntune #Intune #Microsoft365 #EntraID #IdentitySecurity #MobileSecurity #InformationSecurity #DataProtection

  9. 🏆 Congratulations to COSIC researcher Tim Vlummens and co-authors!
    Their paper, "Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost", received the Internet Defense Prize 2026 at #USENIX Security Symposium and was also selected as a Distinguished Paper.
    Their research revealed how Meta and Yandex used localhost communication on Android to link web browsing data to app identities, bypassing privacy protections designed to separate web and app contexts.
    #Privacy #MobileSecurity

  10. AI-driven Mobile Anti-Scam tools are becoming essential for protecting users and businesses alike. This short read explains the latest advancements for Android and iOS and why integrating intelligent detection is critical for reducing fraud risk. wix.to/FuGmL6X

    #AI
    #Infosec
    #Cybersecurity
    #MobileSecurity
    #FraudPrevention

  11. Can privacy tools become evidence?

    Episode 445 of Shared Security looks at the GrapheneOS phone-wipe case and the bigger privacy concern: when strong security tools get reframed as suspicious behavior. Tom and Scott discuss airport searches, duress codes, and practical threat-modeling for anyone traveling with sensitive data.

    Full episode: youtu.be/Cch3pG2EO-g

    #SharedSecurity #Cybersecurity #Privacy #GrapheneOS #MobileSecurity #InfoSec

  12. In my last article, I discussed the importance of protecting our private data.

    👉 In my new article, I share my experience with GrapheneOS — what it is and my thoughts after using it for over six months.

    ➡️ Read it here: cypriendefontenay.de/blog/my_e

    #GrapheneOS #Privacy #MobileSecurity #OpenSource #DataProtection #TechReview

  13. Einordnung: Zero-Click-Lücken sind für Nutzer besonders unangenehm, weil man eben nichts »falsch anklicken« muss. Der Fall zeigt, wie viel Angriffsfläche schon entsteht, wenn ein Gerät eingehende Inhalte automatisch verarbeitet. Regelmäßige Sicherheitsupdates bleiben hier praktisch die einzige realistische Verteidigung.

    2/2

    #Android #ZeroClick #MobileSecurity #KuketzAugust

  14. Porto, get ready! 🇵🇹

    Join Abraham Aranguren on Sep 23 for a hands-on workshop on practical Android and iOS attacks.

    appsecdays.pt/trainings/mobile

  15. Palo Alto Networks discovered Landfall, an Android spyware exploiting a Samsung zero-day (CVE-2025-21042) to deliver malware via DNG images on WhatsApp.
    🎯 Region: Middle East & North Africa
    📱 Targets: Samsung Galaxy S22–S24, Fold4, Flip4
    🕵️‍♂️ Capabilities: Audio recording, GPS tracking, data exfiltration
    The vulnerability was patched in April, but exploitation began months before. Attribution remains uncertain.
    Follow @technadu for neutral, verified #InfoSec updates.

    #CyberSecurity #Android #Spyware #Samsung #ZeroDay #CVE202521042 #ThreatIntelligence #MobileSecurity #DigitalForensics #TechNews

  16. ⚠️ Mobile security risk: New Android malware "SuperCard X" enables contactless payment fraud via NFC relay attacks 📱💳

    Here’s how it works:
    🔹 Victims are socially engineered through fake bank alerts (smishing + calls)
    🔹 Tricked into installing a rogue app posing as “security software”
    🔹 NFC data is intercepted from real debit/credit cards
    🔹 Attackers relay stolen credentials to PoS terminals and ATMs for fraudulent cashouts

    Why it matters:
    • Attackers no longer need stolen physical cards — just proximity + deception
    • Banking customers, payment providers, and card issuers are all at risk
    • Google is working on Android protections — but vigilance is key now

    🛡️ Tip: Always scrutinize app installs, verify messages before acting, and keep Google Play Protect enabled.

    #CyberSecurity #MobileSecurity #Malware #NFC #FinancialFraud #ThreatIntel #security #privacy #cloud #infosec

    thehackernews.com/2025/04/supe