Threat Matrix: Mapping threats across cloud web applications
Microsoft released a Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework mapping threats to cloud-hosted web apps and serverless platforms.
Microsoft introduced the cloud web applications threat matrix, which organizes attack techniques for cloud-hosted web apps and serverless platforms using MITRE ATT&CK tactics, from resource development through impact. The framework covers attack paths spanning application code, managed runtimes, workload identities, and deployment pipelines, cataloging techniques such as subdomain takeover, code injection in connected repositories, compromised registry images, exposed admin interfaces, and serverless trigger injection. It builds on Microsoft's earlier Kubernetes and storage services matrices to help defenders identify visibility gaps, prioritize hardening, and plan investigations in cloud-native environments.
Top 10 Best Cloud Access Security Broker (CASB) Solutions in 2026
2026 CASB guide ranks Netskope first for depth and Microsoft Defender for Cloud Apps for Microsoft estates, as standalone CASB fades into SSE.
Buyer's guide covers ten CASB products across four enforcement modes: API, forward proxy, reverse proxy and log-based discovery. Netskope leads on SaaS activity context depth, while Microsoft Defender for Cloud Apps wins on Microsoft 365 E5 estate economics. The guide argues standalone CASB purchases have largely disappeared into SSE platforms and increasingly overlap with SSPM.
Keepnet launches free SMS/Call Reporter for iOS
Keepnet launched a free iOS app, SMS/Call Reporter, letting users one-tap report smishing and vishing into corporate incident response pipelines.
Keepnet released the free SMS/Call Reporter app for iOS, letting users report suspicious SMS and voice phishing with one tap. For enterprise customers, reports flow into Keepnet Incident Responder alongside email phishing reports. The company cites Verizon 2026 DBIR data showing mobile phishing simulations achieve a 40% higher median click rate than email, and FBI IC3 2025 counted $798 million in smishing and vishing losses. An Android version is planned.
Your passkeys can now move between password managers on Android
Google enabled direct password and passkey transfers between Android password managers, initiated from the destination app without unencrypted file exports.
Android now supports moving passwords and passkeys directly between password managers without exporting them to a file, replacing the previous unencrypted-export workflow. The transfer is initiated in the receiving app, which hands off to Android to detect installed managers and request authorization in the source app. The feature works today with Google Password Manager, 1Password, Bitwarden, and Dashlane, with more partners promised but unnamed. Google says data moves between apps in seconds and calls the handoff secure, without detailing the protections.
GrapheneOS' rewritten Messages app is released
GrapheneOS published version 13 of its rewritten Messaging app, a messaging tool from the privacy-hardened Android OS project.
GrapheneOS released version 13 of its rewritten Messaging application on GitHub. The release surfaced via a Hacker News thread with 61 points and 22 comments. The provided text contains only the release listing, with no vulnerability or exploit details; GrapheneOS is a privacy- and security-focused Android OS project, making the release relevant to mobile privacy tooling.
GrapheneOS Overhauled Default Apps and Secure Clipboard
GrapheneOS announced an overhaul of its default apps and a redesigned secure clipboard in its privacy-focused Android distribution.
The GrapheneOS project posted on Mastodon that it has "overhauled default apps and secure clipboard" in its privacy and security hardened Android OS. The provided text contains only the announcement title and engagement figures, without release notes or technical specifics. Changes to built-in apps and clipboard handling in GrapheneOS are typically relevant to Android privacy and mobile security practitioners.
Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping
Android 17 adds Encrypted Client Hello, Local Network Protection, default Certificate Transparency and operator-controlled 2G disabling to counter Wi-Fi tracking and snooping.
Google announced network security changes in Android 17, led by broad support for Encrypted Client Hello (ECH), which encrypts domain names visible to network operators and eavesdroppers, paired with GREASE decoys where server support is uneven. Jigsaw testing across the top 10,000 domains and 740 ISPs in 202 countries found connection success and interference levels comparable to ordinary TLS. Android 17 also adds Local Network Protection requiring app permission to scan local devices, Certificate Transparency on by default to catch forged certificates, and operator-side 2G disabling to cut exposure to SMS blaster fake base stations. Apps targeting Android 17 get ECH by default via networking libraries such as OkHttp, WebView and HttpEngine.
Product showcase: ScamNet looks for warning signs in suspicious calls and shady links
Synaptrex's ScamNet app filters scam calls, messages and websites on Apple devices using on-device AI and reputation checks.
ScamNet: Anti-Scam Suite from Synaptrex Technologies is a free consumer app (with ScamNet+ subscription) for iPhone, iPad and Mac that blocks robocalls and spam via iOS Call Blocking & Identification, filters unknown senders with an offline detection engine, and provides a Safari extension that analyzes and blocks suspicious websites. A Check/Report tool accepts phone numbers, websites, crypto addresses, text, images and audio, and a Device Shield verifies passcode, OS updates and screen-recording status.