Android's April Patch Targets a Security Layer Most Users Have Never Heard Of

April's Android security update fixes a critical zero-interaction DoS and a High-severity flaw in StrongBox, the hardware layer protecting your payment credentials, biometrics, and encrypted storage.

Read More

Two Active Campaigns Are Using WhatsApp as the Front Door

A VBS-based Windows hijack and an Italian spyware operation are both running through WhatsApp right now. Your chat app is a threat vector.

Read More

A Full Android Rootkit Hid in Google Play for Months. 2.3 Million Downloads.

McAfee found a full rootkit hiding in 50+ Google Play apps. It roots your phone, survives factory resets, and hijacks WhatsApp sessions. 2.3 million devices already got it.

Read More

Apple Is Literally Warning Millions of iPhone Users: You're Being Attacked Right Now

Apple pushed lock screen alerts to millions of iPhones warning of active attacks from the Coruna and DarkSword exploit kits -- and some users have no patch path at all.

Read More

The iPhone Exploit That Won't Die: Operation Triangulation's Code Is Back and More Dangerous

Exploit code from the 2023 Operation Triangulation campaign lives inside Coruna, a new iOS attack framework hitting modern iPhones in mass attacks. Elite nation-state code is now being aimed at everyone.

Read More

The Week the Infrastructure Fought Back (and Lost)

The week of March 16-22 hit management planes, identity infrastructure, and security tooling itself -- and North Korea kept hiring.

Read More

Update Everything: Chrome Zero-Days, Android's March Bulletin, and the Patch Gap That Puts You at Risk

Two Chrome zero-days under active attack, 129 Android vulnerabilities in March, and the stubborn reality that 'patch available' and 'you're protected' are two very different things.

Read More

iPhone Exploit Kits Go Mainstream: DarkSword, Coruna, and the End of 'iOS Is Enough'

New research from Google, iVerify, and Lookout confirms iOS exploit kits have moved from rare targeted spyware to website-level deployment against broad populations. A companion toolkit was found targeting US government officials specifically.

Read More

Mobile Trust Is Fracturing: Android Fraudware and iOS Exploit Chains Converge

Perseus on Android, DarkSword on iOS, and new iPhone exploitation reporting point to a shared reality: mobile trust assumptions are breaking across both ecosystems.

Read More

iPhone Exploit Chains Are Becoming a Market, Not a One-Off

DarkSword iOS exploit capability is showing up across multiple actor sets -- state-linked groups, commercial spyware vendors, and infostealer campaigns. The old 'rare nation-state' framing doesn't hold anymore.

Read More

Your Old iPhone Is Under Active Attack. Update It Today.

Apple issued an emergency patch for older iPhones and iPads to fix actively exploited Coruna WebKit vulnerabilities. If you have an old device you haven't updated, this is when that delay becomes a real problem.

Read More