However, this disclosure should be a wakeup call to all enterprise CEOs, CIOs and CISOs across the world. Malicious perpetrators have developed similar tools and are using them to attack enterprises where they are most vulnerable and lack visibility – mobile devices! While all endpoints, inside and outside the corporate network have proven to be vulnerable, mobile devices are even more so because they connect to all kinds of public, unsecured networks, have a myriad of personal apps installed, and are often not controlled, monitored or even owned by the corporation. Once a hacker gets malicious code onto the device, it can not only be used to steal sensitive information from that device and the cloud / storage services the device has access to, but it can also be weaponized and used as a vehicle to attack other devices or services within a corporate network. This is not something that you just see in the movies or TV shows. It is happening every day across the globe, and most enterprises don’t have the tools to quantify or combat the threats.
Apple and Google are trying their very best to fix vulnerabilities in their respective OS as soon as they are discovered. That is why it is imperative for all mobile users to update to the latest versions of iOS or Android as soon as possible to mitigate reported vulnerabilities. However, that is not enough to protect the enterprise for 3 reasons:
There is no practical way of completely securing any OS – that is the very nature of software development. At Zimperium, our mobile security engine -z9™, which is powered by Machine Learning, was able to detect all the publicly available kernel exploits for Android and iOS in the last few years without requiring an update.
If you would like to learn more, please Contact Us.