Research & Threat Intel
Escalating software supply-chain attacks pose a serious threat to the public sector and organizationes. Adversaries exploit vulnerabilities in third-party code to compromise a supplier to the vast digital ecosystem downstream. The ripple effect causes widespread disruption, financial loss and reputational damage and even endangers national security. Consider the enormous impact the SolarWinds software supply chain […]
Peloton has become perhaps the most well known and successful fitness equipment company today. It makes several connected fitness products including popular Internet-connected stationary exercise bikes and publishes an impressive library of live and on-demand course content. The class platform offers an immersive experience that makes exercise fun and competitive. But this blog post isn’t […]
Tapping the power of NowSecure Platform, the NowSecure MobileRiskTracker™ interactive benchmark portal continuously scans millions of mobile apps from public app stores. The tool aggregates this data anonymously to show real-time security and privacy analysis of the most popular mobile apps in 12 industry categories.
So how loaded for Bear should mobile app developers and mobile app users be? Where and why are nation-state actors targeting mobile vulnerabilities?
In response to high-profile cyberattacks, the U.S. White House announced stringent new cybersecurity guidelines to strengthen American cyberdefenses. Set to roll out over the next year, federal agencies, their private-sector partners and software vendors must begin to prepare their software and services to comply, including mobile apps. Released on May 12, 2021, the Executive Order […]
Picture a world where you browse the web without that little lock next to the URL to assure that your web communications are safe, well at least for the most part anyway. That’s the current state of security with Bluetooth Low Energy (BLE), and more generally the Internet of Things (IoT.) I propose a system to solve the BLE authentication puzzle by automating, and hopefully standardizing, IoT security testing.
iMessage is a widely used secure messaging app and protocol across the Apple ecosystem. Curious about what it would be like to run iMessage on other platforms, we reverse engineered to show how iMessage uses Apple Push Notification (APN) protocol to send and receive messages in conjunction with the system daemon apsd and demonstrate how Apple takes advantage of the fact that it produces the hardware to protect its software.
As a proud sponsor of the OWASP Mobile Security Project and the Global AppSec conference, NowSecure researchers helped develop and maintain the Radare2 Pay v1.0 Android crack-me app featured in the OWASP Mobile Security Testing Guide (MSTG). Intended to be similar to popular mobile payment applications, the Radare2 Pay app is difficult to crack. It features layers and layers of obfuscation and protection and anti-rooting technology in order to delay attacks.
NowSecure Mobile Security Researcher Dawn Isabel has been an avid contributor to bug bounties over the years and has earned many accolades. Before joining the expert research team at NowSecure, Isabel amassed well-rounded experience at IOActive, Hewlett Packard Enterprise, the University of Michigan and Ford Motor Company. We recently spoke with
Isabel about testing the security of iOS and Apple Watch apps, the bug bounty community, and the tools she uses most.
In the course of performing Android application security testing, I suspected that a library called libpac might be vulnerable to exploit. This vulnerability has been assigned CVE-2019-2205. Google deployed a fix and we recommend all users apply it to secure their devices against exploitation.