Industry News
The Apple® App Store® celebrates its 10th anniversary and the original Android store isn’t far behind. A decade in, let’s take a look at how secure these mobile apps are.
As with all things mobile, there are both secure and insecure ways of downloading and using zipped content. Back in 2014, NowSecure identified and properly disclosed zip file download and remote code execution (RCE) vulnerabilities on Android for Samsung and Vungle. Now Pangu has posted about iOS zipfile download issues identified as ZipperDown.
RSA is around the corner starting April 17th! To help plan your agenda, we have crafted our Top 10 Recommended Sessions at RSA 2018. These are the sessions we want to attend and recommend all leaders check out, especially if you are responsible for mobile security or app security…or both.
A series of mobile apps built by or connecting with STRAVA have been sharing and publishing activity by geolocation – including what should be highly confidential information about U.S. personnel and military staff locations. Get recommendations on how to protect your organization and staff from risks like STRAVA data collection and sharing.
Android Dirty COW patch released On Monday, Google announced putting the Dirty COW vulnerability (CVE-2016-5195) out to pasture with the 2016-12-05 patch level in the December 2016 Android Security Update. That’s welcome news for owners of Google Nexus and Pixel devices. Of course even with the patch from Google, the long standing problem of Android […]
Certificate Pinning and Hostname Verification: Don’t Get Pinned by a Mobile Man-In-The-Middle Attack
Recent news stories have brought attention to a research paper (“Spinner: Semi-Automatic Detection of Pinning without Hostname Verification”) published this week highlighting man-in-the-middle (MITM) vulnerabilities in a number of public mobile apps. The vulnerability springs from a failure to validate that the hostname on the certificate matches the actual host to which an app connects.
Researchers unveiled a startling discovery this week: 41 percent of the most popular Android apps that implement OAuth 2.0 allow an attacker to remotely impersonate any user account, access personal information from within the app, and make in-app purchases on the user’s dime. In this post I explain OAuth 2.0 and how it affects mobile app security and risk.
Key reinstallation attacks (KRACK) put Wi-Fi security, mobile devices & mobile apps at risk. Learn what you need to do to protect your enterprise.
Android bootloader security and integrity directly affects the security of the devices they run on. Learn about BootStomp and six recently disclosed zero-day vulnerabilities in Android bootloaders.
AccuWeather recently received a public flogging for their mobile app’s privacy practices. Read a quick summary of the incident with a few lessons on critical mobile app security best practices.