CuraSec

tag: Mobile-Security · 6 items

  • Engineer — Skip
  • SOC/IR — Learn: The VPN-permission-as-blocker technique is a noteworthy evasion TTP for mobile threat awareness, but the summary provides no IOCs or detection signatures to act on; file for context when tuning mobile EDR or MAM policies.
  • Leader — Skip
  • Engineer — Skip
  • SOC/IR — Learn: The P2P relay exfiltration method — routing data through nearby compromised devices — is a novel evasion technique worth understanding, but no IOCs or enterprise-targeting details are published yet to build detections against.
  • Leader — Skip
  • Engineer — Learn: Mercenary spyware campaigns (e.g. Pegasus-class) rarely target enterprise engineers directly, but if your org issues iPhones to executives or privileged users, this is a signal to review mobile device management policies and ensure Lockdown Mode is available for high-risk individuals.
  • SOC/IR — Act: If any employees in your org received Apple Threat Notifications, treat them as potential high-value-target indicators — initiate an IR triage for those devices, collect sysdiagnose logs via Apple’s guidance, and check for known mercenary spyware IOCs (e.g. iVerify or MVT scans) before the trail goes cold.
  • Leader — Plan: Apple’s active notification campaign signals a broader mercenary spyware wave targeting high-value individuals; review whether executives, legal, or board members use personal iPhones for sensitive communications and consider enrolling at-risk individuals in Apple’s Lockdown Mode or a mobile threat defense program this quarter.
  • Engineer — Learn: A dense research compilation covering Android preinstalled-app attack surface (IPC abuse, content provider exposure, etc.); worth reviewing if mobile or Android MDM is in scope, but no exploitation signals and no patch action available today.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-13 · BleepingComputer · source ↗ #android#malware#mobile-security
  • Engineer — Learn: Novel abuse of Android Wireless ADB for privilege escalation without a USB/computer connection — worth tracking if your org manages Android devices or develops Android apps, but no patch or config action is available from this report.
  • SOC/IR — Plan: This technique adds a new lateral-movement/privilege-escalation vector on Android endpoints; start evaluating whether your EDR or MDM telemetry can detect unexpected Wireless ADB activation or connections on managed devices.
  • Leader — Skip
2026-07-11 · The Hacker News · source ↗ #vpn#mobile-security#privacy
  • Engineer — Skip
  • SOC/IR — Learn: If your organization allows or recommends free VPN apps to employees, this research highlights that many leak traffic or track users — worth reviewing your mobile device policy and VPN approved-list.
  • Leader — Plan: With 2.4 billion installs across flagged apps, if free VPNs are in use on corporate or BYOD devices, assess your approved-VPN policy and consider communicating guidance to employees before a data-handling incident creates liability.