Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Register Now →
magnifying glass icon

Research & Threat Intel

Remote USSD Code Execution on Android Devices

By NowSecure Marketing / September 24, 2017 / Comments Off on Remote USSD Code Execution on Android Devices

Samsung Galaxy S3 can be triggered via an injected frame, QR code, Near Field Communications, or SMS text message

Ruminations on App CVEs

By Amy Schurr / September 16, 2017 / Comments Off on Ruminations on App CVEs

Issues associated with many apps’ CEVs.

Announcing Android Vulnerability Test Suite

By Amy Schurr / September 14, 2017 / Comments Off on Announcing Android Vulnerability Test Suite

We have developed a testing suite for detecting the vulnerabilities of Android devices.

Android buckles down and iOS opens up? Trends in platform security affecting developers

By NowSecure Marketing / August 24, 2017 / 0 Comments

Monday night, NowSecure Director of Research David Weinstein highlighted key trends in Android and iOS security in 2016 and participated in a panel discussion during Security by Design’s event “iOS and Android Security – Differences You Need to Know” in McLean, VA. Security by Design educates developers about secure development practices by connecting them with security experts at […]

New Mobile Risk: Decryption key published for iOS Secure Enclave Processor

By Andrew Hoog / August 18, 2017 / Comments Off on New Mobile Risk: Decryption key published for iOS Secure Enclave Processor

A researcher published the decryption key for the iOS Secure Enclave Processor exposing a critical new risk within the iOS operating system. We’ve verified this information and explained its impact.

Raspberry PI hang instruction

By NowSecure Marketing / August 16, 2017 / Comments Off on Raspberry PI hang instruction

Some tips from one of our security pros.

World Writable Code Is Bad, MMMMKAY

By NowSecure Marketing / August 10, 2017 / 0 Comments

Introduction One of the core designs of the Android operating system’s sandbox is to assign different applications a unique user identifier (UID). By doing this, Android reuses the underlying Linux kernel and filesystem properties to enforce boundaries. There are certain situations where apps may share the same UID, but that requires they be signed with […]

Reverse Engineering with JavaScript

By NowSecure Marketing / August 5, 2017 / Comments Off on Reverse Engineering with JavaScript

A security researcher’s tips for using JavaScript for reverse-engineering.

Remote Code Execution as System User on Samsung Phones

By NowSecure Marketing / June 16, 2017 / Comments Off on Remote Code Execution as System User on Samsung Phones

We examine a security vulnerability of Samsung devices.

A Pattern for Remote Code Execution using Arbitrary File Writes and MultiDex Applications

By NowSecure Marketing / June 15, 2017 / Comments Off on A Pattern for Remote Code Execution using Arbitrary File Writes and MultiDex Applications

We examine vulnerabilities that allow attackers to execute code remotely on an Android userUs device.