Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Register Now →
magnifying glass icon

NowSecure Marketing

President Trump cybersecurity executive order: A distinct lack of controversy

By NowSecure Marketing / January 31, 2017 / Comments Off on President Trump cybersecurity executive order: A distinct lack of controversy

The Washington Post recently published what they claim is a draft of President Trump’s executive order on cybersecurity1, which reports say he’s expected to sign this afternoon2 (at a press briefing on Tuesday, January 31, Press Secretary Sean Spicer suggested that the executive order would not be signed on Tuesday). There’s little-to-nothing that’s particularly controversial about […]

Samsung Account and GALAXY Apps Technical Breakdown – CVE-2015-0863 and CVE-2015-0864

By NowSecure Marketing / January 26, 2017 / Comments Off on Samsung Account and GALAXY Apps Technical Breakdown – CVE-2015-0863 and CVE-2015-0864

The Corrupdate patch corrects the vulnerabilities discovered in Samsung Account and Samsung GALAXY Apps.

Building the best open-source mobile app security testing tool: Q&A with the creators of Frida and Radare

By NowSecure Marketing / January 24, 2017 / Comments Off on Building the best open-source mobile app security testing tool: Q&A with the creators of Frida and Radare

Imagine a man confined in a room and observed by a researcher over video surveillance. Imagine that the surveillance cameras can also, at any time, zoom in-and-out to scrutinize the atoms, molecules, cells, tissues, organs, or organ systems that make up the man.

Corrupdate vulnerability in Samsung Account App

By NowSecure Marketing / January 23, 2017 / 0 Comments

VULNERABILITY NowSecure has discovered that Samsung Account is susceptible to man-in-the-middle attack (CVE 2015-0864). The vulnerability allows a remote attacker to install a malicious app, which could steal data or attempt other attacks. RECOMMENDATION Since this is a system app, you cannot uninstall. On a trusted network, open any app that requires Samsung login, and […]

Exploiting Printers via Jetdirect Vulnerabilities

By NowSecure Marketing / January 13, 2017 / Comments Off on Exploiting Printers via Jetdirect Vulnerabilities

Sebastiàn Guerrero explains a few of the printer vulnerabilities that can be exploited for denial of service attacks-of perhaps greater worry to companies might be data theft that could easily occur on printer devices that store sensitive information.

GoDaddy domain validation bug a reminder of mobile app security risks

By NowSecure Marketing / January 12, 2017 / Comments Off on GoDaddy domain validation bug a reminder of mobile app security risks

This week domain registrar and web hosting company GoDaddy revealed the introduction of a bug into their domain validation processing system in July 2016. The flaw could have resulted in forged certificates issued to an individual for a domain they don’t own, and highlights security challenges inherent in mobile apps’ dependence on third-party services and […]