A threat intelligence report from a major vendor highlighted two simple but important trends: mobile devices are an increasingly attractive target for malware, and many Internet of Things (IoT) devices are deployed with weak security. Those findings aren’t surprising now, but they’re a useful reminder of where most attacks concentrate and how to reduce your risk.
Why phones and IoT gadgets are favourite targets
Smartphones carry a lot of value: banking apps, email, photos, social accounts and always-on connectivity make them a rich target for malware and spyware. Reports from security labs have shown sustained increases in mobile infections and that smartphones account for the majority of detected mobile-device compromises in some datasets. Android devices are commonly targeted because of their market share and the wider variety of app sources; however, other platforms and devices have been affected too.
IoT devices — everything from Wi‑Fi cameras and digital video recorders to smart plugs and routers — are attractive for different reasons. Many are shipped with default passwords, lack firmware update mechanisms, or haven’t been configured with security in mind. That makes them vulnerable to being hijacked into botnets that launch distributed denial-of-service (DDoS) attacks or to being enlisted for other malicious purposes. Past incidents have shown how thousands of insecure IoT devices can be compromised and used to cause widespread disruption.
What network-based detection can do — and what you should do yourself
One defence highlighted by vendors is network-based detection: analysing traffic on the network to spot signs of infection or suspicious behaviour. Network tools can identify devices that are behaving oddly even if the device itself lacks security software, making this approach useful for service providers and home networks alike. That said, network detection is a complement to device-level hygiene, not a replacement.
Practical steps to reduce your personal risk:
- Keep phones and apps updated: install operating system updates and app patches promptly — they often fix security holes. - Install apps only from official stores and check permissions before granting access to sensitive data. - Use a screen lock, and enable device-level encryption and biometric protections where available. - Be cautious about links, attachments and unexpected messages — social engineering and phishing are common delivery methods for mobile malware. - For IoT devices: change default passwords immediately, apply firmware updates, and disable features you don’t need (remote access, universal plug-and-play, etc.). - Segment IoT on a separate guest network or VLAN so a compromised device has limited access to your phones and computers. - Use a reputable router or network security appliance that offers intrusion detection or device-monitoring features. - Back up important data regularly so you can recover if a device is compromised.
Across homes and organisations, the same basic principles apply: treat connected devices as security endpoints, keep software current, limit unnecessary exposure, and monitor networks for strange behaviour. Reports that once focused on uplifts in infection rates serve as a useful nudge — attackers follow convenience, and convenience still too often comes at the expense of basic security. Taking a few straightforward steps will make you much less attractive to opportunistic attackers.