MobileTrends

// Mobile security ops

Säkerhet & hot mot mobila ekosystem

Live-feeds från ledande antivirus- och threat-intel-leverantörer, kända hot mot iOS/Android/iPadOS i en riskskala, samt pågående kampanjer mot Apple, Google och Samsung.

hämtat just nu
Kaspersky · Securelist
ESET · WeLiveSecurity
Bitdefender Labs · offline
Sophos · Naked Security
Malwarebytes Labs
Trend Micro Research · offline
Lookout Threat Intel · offline
The Hacker News · Mobile
BleepingComputer · Mobile
BleepingComputer · Mobile
11 h sedan

New Prinz Eugen ransomware prioritizes recent files for encryption

A new ransomware operation named 'Prinz Eugen' prioritizes recently modified files for encryption and leaves no ransom note on the system. [...]

Läs hos källan
BleepingComputer · Mobile
12 h sedan

Microsoft links Mastra AI supply chain attack to North Korean hackers

Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. [...]

Läs hos källan
The Hacker News · Mobile
16 h sedan

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity informatio

Läs hos källan
BleepingComputer · Mobile
1 d sedan

Klue OAuth breach victim list grows as Icarus hackers claim attack

Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims

Läs hos källan
BleepingComputer · Mobile
1 d sedan

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. [...]

Läs hos källan
The Hacker News · Mobile
1 d sedan

Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. That code is burned into the silicon at manu

Läs hos källan
The Hacker News · Mobile
1 d sedan

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryp

Läs hos källan
BleepingComputer · Mobile
1 d sedan

Texas govt data breach exposes over 3 million driver’s licenses

The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals. [...]

Läs hos källan
Malwarebytes Labs
1 d sedan

Nearly 15,000 infected websites cleaned in SocGholish crackdown

Thousands of everyday websites were cleaned as part of a global operation targeting the malware network behind fake browser update scams.

Läs hos källan
The Hacker News · Mobile
1 d sedan

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker's web page, and that page's JavaScript can rea

Läs hos källan
The Hacker News · Mobile
1 d sedan

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. "With these actions

Läs hos källan
The Hacker News · Mobile
1 d sedan

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices. Th

Läs hos källan
BleepingComputer · Mobile
1 d sedan

Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

AI agents can access data, trigger workflows, deploy code, and interact with critical business systems, often with little oversight. Token Security breaks down why AI agents are becoming a new identity and governance challenge. [...]

Läs hos källan
BleepingComputer · Mobile
1 d sedan

Webinar: How attackers bypass MFA and how defenders can respond

Modern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This webinar explores how behavioral AI can help security teams detect compr

Läs hos källan
The Hacker News · Mobile
1 d sedan

From Assistive to Agentic: The AI Shift That's Redefining Threat Management

Introduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in siloes, generating (overlapping) alerts and data. And

Läs hos källan
Malwarebytes Labs
1 d sedan

Apple patches Beats Studio Buds flaw that could turn earbuds into a wiretap

Apple has patched a year-old Bluetooth vulnerability that could have let nearby attackers listen through Beats Studio Buds' microphone.

Läs hos källan
BleepingComputer · Mobile
1 d sedan

Microsoft: June 2026 Windows updates break Recycle Bin prompts

Microsoft has confirmed a confusing Windows bug that causes different filenames to appear in the confirmation dialog when deleting a file from the Recycle Bin. [...]

Läs hos källan
BleepingComputer · Mobile
1 d sedan

CISA: Splunk Enterprise flaw actively exploited, patch by Sunday

CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. [...]

Läs hos källan
The Hacker News · Mobile
1 d sedan

Forget Data Leakage: Shadow AI's Real Threat Is Access Control

The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response mad

Läs hos källan
The Hacker News · Mobile
1 d sedan

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To that end, organizations will be unable

Läs hos källan
BleepingComputer · Mobile
1 d sedan

NY man charged after harassing college student with AI-generated nudes

A New York man faces cyberstalking charges after allegedly sharing AI-generated nude images and fabricated racist messages using fake social media profiles to harass a Georgia college student. [...]

Läs hos källan
BleepingComputer · Mobile
1 d sedan

CISA warns Fortinet users to secure devices after FortiBleed leak

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed "FortiBleed." [...]

Läs hos källan
The Hacker News · Mobile
1 d sedan

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a cas

Läs hos källan
BleepingComputer · Mobile
2 d sedan

Gentlemen ransomware uses multiple EDR killers to disable defenses

The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. [...]

Läs hos källan
The Hacker News · Mobile
2 d sedan

F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed below - CVE-2026-42530 (CVSS v4 score: 9.2) -

Läs hos källan
The Hacker News · Mobile
2 d sedan

Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network

If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who authorized it? For most enterprises, the answer is a simple no. The rush to adopt internal AI too

Läs hos källan
Malwarebytes Labs
2 d sedan

Microsoft working on a fix for RoguePlanet, a flaw that grants full PC control

Microsoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.

Läs hos källan
Malwarebytes Labs
2 d sedan

Retro gaming fans are the new target for fake GitHub malware

Retro gaming fans should be careful with GitHub projects that claim to be tools or plugins for their consoles. We looked at one example aimed at PlayStation Vita owners.

Läs hos källan
Malwarebytes Labs
2 d sedan

Kodak confirms breach as ShinyHunters’ leak threat reaches deadline

The photography giant confirmed a data breach after ShinyHunters claimed it stole 2.2 million records and threatened to leak them.

Läs hos källan
ESET · WeLiveSecurity
2 d sedan

Killing me gently: Inside Gentlemen’s EDR killer framework

ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen

Läs hos källan
Malwarebytes Labs
3 d sedan

Roblox developers are losing entire games to malware attacks

Attackers are using fake job offers and malware to steal accounts, Robux, and Roblox games from the developers who build them.

Läs hos källan
Malwarebytes Labs
3 d sedan

Rokarolla Android malware can take over your phone and steal banking logins

Researchers have uncovered an Android banking Trojan that targets more than 200 banking and cryptocurrency apps and can take over infected devices.

Läs hos källan
Malwarebytes Labs
3 d sedan

24 billion stolen records exposed online. Here’s what to do

Researchers found an exposed collection of 24 billion stolen records, including usernames, passwords, and other sensitive account data.

Läs hos källan
Malwarebytes Labs
3 d sedan

Malwarebytes earns AV-TEST Top Product award, aces other third-party tests

Malwarebytes got top marks in independent tests against malware, phishing, and other online threats.

Läs hos källan
ESET · WeLiveSecurity
3 d sedan

Protecting legacy OT systems against modern cyberthreats

Many manufacturing plants depend on OT systems that stay in service for many years. That long run can hide significant cybersecurity risks.

Läs hos källan
Sophos · Naked Security
4 d sedan

AI in the underground: Curiosity, claims, and concerns

Amid discussions about how artificial intelligence can facilitate cybercrime, some threat actors remain skepticalCategories: Threat ResearchTags: AI, Dark Web, underground

Läs hos källan
Malwarebytes Labs
4 d sedan

“Free World Cup stream” sites are serving scams, not football

We found dozens of fake World Cup streaming sites using football as bait to funnel visitors through a malicious advertising network.

Läs hos källan
Malwarebytes Labs
4 d sedan

Cardiac patients’ medical data stolen and held to ransom

Cardiac monitoring provider iRhythm has been hit by a data theft followed by an extortion attempt.

Läs hos källan
Malwarebytes Labs
4 d sedan

Deepfake posting sites depicting famous women taken down by feds

Thanks to Uncle Sam, anyone trying to find nonconsensual intimate deepfakes on CFake.com and SOCFake.com will be disappointed.

Läs hos källan
Kaspersky · Securelist
4 d sedan

Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk

Since late 2025, malware has been spreading rapidly through the Steam Workshop, the gaming platform's built-in service for players to create and share custom content. The attackers are primarily targeting gamers in China and Russia.

Läs hos källan
ESET · WeLiveSecurity
4 d sedan

FishMonger’s arsenal upgraded: SprySOCKS for Windows

ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness

Läs hos källan
ESET · WeLiveSecurity
5 d sedan

EvilTokens: A phishing attack that doesn’t steal your password

A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages

Läs hos källan
ESET · WeLiveSecurity
9 d sedan

OceanLotus: From external espionage to domestic targeting

A shift in operational pattern of the infamous Vietnam-aligned APT group

Läs hos källan
Sophos · Naked Security
10 d sedan

June Patch Tuesday smashes past 500-CVE mark

209 patches + 388 advisories = welcome to summer 2026Categories: Threat ResearchTags: x-ops, Patch Tuesday, MICROSOFT PATCH TUESDAY

Läs hos källan
ESET · WeLiveSecurity
10 d sedan

Unpacking SMB cyber-readiness – and what makes or breaks it

A company that's expecting a cyberattack but hasn’t actively prepared for it risks making the hardest decisions at the worst possible moment

Läs hos källan
ESET · WeLiveSecurity
11 d sedan

Cybercriminals: the 'auditors' you never hired

Every organisation gets audited. The question is who does the auditing.

Läs hos källan
Sophos · Naked Security
17 d sedan

You do surprise me.exe: An unexpected executable in Hola Browser

Following a certification test, Sophos X-Ops found an unexpected guest had hitched a rideCategories: Threat ResearchTags: Crypto mining, Supply chain

Läs hos källan
Kaspersky · Securelist
17 d sedan

Argamal: Malware hidden in hentai games

Kaspersky researchers analyze new Argamal RAT distributed via infected hentai games and allowing the attacker to control the target machine.

Läs hos källan
ESET · WeLiveSecurity
17 d sedan

Lessons for life: Why children’s data is a long-term identity risk

Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.

Läs hos källan
Kaspersky · Securelist
18 d sedan

Wardriving assessment across Mexico: Preparing for the 2026 World Cup

In the lead-up to the 2026 FIFA World Cup, Kaspersky GReAT experts conducted a wardriving assessment in Mexico City, Monterrey, and Guadalajara to evaluate Wi-Fi hotspot security configurations and potential exposure risks.

Läs hos källan
Sophos · Naked Security
19 d sedan

Pointing a Cursor at evading detection

AI accelerated tool development and testing, but humans drove the workflowCategories: Threat ResearchTags: AI, EDR

Läs hos källan
Kaspersky · Securelist
19 d sedan

Containers on fire: from container escapes to supply chain attacks

We break down the primary attack vectors in containerized environments: exposed secrets, privilege misconfigurations, API compromise, and supply chain attacks.

Läs hos källan
ESET · WeLiveSecurity
22 d sedan

This month in security with Tony Anscombe – May 2026 edition

In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit

Läs hos källan
Kaspersky · Securelist
22 d sedan

What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant

What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and how Kaspersky Container Security with the KIRA AI assistant can help.

Läs hos källan
ESET · WeLiveSecurity
23 d sedan

ESET APT Activity Report Q4 2025–Q1 2026

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026

Läs hos källan
Kaspersky · Securelist
23 d sedan

Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years

Our experts continue to track attacks targeting consumers of pirated content, both books and movies. 2026 saw the discovery of new target sites with tens of millions of visitors, while the miner gained a RAT module.

Läs hos källan
ESET · WeLiveSecurity
24 d sedan

What to consider before asking an AI chatbot for health advice

Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe.

Läs hos källan
ESET · WeLiveSecurity
25 d sedan

BTMOB: A stealthy RAT burrowing deep into Android devices

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise

Läs hos källan
Kaspersky · Securelist
29 d sedan

Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

Cloud Atlas attacks the public sector and diplomatic structures of Russia and Belarus, using ReverseSocks, SSH, and Tor for persistence in infected systems and its new tool, PowerCloud.

Läs hos källan
Kaspersky · Securelist
31 d sedan

How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)

We explain how a flaw in ExifTool allows attackers to compromise macOS systems via a malicious image (CVE-2026-3102).

Läs hos källan