Mobile malware targets smartphones and tablets through malicious apps, fake app stores, and SMS-based attack vectors. Banking trojans, spyware, and adware campaigns increasingly target both Android and iOS platforms. defend.network tracks mobile threats that pose risks to enterprise environments through BYOD policies and mobile device management gaps.
Microsoft released 974 patches in its largest single batch; Check Point Security Management servers vulnerable to unauthenticated RCE; Docker Sandboxes can be escaped on macOS.
Mantax Otax and Gigabud banking trojans spread across Android, Russian-speaking actors deployed hundreds of AI agents to exploit PaperCut flaws on 395 organizations
Microsoft released 398 security patches including one actively exploited flaw; Zimbra command injection (CVE-2026-73570) in CISA KEV with Aug 24 federal deadline; Android vehicle head units infected via supply-chain attack distributing proxy botnet malware.
Android car head units infected via malware-laden firmware updates; 9,300+ AWS keys remain active; Snowflake extortionist pleads guilty after compromising 165+ organizations.
GitHub Agentic Workflows leak private repo data via public issues; Gitea CVE-2026-20896 authentication bypass actively exploited; RedWing Android malware rented as fraud service on Telegram.
Fortinet FortiSandbox faces active in-the-wild exploitation of three CVEs. Android banking trojan Rokarolla targets 217 financial apps with 137 remote commands. Google Vertex AI SDK bucket-squatting flaw enables unauthorized model hijacking.
Google Gemini voice assistant hijackable via poisoned notifications; Microsoft 365 Android apps leak tokens; Redis RCE (CVE-2026-23479) patched; critical fuel tank systems under active attack.
Subscribe free and never miss a threat briefing.