{"id":286614,"date":"2025-11-27T19:05:04","date_gmt":"2025-11-27T19:05:04","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/286614\/"},"modified":"2025-11-27T19:05:04","modified_gmt":"2025-11-27T19:05:04","slug":"cisa-warns-iphone-and-android-users-secure-your-smartphone-now-2","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/286614\/","title":{"rendered":"CISA Warns iPhone And Android Users \u2014 Secure Your Smartphone Now"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/11\/1764172204_482_0x0.jpg\" alt=\"United States Cybersecurity and Infrastructure Security Agency (CISA) logo is seen displayed on a smartphone screen\" data-height=\"1746\" data-width=\"2620\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Secure your smartphone now, CISA warns.<\/p>\n<p>SOPA Images\/LightRocket via Getty Images<\/p>\n<p>Updated November 27 with further security agency advice for iPhone and Android smartphone users, this time from the U.K. National Cyber Security Centre, to accompany the already published advice from the U.S. Cybersecurity and Infrastructure Security Agency.<\/p>\n<p>Hot on the heels of reports of Sturnus spyware being used to effectively bypass encryption and <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/25\/hackers-bypass-signal-telegram-and-whatsapp-encryption-to-read-messages\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/25\/hackers-bypass-signal-telegram-and-whatsapp-encryption-to-read-messages\/\" target=\"_self\" aria-label=\"read private messages\" rel=\"nofollow noopener\">read private messages<\/a> sent by Signal, Telegram and WhatsApp to your smartphone, the U.S. Cybersecurity and Infrastructure Security Agency issued an <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/11\/24\/spyware-allows-cyber-threat-actors-target-users-messaging-applications\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/11\/24\/spyware-allows-cyber-threat-actors-target-users-messaging-applications\" aria-label=\"urgent alert\">urgent alert<\/a> that \u201cmultiple cyber threat actors\u201d are \u201cactively leveraging commercial spyware to target users of mobile messaging applications.\u201d Now CISA has released further urgent guidance that it says individuals at risk of being targeted should  \u201cimmediately review and apply.\u201d Here\u2019s the step-by-step instructions to secure your smartphone, with guides for both iPhone and Android, from <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/11\/update-your-samsung-smartphone-now---cisa-issues-21-day-spyware-warning\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/11\/update-your-samsung-smartphone-now---cisa-issues-21-day-spyware-warning\/\" target=\"_self\" aria-label=\"spyware attack\" rel=\"nofollow noopener\">spyware attack<\/a> according to America\u2019s Cyber Defense Agency.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/26\/amazon-issues-attack-warning-for-300-million-customers\/\" target=\"_blank\" aria-label=\"Amazon Issues Attack Alert \u2014 300 Million Customers Are At Risk Now\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/26\/amazon-issues-attack-warning-for-300-million-customers\/\" rel=\"nofollow noopener\">ForbesAmazon Issues Attack Alert \u2014 300 Million Customers Are At Risk NowBy Davey Winder<\/a>Cyber Attacks Target iPhone And Android Smartphone Users<\/p>\n<p>Cyber attacks come in a myriad of shapes and sizes. From the newly reported <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/26\/london-cyberattacks-confirmed---security-experts-issue-multiple-warnings\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/26\/london-cyberattacks-confirmed---security-experts-issue-multiple-warnings\/\" target=\"_self\" aria-label=\"attacks against London councils\" rel=\"nofollow noopener\">attacks against London councils<\/a>, to those against users of Amazon, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/23\/netflix-and-paypal-users-warned-as-matrix-hackers-attack\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/23\/netflix-and-paypal-users-warned-as-matrix-hackers-attack\/\" target=\"_self\" aria-label=\"Netflix and PayPal\" rel=\"nofollow noopener\">Netflix and PayPal<\/a>, to the highly-targeted and constantly <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/08\/samsung-spyware-attack---critical-landfall-0-day-used-whatsapp-images\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/08\/samsung-spyware-attack---critical-landfall-0-day-used-whatsapp-images\/\" target=\"_self\" aria-label=\"evolving spyware threats\" rel=\"nofollow noopener\">evolving spyware threats<\/a> facing smartphone users. It is the latter that is of concern to CISA, and should be to you as well, especially if you fall into the high-risk category of individual. That is, dear reader, a broad remit: journalists, political activists, government employees, the military, and, well, the list goes on. Better to assume you could be a target, even if only in terms of collateral damage to get to a bigger fish, and secure your smartphones as best you can.<\/p>\n<p>The CISA <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2025-11\/guidance-mobile-communications-best-practices-20251124_508c.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/sites\/default\/files\/2025-11\/guidance-mobile-communications-best-practices-20251124_508c.pdf\" aria-label=\"Mobile Communications Best Practice Guidance\">Mobile Communications Best Practice Guidance<\/a> document, classified as traffic light protocol clear, meaning I am able to share the information contained within, has just been updated and, as well as including recommendations for securing end-to-end encrypted communications, has step-by-step guides to enhance the security and privacy of both iPhone and Android smartphones. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/27\/fbi-warns-that-hackers-are-posing-as-fake-feds---what-you-need-to-know\/\" target=\"_blank\" aria-label=\"FBI Warns That Hackers Are Posing As Fake Feds \u2014 What You Need To Know\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/27\/fbi-warns-that-hackers-are-posing-as-fake-feds---what-you-need-to-know\/\" rel=\"nofollow noopener\">ForbesFBI Warns That Hackers Are Posing As Fake Feds \u2014 What You Need To KnowBy Davey Winder<\/a><\/p>\n<p>iPhone recommendations:<\/p>\n<p>Enable Lockdown Mode to limit apps, websites and features to effectively reduce the attack surface.Disable the send as text message option that would otherwise allow SMS use if end-to-end encrypted iMessage were not available.Use Apple iCloud Private Relay for enhanced security and privacy by protecting Domain Name System queries.Review and restrict app permissions, revoking those that are not essential, especially when it comes to location, camera and microphone.<\/p>\n<p>Android recommendations:<\/p>\n<p>Use smartphone devices from those manufacturers with a commitment to long-term security updates and that support hardware-level security features.Only use RCS messaging if end-to-end encryption is enabled.Configure the Android Private DNS option to use a high-privacy resolver such as Cloudflare\u2019s 1.1.1.1, Google\u2019s 8.8.8.8 Resolver, and Quad9\u2019s 9.9.9.9.Ensure \u2018always use secure connections\u2019 is enabled in the Android Chrome browser.Ensure \u2018enhanced protection for safe browsing\u2019 is enabled in the Android Chrome browser.Ensure \u2018Google Play Protect\u2019 is enabled to detect and prevent malicious app downloads.Review and restrict app permissions, revoking them in the same way as for the iPhone advice.<a class=\"embed-base color-body color-body-border link-embed embed-5\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/27\/do-not-download-these-windows-security-updates-experts-warn\/\" target=\"_blank\" aria-label=\"Do Not Download These Windows Security Updates, Experts Warn\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/27\/do-not-download-these-windows-security-updates-experts-warn\/\" rel=\"nofollow noopener\">ForbesDo Not Download These Windows Security Updates, Experts WarnBy Davey Winder<\/a>National Cyber Security Centre Advice For iPhone And Android Smartphone Users<\/p>\n<p>The National Cyber Security Centre, part of the U.K. Government Communications Headquarters, better known as GCHQ, has a mission-based strategy to \u201cmake the UK the safest place to live and work online.\u201d So, it is hardly surprising to learn that it has also published <a class=\"color-link\" href=\"https:\/\/www.ncsc.gov.uk\/collection\/small-business-guide\/keeping-your-smartphones-and-tablets-safe\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.ncsc.gov.uk\/collection\/small-business-guide\/keeping-your-smartphones-and-tablets-safe\" aria-label=\"recommendations\">recommendations <\/a>for smartphone users on how to keep them, and the data stored within them, secure. <\/p>\n<p>Number one, the NCSC advisory stated, is to ensure that you are using a secure lock screen password or PIN, not \u201ca simple one that can be easily guessed or gleaned from your social media profiles.\u201d That is very solid advice, and you can read more about lock screen PINs to avoid <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/20\/new-iphone-and-android-warning---do-not-use-these-pin-numbers\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/20\/new-iphone-and-android-warning---do-not-use-these-pin-numbers\/\" target=\"_self\" aria-label=\"here\" rel=\"nofollow noopener\">here<\/a>.<\/p>\n<p>Next, we have enabling the built-in find me or tracking function,  a feature of your smartphone, so that lost or stolen devices can be tracked and, most importantly, locked and data deleted if necessary. <\/p>\n<p>Keep your smartphone updated with the latest security patches, it\u2019s free, mostly automated, and can save you from being vulnerable to hack attacks.<\/p>\n<p>Ditto, but for your apps.<\/p>\n<p>Finally, and most controversially in my never humble opinion, is the \u201cdon&#8217;t connect to unknown Wi-Fi hotspots\u201d advice. While it is true that someone could have setup a malicious hotspot in a coffee shop or at the airport, the reality is that this is extremely unlikely and, given the near-ubiquity of HTTPS encryption during communications, the risk is massively reduced when it comes to the majority of snoopers. Yes, if you are a high-value individual, then you could be targeted, but someone just sweeping an entire coffee shop on the off chance of finding a profitable enough mark is slim. Indeed, most cybersecurity professionals of my acquaintance will happily tell you they connect to such networks without fear. If you are concerned, using your mobile 4G or 5G network is recommended if available, like you\u2019d be using a free hotspot if it weren\u2019t.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-6\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/26\/london-cyberattacks-confirmed---security-experts-issue-multiple-warnings\/\" target=\"_blank\" aria-label=\"London Cyberattacks Confirmed \u2014 Security Experts Issue Multiple Warnings\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/26\/london-cyberattacks-confirmed---security-experts-issue-multiple-warnings\/\" rel=\"nofollow noopener\">ForbesLondon Cyberattacks Confirmed \u2014 Security Experts Issue Multiple WarningsBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Secure your smartphone now, CISA warns. SOPA Images\/LightRocket via Getty Images Updated November 27 with further security agency&hellip;\n","protected":false},"author":2,"featured_media":284592,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[2596,115907,115905,115911,115910,115909,115906,115904,2306,115908,61897,86,56,54,55],"class_list":{"0":"post-286614","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile","8":"tag-android","9":"tag-android-privacy","10":"tag-android-security-setup","11":"tag-cisa-smartphone-attack-warning","12":"tag-how-to-secure-your-android-smartphone","13":"tag-how-to-secure-your-iphone","14":"tag-iphone-privacy","15":"tag-iphone-security-setup","16":"tag-mobile","17":"tag-smartphone-security-tips","18":"tag-spyware","19":"tag-technology","20":"tag-uk","21":"tag-united-kingdom","22":"tag-unitedkingdom"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/286614","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=286614"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/286614\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/284592"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=286614"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=286614"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=286614"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}