Meet us at Black Hat 2026

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
Get a closer look at mobile AI risk: Get a closer look at mobile AI risk: Meet Us at Black Hat Booth #5545
magnifying glass icon

Research & Threat Intel

Call me maybe: Exploiting iOS WebViews to force automatic FaceTime calls

By Amy Schurr / November 22, 2017 / Comments Off on Call me maybe: Exploiting iOS WebViews to force automatic FaceTime calls

An attacker can exploit iOS WebViews to make automatic calls to an attacker-controlled phone number OR FaceTime address. Our research has found that FaceTime URL (facetime://) handlers are frequently overlooked in iOS applications. The oversight allows an attacker to potentially capture a video or snapshot of the affected user by directing them to a webpage from within a vulnerable WebView.

Android malware analysis with Radare: Dissecting the Triada Trojan

By NowSecure Marketing / November 21, 2017 / Comments Off on Android malware analysis with Radare: Dissecting the Triada Trojan

A blog post providing an introduction on how to use Radare for Android malware analysis. After reading this post, you’ll understand how to use Radare2 to disassemble Android binaries, how to identify suspicious or malicious app behavior, and some of the benefits and limitations of using Radare2 for this use case.

Your Device is Vulnerable … Now What?

By NowSecure Marketing / November 18, 2017 / Comments Off on Your Device is Vulnerable … Now What?

The Android Vulnerability Test Suite lets Android users test their devices for security issues.

iOS 9 Reverse Engineering with JavaScript

By NowSecure Marketing / November 16, 2017 / Comments Off on iOS 9 Reverse Engineering with JavaScript

The new Frida 6.0 includes many exciting functionalities.

How to use Xcode to export an app for security testing

By NowSecure Marketing / November 15, 2017 / Comments Off on How to use Xcode to export an app for security testing

Security analysts typically rely on their development team to export an .ipa file for security testing iOS apps. This post provides step-by-step instructions for using Xcode to export an app for security testing purposes.

OnePlus Device Root Exploit: Backdoor in EngineerMode App for Diagnostics Mode

By NowSecure Marketing / November 14, 2017 / Comments Off on OnePlus Device Root Exploit: Backdoor in EngineerMode App for Diagnostics Mode

Learn more about the OnePlus device backdoor created by the EngineerMode App and how the NowSecure Threat Research Team helped verify this root exploit.

How to compile DVIA for iOS 10 and Xcode 8 for mobile app security testing

By Andrew Hoog / October 25, 2017 / Comments Off on How to compile DVIA for iOS 10 and Xcode 8 for mobile app security testing

If you’ve ever tried to compile DVIA for iOS 10 and Xcode 8, you probably ran into some challenges. This article teaches you step-by-step how to compile DVIA for mobile app security testing.

What is the Dirty COW vulnerability and how does it impact mobile security?

By NowSecure Marketing / October 21, 2017 / Comments Off on What is the Dirty COW vulnerability and how does it impact mobile security?

The Dirty COW vulnerability impacts many mobile devices. I analyzed it and its exploit and ended up writing a plug-in for Radare2.

Remote USSD Code Execution on Android Devices

By NowSecure Marketing / September 24, 2017 / Comments Off on Remote USSD Code Execution on Android Devices

Samsung Galaxy S3 can be triggered via an injected frame, QR code, Near Field Communications, or SMS text message

Ruminations on App CVEs

By Amy Schurr / September 16, 2017 / Comments Off on Ruminations on App CVEs

Issues associated with many apps’ CEVs.