Home / Blog
INSIGHTS
From the Honeybadger blog
Field notes on security, investigations, privacy, and protection.
- Enterprise iPhone Intrusion: How Apple Business Manager, Automated Device Enrollment, and MDM Misconfiguration Become a Fleet-Wide BreachHow supervised iPhones, Apple Business Manager, ADE, and MDM work — and how misconfiguration or a compromised MDM server turns one flaw into a fleet-wide intrusion.
- Actively Exploited: When Apple Lands in CISA’s KEV Catalog — and Why Patch Velocity WinsWhen an Apple or WebKit zero-day hits CISA’s KEV catalog, it is proof of active exploitation. Here is how patch velocity and MDM close the window.
- Zero-Click Nightmares: Pegasus, BLASTPASS, and Operation Triangulation on iOSHow zero-click iMessage exploits like Pegasus, BLASTPASS, and Operation Triangulation breach iPhones with no user action—and how to defend.
- Trust Permissions Under Attack: iOS Certificate Trust, “Trust This Computer,” and Man-in-the-Middle IntrusionHow iOS trust decisions—root CA certificates, enterprise certs, and “Trust This Computer”—become an attack surface, and how to defend against MITM and intrusion.
- Mercenary Spyware on Android: Predator, Hermit, and the Permissions They ExploitHow mercenary spyware like Predator and Hermit compromises Android via zero-click exploit chains and abused permissions, and how high-risk users defend.
- Rogue MDM & Malicious Configuration Profiles: How Attackers Hijack iPhones and iPadsHow threat actors abuse rogue MDM enrollment and malicious .mobileconfig profiles to hijack iPhones and iPads, plus how to detect and defend.
- Sideloading, Fake Apps, and Google Play Droppers: Intrusion Through the App You TrustedHow Android intrusion starts with a malicious app — sideloaded APKs, fake apps, and Google Play droppers — and how users and organizations cut their attack surface.
- Actively Exploited Android Zero-Days: Inside CISA’s KEV Catalog, Qualcomm and Arm Mali Chip Bugs, and the Monthly Android Security BulletinHow Android zero-days in Qualcomm, Arm Mali GPU, and kernel code get exploited, why they land in CISA’s KEV catalog, and how to patch fleets fast.
- Android Enterprise, EMM, and Managed-Device Intrusion: When Mobile Device Management Becomes the Attack SurfaceHow MDM/EMM misconfiguration, malicious DPCs, and fake “device management” social engineering turn Android Enterprise into an attack surface — and how to harden it.
- Device Admin and Accessibility Abuse: How Android Malware Seizes Control of Your PhoneHow Android banking trojans abuse Accessibility Services, overlays, and Device Admin to hijack phones, steal MFA codes, and commit fraud — and how to defend.
- Attacking the Modern Linux Stack: Containers, Kubernetes, and Supply-Chain IntrusionHow threat actors breach cloud-native Linux via exposed Docker APIs, misconfigured Kubernetes, and supply-chain backdoors, and how to defend.
- Linux Privilege Escalation: From Foothold to Root, and the Bugs That Get ThereHow attackers escalate a Linux foothold to root using famous privilege escalation bugs like PwnKit and Dirty Pipe, and how to patch and defend.