Research & Threat Intel
We have developed a testing suite for detecting the vulnerabilities of Android devices.
Monday night, NowSecure Director of Research David Weinstein highlighted key trends in Android and iOS security in 2016 and participated in a panel discussion during Security by Design’s event “iOS and Android Security – Differences You Need to Know” in McLean, VA. Security by Design educates developers about secure development practices by connecting them with security experts at […]
A researcher published the decryption key for the iOS Secure Enclave Processor exposing a critical new risk within the iOS operating system. We’ve verified this information and explained its impact.
Introduction One of the core designs of the Android operating system’s sandbox is to assign different applications a unique user identifier (UID). By doing this, Android reuses the underlying Linux kernel and filesystem properties to enforce boundaries. There are certain situations where apps may share the same UID, but that requires they be signed with […]
A security researcher’s tips for using JavaScript for reverse-engineering.
We examine a security vulnerability of Samsung devices.
We examine vulnerabilities that allow attackers to execute code remotely on an Android userUs device.
The convenience of Instant Apps is appealing, but attackers will view it as a shiny new attack vector, and for me the security jury is still out.
In this post I explain step-by-step how I solved the OWASP Mobile Security Testing Guide (MSTG) Crackme Level 1 using Frida (and how I then automated it).