This edition of Techstep Pulse covers the developments that shaped mobile security in June and July 2026. Three areas stand out: a wave of attacks that hit mobile users from multiple directions at the same time, Apple's WWDC preview of iOS 27 and a changing device management model, and Google's reveal of an AI agent that acts on a user's behalf in the background. Together, they describe a mobile landscape where the time available to notice and respond to a threat is getting shorter.

Recent attacks show mobile users are being targeted from every angle at once
This summer's World Cup has turned into one of the largest phishing operations tied to a single sporting event that security researchers say they have seen. It is a useful reminder of how far social engineering has come.
Researchers at Group-IB tracked more than 4,300 fraudulent domains impersonating FIFA's official site. One operation, referred to as Ghost Stadium, ran hundreds of near-perfect clones of FIFA's login page, pulling real images directly from FIFA's own servers to defeat basic visual checks. The FBI issued a public warning in late May. The same wave includes fake streaming apps carrying banking trojans and over 1,700 fraudulent social media accounts pushing fake tickets, jobs, and streaming offers. None of this requires a technical flaw. It only needs someone excited about a match to click the wrong link.
At almost the same time, Microsoft disclosed a critical flaw in its Authenticator app, the tool millions of employees rely on for multi-factor authentication. The mechanism is similar to the World Cup scams: a user approves what looks like a legitimate sign-in request. Once approved, the app can be tricked into leaking a valid work-account access token, without clearly informing the person what they just granted. Because Authenticator underpins MFA for a large share of enterprise environments, a leaked token can function as a way around MFA entirely, not just a stolen password.
The third story is different in kind. Google's June security update for Android fixed a zero-day vulnerability that allows an attacker to escalate privileges and take control of a device without any action from the user. No click, no approval, nothing to fall for. It has already been added to CISA's list of known exploited vulnerabilities.
Taken together, these three stories describe the same mobile user facing pressure from every direction within the same few weeks: a fraud campaign built entirely around convincing someone to click, an authentication app flaw that needs one approved tap, and an operating system flaw that needs nothing at all. User awareness helps against the first two. It does nothing against the third.
That is exactly the kind of layered risk that a combination of patch management and on-device threat detection is built to close, whether the trigger is a technical exploit or a convincing fake login page. Essentials MDM keeps devices on the latest security patch level automatically, and Essentials MTD adds on-device detection on top, catching suspicious behaviour regardless of where it started.
Apple's WWDC: a smarter Siri, and a device management model that is shifting underneath it
Apple used WWDC to preview iOS 27, iPadOS 27, and macOS 27, with most of the attention going to a rebuilt Siri.
The headline changes: Siri can now read messages, email, and calendar through what Apple calls Personal Context. It understands what is currently on the screen through On-Screen Awareness, and it can pull live information from the web. A dedicated Siri app keeps a private, synced record of conversations across Apple devices. iOS 27 supports iPhone 11 and later, but the most capable on-device AI is limited to iPhone 17 and iPhone Air, meaning the same OS version will feel significantly different depending on the hardware underneath it.
For European users specifically, Siri AI will not be available at launch in the EU on iOS, iPadOS, or watchOS, due to ongoing compliance work tied to the Digital Markets Act.
On the management side, Apple confirmed the industry is moving toward Declarative Device Management, with legacy MDM commands, credential management, and Platform SSO all shifting to this new model. New real-time hardware health signals are also coming to management consoles.
For anyone managing a fleet, the significant part is not the new Siri itself. It is that an assistant with visibility into on-screen content and personal data is arriving on the same devices where the underlying management model is also changing. Those two shifts are worth planning for together rather than treating either one as routine.
An AI assistant that can see what is on screen and reach into personal data is a governance question, not just a feature update. And it is arriving at the same time as a structural change in how these devices get managed.
Google I/O: AI that acts without being asked
Google's May developer conference introduced a significant expansion of AI capability across its product lineup. The announcements most relevant to organisations managing mobile fleets centre on one product in particular.
Gemini Spark is a persistent AI agent designed to keep working in the background and complete multi-step tasks on a person's behalf. It starts with Gmail and Google Workspace, with plans to expand to third-party tools. Elsewhere, Gemini 3.5 Flash now powers the Gemini app and Google Search's AI Mode, and Gemini Omni can generate and edit video from text, image, audio, or existing video input.
On the hardware side, Android XR audio glasses built with Samsung, Gentle Monster, and Warby Parker arrive this autumn as a screen-free companion device for voice-based Gemini access.
The practical shift to watch is Spark. An assistant that answers questions is a different thing from an agent that takes action while nobody is actively watching. That changes the question IT needs to be able to answer: not just what did the user do, but what did the user's agent do on their behalf.
Combined with screen-free wearables capable of capturing and acting on information without a deliberate, visible step from the user, the number of active points in a mobile environment is growing. Most mobile policies were not written with that in mind.
Background AI agents and always-on wearables are arriving faster than most organisations' mobile policies are built to handle. Getting ahead of that gap now is considerably cheaper than reacting to it after adoption has already taken place.
Worth watching: Europe wants its own cloud and AI stack
In early June, the European Commission proposed the European Technological Sovereignty Package, aimed at reducing the EU's dependence on non-EU cloud, AI, and semiconductor suppliers. Its centrepiece, the Cloud and AI Development Act, would introduce a tiered sovereignty framework for cloud procurement and aims to roughly triple EU data centre capacity within five to seven years. A companion Chips Act 2.0 targets EU capacity in advanced semiconductor manufacturing.
It is worth being precise about where this stands. This is a legislative proposal, not adopted law. It still requires negotiation in the European Parliament and the Council of the EU, and observers expect the process to run well into 2027 before anything is finalised.
That direction is still worth tracking if data residency, sovereignty, or long-term vendor strategy are on your roadmap. "Built and certified in Europe" is becoming less of a niche preference and more of a question that procurement teams are increasingly expected to have a considered answer for.
Techstep in the Gartner Market Guide for Managed Mobility Services
The June 2026 edition of Gartner's Market Guide for Managed Mobility Services lists Techstep alongside 23 global vendors, recognised for our work in helping organisations manage, secure, and optimise their mobile device fleets.
What this edition adds up to
A phishing wave built on human trust, an AI assistant that can see what is on your screen, and an agent that acts on your behalf without being asked. These are three different technologies moving in the same direction: less time for a person to notice and react, and more need for policy and protection that are already in place before the moment arrives.
Mobile security is no longer a discipline where reacting quickly is enough. The combination of social engineering at scale, authentication layer vulnerabilities, OS-level zero-days, and autonomous AI agents requires a security posture that is continuous, layered, and built for environments that are already more complex than most policies account for.


