Industry News
RSA is around the corner starting April 17th! To help plan your agenda, we have crafted our Top 10 Recommended Sessions at RSA 2018. These are the sessions we want to attend and recommend all leaders check out, especially if you are responsible for mobile security or app security…or both.
A series of mobile apps built by or connecting with STRAVA have been sharing and publishing activity by geolocation – including what should be highly confidential information about U.S. personnel and military staff locations. Get recommendations on how to protect your organization and staff from risks like STRAVA data collection and sharing.
Android Dirty COW patch released On Monday, Google announced putting the Dirty COW vulnerability (CVE-2016-5195) out to pasture with the 2016-12-05 patch level in the December 2016 Android Security Update. That’s welcome news for owners of Google Nexus and Pixel devices. Of course even with the patch from Google, the long standing problem of Android […]
Certificate Pinning and Hostname Verification: Don’t Get Pinned by a Mobile Man-In-The-Middle Attack
Recent news stories have brought attention to a research paper (“Spinner: Semi-Automatic Detection of Pinning without Hostname Verification”) published this week highlighting man-in-the-middle (MITM) vulnerabilities in a number of public mobile apps. The vulnerability springs from a failure to validate that the hostname on the certificate matches the actual host to which an app connects.
Researchers unveiled a startling discovery this week: 41 percent of the most popular Android apps that implement OAuth 2.0 allow an attacker to remotely impersonate any user account, access personal information from within the app, and make in-app purchases on the user’s dime. In this post I explain OAuth 2.0 and how it affects mobile app security and risk.
Key reinstallation attacks (KRACK) put Wi-Fi security, mobile devices & mobile apps at risk. Learn what you need to do to protect your enterprise.
Android bootloader security and integrity directly affects the security of the devices they run on. Learn about BootStomp and six recently disclosed zero-day vulnerabilities in Android bootloaders.
AccuWeather recently received a public flogging for their mobile app’s privacy practices. Read a quick summary of the incident with a few lessons on critical mobile app security best practices.
Gone are the days when employees kept rolodexes on their desks. According to the “How Much Information?” study conducted by the University of California Berkeley, 92% of all new information in 2002 was stored electronically. This percentage appears to increase each year with some informal estimates that 97% of all organization documents are now created […]
A researcher published the decryption key for the iOS Secure Enclave Processor exposing a critical new risk within the iOS operating system. We’ve verified this information and explained its impact.