The mobile threat landscape continues to grow at an alarming rate as cybercrime groups shift their tactics and target mobile devices in the early stages of their attacks, according to a recent Lookout report.

The report highlights insights behind a 17% increase QoQ (quarter on quarter) in enterprise-focused credential theft and phishing attempts, 32% increase QoQ in malicious app detections and a trend showing iOS devices are more exposed to phishing attacks than Android devices.
New mobile surveillance tools tied to Chinese and Russian APTs
In a series of multiple novel threat discoveries, researchers have disclosed a number of mobile surveillanceware are tools developed by advanced persistent threat (APT) groups based in China and Russia including Gamaredon and more.
More than 106,000 malicious apps were detected on enterprise mobile devices, which can vary widely from trojan malware to sophisticated spyware.
Globally, mobile phishing and malicious web content have become synonymous with business email compromise (BEC), MFA bypass attacks, executive impersonation, and vulnerability exploitation. These attacks are typically low cost and high reward, and for that reason have become the preferred initial step in the modern kill chain.
The most recent evolution in this threat vector is the use of executive impersonation attacks, which leverage an individual’s seniority and a lower-level employee’s innate desire to be helpful together to drive higher success rates. By creating a highly urgent situation and relying on lack of familiarity between the executive and the employee, attackers convince employees to share sensitive data, visit phishing pages, or send them money.
iOS is more popular for enterprises than Android, therefore Lookout observed iOS targeted by threat actors more often (18.4%) in phishing attacks than Android (11.4%) in Q3 2024. Top device misconfigurations include out-of-date OS, out-of-date Android Security Patch Levels (ASPL), no device lock and no encryption.
Attackers target mobile devices to breach enterprise cloud systems
The most critical families of mobile malware continued to lean heavily towards Android surveillanceware.
The top ten most common mobile browser vulnerabilities encountered by Lookout users affect Chromium-based browsers. Attackers target these vulnerabilities in particular in hopes users haven’t updated to patched versions.
Outside of browser vulnerabilities, the five most common mobile app vulnerabilities were in social media, messaging and authentication apps and app stores.
With the commoditization of advanced malware, evolution of nation-state mobile malware capabilities, and a heavy reliance on mobile-focused social engineering, organizations today must have advanced mobile threat defense as part of their security strategy. Threat actors are increasingly targeting mobile devices to steal credentials and infiltrate the enterprise cloud in a pathway known as the modern kill chain.
“As cyber threats evolve, we’re seeing more and more attacks targeting mobile devices as the gateway to corporate cloud apps that house sensitive data. This trend underscores the urgent need for advanced MTD solutions that not only protect devices but also safeguard the sensitive data and systems they connect to,” said David Richardson, VP of Endpoint, Lookout.
The Lookout Mobile Threat Landscape Report is based on data derived from the Lookout Security Cloud’s AI-driven mobile dataset of more than 220 million devices, 360 million apps and billions of web items.
from Help Net Security https://ift.tt/XBQxhnj
We may earn a commission from links on this page.
If you're curious about how younger people are celebrating the holiday season this year, I have you covered: They're singing each other Rizzmas Carols, with lyrics like "On the first day or Rizzmas, my gyat gave to me, a toilet, skibidi." They're also decorating their Fortnite avatars with festive Skibidi Toilet skins, and watching MrBeast's new game show, The Beast Games.
The rise of Rizzmas Carols
This year, the kids are marking the holiday by singing "Rizzmas Carols" with lines like "deck the halls with boughs of sigmas." They're basically slang overload, brain rot versions of Christmas carols. Check out "It's Beginning to Look a Gyat like Rizzmas" to see what I mean:
For reasons known to no one, this brain rot version of "Last Christmas" ("Last Rizzmas") has a million and a half plays on TikTok:
A favorite song to parody if you want to really cram in as many Gen-A references as possible is "12 Days of Rizzmas," in which your rizzler might give you nine sigmas moggings...
...or 10 skibidi toilets.
Before you start bemoaning the future of the holidays, ask yourself how many times you sang "Jingle bells, Batman smells, Robin laid an egg" when you were a kid. (If you asked your parents, I bet they'd answer "way too many.") And if you simply don't know what any of these newer slang words mean, I have you covered with my constantly updated guide to Gen Z and Gen A slang.
Skibidi Toilet comes to Fortnite
While we're doing brain rot, let's talk about Skibidi Toilet coming to Fortnite. The "Skibidi Toilet Bundle" contains a skin of Skibidi Toilet, two versions of Plungerman, a skibidi backpack, and the Plungerman's plungers, all for 2,200 V-Bucks. But act fast, it's only available until December 28.
If none of the above made any sense to you, allow me to translate: Fortnite is a massively popular competitive online game. Skibidi Toilet is a massively popular (among the younger set, anyway) web series on YouTube. Skins allow players to "dress" their in-game avatars, and it all costs V-Bucks, which are the online currency in Fortnite. At the current exchange rate, 2,200 V-Bucks is about $20, so kids can now spend $20 to look like Skibidi Toilet characters while they're playing Fortnite. If you're looking for a last minute gift for the 11 year-old in your life, hold your nose and fork over the V-Bucks.
TikTok gets nostalgic with Google Maps
For many, the end of the year is a time for bittersweet reflection, and TikTok denizens are getting into the spirit in an interesting way. The newest trend on social media involves posting videos of virtual time travel: finding familiar places on Google Maps' street view, then virtually going back in time by checking out earlier photos to note who or what is no longer around. For instance, this TikToker misses her grandparents, but somewhere on Google Maps, they're alive, working on the front lawn:
People are finding their own chalk drawings on the driveway:
People are seeing themselves waiting for the school bus:
People are catching themselves on a first date in the driveway:
Many people are finding beloved pets, sunning themselves in the yard, with no idea of how little time they have left:
Even if no one was captured by Google's map car, just a missing car in a driveway is enough to stop people cold:
If you're interested in checking out how your own home has changed over the years, here's how:
-
Open up the google maps app or go to the Google Maps page.
-
Put in your address
-
Click "View street view"
-
Click “Show more dates”
-
Pick a year and see if it makes you cry
Man brings flowers to date, gets flamed
X user @Thehullboy posted a photo of himself about to go on a date last week and drew the ire and bile of a countless X users. See if you can guess what he did wrong:
This Tweet is currently unavailable. It might be loading or has been removed.
If you said, "nothing," congratulations, you're not a bitter cretin. According to man-o-sphere types, incels, and other sentient garbage heaps, though, the dude should not have brought the girl flowers. Some sample comments:
This Tweet is currently unavailable. It might be loading or has been removed.
This Tweet is currently unavailable. It might be loading or has been removed.
This Tweet is currently unavailable. It might be loading or has been removed.
To be fair, many commenters on this dude's post support his decision to bring a bouquet on a date, pointing out that it's kind of a nice thing to do on a date, and sort of adorable. In response, angry men are pointing out that those comments are from women, and what do women know about what women like? In other words, something has gone terrible wrong with many, many young men.
Viral Video of the Week: The first episode of 'The Beast Games'
Mr. Beast has 338 million followers on his YouTube channel, more than anyone else on Earth, but this month he's making the move to more traditional streaming by hosting his own game show on Amazon Prime Video. The Beast Games is like a real life version of Squid Game where 1,000 regular people compete for a prize of $5 million through the kinds of endurance tests and contests that MrBeast made so popular on his YouTube channel. Critics do not like it, dubbing it "$100 million worth of charmless YouTube nonsense" and "about what you’d expect from an ever-hustling spectacle merchant like MrBeast." The kids, though, seem to like it: Almost 100 million people viewed the first episode on YouTube in less than a week. For comparison: around 123 million people viewed the last Super Bowl.
from LifeHacker https://ift.tt/GcxwALm
We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.
The Amazon Echo Buds, available in black or glacier white, are now $24.99 (down from $49.99)—their lowest price ever, according to price-tracking tools. These stem-style earbuds come with translucent silicone covers to provide a fit that is generally secure, but the sound can vary depending on how the earbuds sit in your ears. Inside, the Echo Buds house 12mm dynamic drivers with a frequency range of 20Hz to 20kHz. When properly positioned, they deliver solid bass without distortion, even at high volumes, while mids and highs balance the sound nicely, as noted in this PCMag review.
These earbuds are equipped with Bluetooth 5.2 and support AAC, AptX, and SBC codecs, offering impressive compatibility for their price. That said, they lack active noise cancellation, which may be a drawback for some users. On the plus side, they support multipoint pairing for seamless switching between devices. Additionally, the earbuds' touch controls are reportedly highly responsive and customizable via the companion app—where you can also tweak the EQ settings, manage your default streaming platforms, toggle hands-free Alexa access, and enable the Find My feature to locate misplaced earbuds.
The Echo Buds offer up to five hours of battery life per charge with an additional 20 hours provided by the charging case (turning off hands-free Alexa can extend that runtime to six hours, though your mileage may vary). Note that Amazon does not include a USB-C charging cable in the box, so you’ll need to provide your own. Also, if durability is a priority, you'll probably find the IPX2 water-resistance rating of the Echo Buds disappointing. While they can handle light splashes, they’re not built to endure heavy rain or sweat, so you’ll want to be cautious in more challenging conditions.
from LifeHacker https://ift.tt/6xHSoDq
If you have a well-balanced, diversified portfolio, chances are it was designed to weather the ups and downs of the market. In other words, for most casual investors, your portfolio was created to not need the (potentially costly) help of a hands-on advisor. So, how do you know when you've tipped into situations that warrant professional help? Here's how to decide what's right for you and find quality assistance if needed.
The case for DIY investing
DIY investing brings several advantages:
-
Lower costs: Most financial advisors charge based on how much money they manage for you, and that fee can range from 0.25% to 1% per year. On a $500,000 portfolio, that could cost you around $1,250-5,000 per year. Over decades, these fees can reduce your returns by hundreds of thousands of dollars (thanks a lot, compound interest).
-
Simpler options: For most investors, managing your own investments through low-cost index funds is a sufficient approach. A basic three-fund portfolio using low-cost index funds (total U.S. stock market, international stocks, and bonds) provides broad diversification and historically strong returns. This strategy requires minimal time and expertise to implement. If you're using this sort of approach, you probably don't need to pay an advisor to keep an eye on it.
-
Sense of control: Managing your own investments means maintaining full visibility and control over your money. You can adjust your strategy immediately as circumstances change without going through an intermediary, which can be very appealing. However, let's dig into why this might sound better than it usually plays out in reality.
When professional help makes sense
Consider a financial advisor if you:
-
Have complex financial needs: Estate planning, tax optimization across multiple accounts, or managing inherited assets require professional expertise. If you're a business owner or a truly high-net-worth individual, odds are you can afford—and will benefit from—comprehensive wealth management.
-
Lack time or interest: Be honest with yourself. If researching investments and rebalancing portfolios feels overwhelming, an advisor can handle these tasks. The cost may be worthwhile if it prevents analysis paralysis or emotional trading decisions.
-
Need emotional discipline: Quite frankly, you're never as objective as you think you are. When I spoke with Matthew Chancey, CFP, about what it takes to be an active investor, he explained how you need to "have a higher appetite for risk and be more emotionally fortified than every investor sentiment survey has ever suggested that passive investors can be." Some investors panic-sell during market downturns or chase performance. This is where a good advisor comes in: They can provide behavioral coaching and prevent costly mistakes during volatile periods.
-
Face major life transitions: On top of emotional discipline, major life transitions come with their own set of financial potholes. During divorce, inheritance, retirement, or career changes, professional guidance can help navigate complex financial decisions and tax implications. Here are more cases of financial milestones that are worth the time and money of a professional.
Finding quality financial help
If you decide to hire help, here's how you can get started.
Fee-only fiduciary advisors
First things first: Be sure to pay close attention to the difference between fee-based vs. fee-only advisors, as certain financial advisors may not have your best interests at heart. After all, when it comes to finding the right financial planner for you, the last thing you want is to get ripped off. Look for advisors who:
-
Charge transparent fees (not commissions)
-
Have a fiduciary duty to put your interests first
-
Hold respected credentials (CFP, CFA)
-
Provide comprehensive financial planning, not just investment management
-
Are willing to explain their approach and fees in detail
Robo-advisors
For hands-off investing with minimal fees, a robo-advisor could suffice. They can be a great choice for newer, younger investors. But for advanced planning and strategy, a human touch may still be required for advice you can trust.
Digital platforms like Vanguard Personal Advisor Services or Betterment offer a middle ground:
-
Lower fees (0.20-0.30% annually)
-
Automated investment management
-
Basic financial planning tools
-
Access to human advisors
-
Good for straightforward situations requiring minimal customization
The bottom line
Most investors are better served by learning basic investment principles and managing a simple portfolio themselves. The money saved on fees can compound significantly over time.
However, if you have complex needs or know you won't stay disciplined without help, working with a qualified advisor can be worthwhile. Choose carefully, understand all fees, and regularly evaluate whether you're getting sufficient value for the cost. For more details about the process of choosing an advisor, check out our guide here.
Remember: Even with an advisor, you should understand your investment strategy and feel comfortable asking questions. The best advisors educate their clients rather than create dependency.
from LifeHacker https://ift.tt/IAfW9DL
We're getting close to a year since the launch of the Samsung Galaxy S24 series, which means it's almost time for the Galaxy S25 series to break cover—and there have been plenty of leaks and rumors about what to expect. Nothing is confirmed yet, but here you'll find all of that speculation collected and cross-referenced.
It looks as though we're going to get four models next year: The usual trio of the standard Galaxy S25, the Galaxy S25 Plus, and the Galaxy S25 Ultra, and then the added bonus of a new Galaxy S25 'Slim' model that goes for a thinner form factor (and may or may not end up replacing the Galaxy S24 FE).
Samsung Galaxy S25: launch date and pricing
Considering the Galaxy S24 phones were launched on January 17, 2024, it's a safe bet that we'll see the Galaxy S25 replacements around a year later. Most well-placed sources, including South Korean outlet Financial News, are predicting an Unpacked event on Wednesday, January 22, 2025—with a possible on-sale date of February 7.
There's some debate about whether or not the Galaxy S25 Slim will appear at the same time as the other three models, or come out later in the year: It's possible we might get a January tease before a full launch several months down the line. Some tipsters have specified Q2 2025 for this handset (April, May, or June).
This Tweet is currently unavailable. It might be loading or has been removed.
A promotional poster for Galaxy Unpacked January 2025 has leaked online, which makes reference to the January 22 date. It also looks like we can see the corners of four different phones there, backing up the idea that the Slim model is going to be showcased at this event even if it doesn't go on sale immediately.
As for pricing, most of the leaks so far are predicting some kind of bump over the launch prices attached to the Galaxy S24 models (which started at $799 for the base model). This has been attributed to the cost of the Qualcomm Snapdragon 8 Elite chipset, but there may be variations between countries.
Samsung Galaxy S25: four different models
The Galaxy S25 series will start with the standard S25 model: While it will have that faster Snapdragon chip on the inside, on the outside, it doesn't look like much will change. The same 6.2-inch screen is expected, and there might be some tweaks to the camera lens design. Speaking of cameras, several sources say the Galaxy S25 will match the Galaxy S24 with a triple-lens 50MP+10MP+12MP rear camera setup with 3x optical zoom.
It's much the same story with the Samsung Galaxy S25 Plus—there won't be much in the way of upgrades over the Galaxy S24 Plus, apart from the faster silicon inside and a potential bump to 12GB of RAM. The general consensus is that the screen size will stay the same at 6.7 inches, while the rear camera will match the standard S25. We have seen some hands-on images for this handset leaked too.
This Tweet is currently unavailable. It might be loading or has been removed.
There's a bit more changing with the Galaxy 25 Ultra, apparently. It's rumored to have more rounded corners, tiny bezels, and an upgrade to the ultrawide camera that's part of the triple-lens setup on the back (from 12MP to 50MP). The screen size will remain the same at 6.8 inches, but we might see a 16GB option for the RAM, alongside the upgrade to the Snapdragon 8 Elite chipset.
As for the new Galaxy S25 Slim model, based on the leaks that have emerged to date, we're looking at a phone that could be thinner than the rest with a high-end camera setup on the back that beats the standard Galaxy S25. It's not clear what else this handset is going to bring with it, but the Snapdragon 8 Elite should be the processor inside it.
Samsung Galaxy S25: other specs and features
It doesn't look like the Galaxy S25 phones are going to be drastically different from the Galaxy S24 equivalents in a lot of areas: The rather slow charging speeds are apparently going to be the same again, while battery capacities might not be upgraded either (though internal optimizations may lead to better battery life).
There have been some rumors spreading about the colors that are coming with the new phones—and it's mostly what we've seen before, plus some potential new additions. Blues, whites, and grays dominate, though it's not clear exactly what the differences will be from the Galaxy S24 series until we actually see them (the same color could be used but with a new name, for example).
This Tweet is currently unavailable. It might be loading or has been removed.
It looks very probable that the final version of One UI 7.0 (Samsung's take on Android 15) will be pushed out alongside the Galaxy 25 phones. The software is currently in beta testing, and—unsurprisingly—comes with a bunch of new AI features (including call transcriptions) as well as some tweaks to the interface design.
All told, we already have a good idea of what's coming from Samsung with the Galaxy S25 series, although of course, nothing is confirmed until it actually is. While there aren't any dramatic upgrades in the pipeline, it would seem there are a few well-chosen tweaks on the way—as well as, perhaps, a fourth model.
from LifeHacker https://ift.tt/xTvVyYg
Evilginx is an open-source man-in-the-middle attack framework designed to phish login credentials and session cookies, enabling attackers to bypass 2FA safeguards.

“Back in 2017, I was experimenting with extracting cookies from one browser and importing them into another. I realized this technique could effectively take over accounts, bypassing the need for credentials or even MFA authorization. This discovery led me to consider the possibility of executing such an attack remotely by proxying HTTP traffic between the target user and the website. I built a proof-of-concept using Nginx combined with LUA scripting to test this idea. This project eventually evolved into Evilginx v1.0,” Kuba Gretzky, the creator of Evilginx, told Help Net Security.
“When Evilginx v1.0 was released, the concept of using reverse proxies wasn’t new. What set it apart, however, was that it was the first publicly available tool to expose the vulnerabilities of MFA, even on high-profile platforms like Google. Its uniqueness lay in the attention it garnered—it made a lot of noise. In truth, there was nothing cutting-edge about the tool itself; its impact came from how it highlighted a critical security gap,” Gretzky explained.
The author of Evilginx emphasizes that the project demonstrates the techniques skilled attackers may employ. The author asserts that it is the responsibility of defenders to consider such threats and develop strategies to protect users from these types of phishing attacks. Evilginx is intended solely for legitimate penetration testing assignments conducted with explicit written permission from the targeted parties.
Evilginx is available for free download on GitHub.

Must read:
from Help Net Security https://ift.tt/5YxlkPr
