The expansion of the mobile attack surface is one of the biggest risks for businesses today, as Shadow AI embedded in everyday applications, combined with aging mobile devices and zero-click exploits, creates new and largely invisible security risks.
See also: Google attributes Axios Supply Chain Attack to UNC1069

The shift to hybrid and remote work models post- 2020 has introduced uncontrolled personal devices through BYOD (Bring Your Own Device), shadow IT, and mobile-first initiatives. This has dramatically increased the number of endpoints beyond traditional company-issued laptops. Attacks have shifted to mobile devices due to the high value of data and financial incentives, with the FBI reporting losses of $16.6 billion in 2024, a 33% over 2023.
Outdated assumptions that mobile operating systems are “secure by default” still prevail, despite the fact that mobile security lags behind endpoint and cloud protections. The problem is exacerbated by Shadow AI in applications and parallel privacy environments that evade the controls of MDM (Mobile Device Management) systems.
Major Incidents and Mobile Attack Surface Expansions
Recent incidents reveal the scope of the threat. The Stryker showed how attackers can compromise the MDM, allowing mass device wipes, app installations, and disabling security controls on thousands of endpoints through abuse of administrative privileges. The Coruna exploit is an advanced exploit chain that targets the iOS and Android, bypassing user interaction, app sandboxes, and traditional detection signals.
Supply chain attacks such as SolarWinds, MOVEit , and Log4Shell have reminded businesses of the widespread risks posed by APIs and shadow IT. T-Mobile faces ongoing supply chain challenges due to its extensive partner ecosystems, requiring red teaming amid the expansion of endpoints in hybrid work.
See also: Axios Supply Chain Attack: Malicious versions distribute RAT

The Coruna exploit is an advanced chain that targets the kernels of mobile operating systems, operating without user interaction and bypassing sandboxes, MDM systems, and traditional detection signals. It affects modern versions of iOS and Android, raising serious concerns for the security of corporate data.
MDM abuse vectors include management console compromise, which allows malicious profiles to be promoted to change settings and disable protections, silent application installations, certificate rotation, and large-scale remote wipes. These are common on platforms that integrate with identity and cloud systems.
Shadow AI and privacy apps create sandboxed parallel environments with separate credentials, storage, and app stores, bypassing corporate visibility into BYOD . These are vulnerable to AI-phishing , Bluetooth/NFC exploits , and unverified connections.
Protection Strategies
Security researchers from iVerify note that attackers are going after high-value data on mobile devices, using AI for automated phishing and exploits that bypass MDM and containerization. Layer8 Security experts emphasize that MDMs are high-value targets, where overly permissive administrator roles allow for fleet-wide abuse.
See also: T-Mobile will translate live phone calls without an app

According to SecurityWeek research, enterprises must develop advanced defenses against mobile threats beyond MDM/containerization, focusing on runtime threat detection for kernel exploits and AI-social engineering. Implementing a zero-trust as an ongoing cultural practice, with red teaming and adversarial testing, is critical.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
