ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes
ClingSTUN exploits known IoT flaws and abuses public STUN servers to keep proxy access to devices
ClingSTUN exploits known IoT flaws and abuses public STUN servers to keep proxy access to devices
FortiGuard Labs examines how ClingSTUN exploits vulnerable devices and abuses public STUN servers to support a Linux proxy backdoor.
Banking scam fraudsters are increasingly focusing on mobile devices, with a 35% increase in such scams over the last 12 months.
A newly identified IoT botnet, Cling, disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate...
Microsoft has automatically enabled Windows settings backup for eligible commercial devices running Windows 11, version 26H2. Microsoft positions this capabi...
CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices to remote C2 servers.
The vulnerabilities in Android allowed for malicious apps to be installed and executed via a crafted NFC tag without user approval.
This year at Microsoft Ignite, we spotlight our AI-first, end-to-end security platform designed to protect identities, devices, data, applications, clouds, i...
Google report focuses on exploit of CVE-2026-88772, which executed lateral movement a month before a patch existed.
'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.
A critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute code on vulnerable devices or trigger a denial-of-servi...
View CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with...
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [.
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild.
Linkage analysis connects accounts, devices and infrastructure to detect coordinated fraud rings that traditional account-level risk controls may fail to ide...
The newly-discovered trojan abuses the Android Accessibility Service to gain control over victim devices and collect sensitive banking credentials
Mobile security company Lookout Inc. has launched Social Engineering Protection, a new module designed to analyze text messages and phone calls for signs of ...
IoT and OT devices can create hidden security gaps. Learn how asset visibility helps organizations find forgotten devices and reduce network security risks now.
Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy p...
Portnox has announced new capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy, restri...