Research & Threat Intel
Security and privacy vulnerabilities can compromise popular consumer brands.
Many mobile applications rely heavily on web technologies and resources for their functionality. For example, WebViews offer a simple and convenient way to load and display web content directly within a mobile app. However, WebViews can increase the mobile attack surface while introducing significant risk depending on their configuration. Cyberattackers can exploit Android WebViews to […]
Reverse engineering a mobile application means taking apart an Android or iOS binary to learn about its makeup. This insight makes it easier to manipulate an app in ways its developer didn’t originally intend. As a mobile pen tester, security analyst or researcher, knowing how to reverse engineer mobile apps improves the quality and depth […]
Security and privacy vulnerabilities in popular business software could spill corporate secrets.
Smartphone manufacturers ship Android devices with a strict set of permissions and access control systems to protect users from security risks and prevent them from acSmartphone manufacturers ship Android devices with a strict set of permissions and access control systems to protect users and reduce risk.But for users and researchers alike, these controls can limit […]
On Oct. 25, 2022, OpenSSL began pre-notifying organizations of two critical vulnerabilities in OpenSSL 3.0.x. On the positive side, OpenSSL 3.0 had not been widely deployed yet, and even better on Nov 1, 2022, the two vulnerabilities were downgraded from critical to high. However, on the heels of other recent highly impactful vulnerabilities like Log4j […]
NowSecure recently partnered with Coalfire to contribute mobile risk data to the cybersecurity advisory company’s 4th Annual Penetration Risk Report. The report findings reveal the importance of continuous testing in vulnerability management combined with human-based testing to reduce risk. The most successful vulnerability and risk management programs are no longer focused on point-in-time schedules but […]
TL;DR: The Peloton Bike ran an unpatched version of Android 7 which led to it being vulnerable to a number of known issues, most significantly CVE-2021-0326, which could allow an attacker within WiFi range to execute arbitrary code on the device. There is no requirement for the user to interact with any attacker controlled data, […]