home.social

#android-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #android-security, aggregated by home.social.

fetched live
  1. 🔥 HOW SECURE IS YOUR Wi-Fi? TESTING IT WITH STRYKER v6 📱📡

    Stryker v6 is here — and this time I’m putting its Wi-Fi security capabilities to the test. ⚡ Watch the full process on my own test network and see what this mobile security toolkit can actually do. 🐉💥

    ⚠️ Tested in an authorized environment. Only audit networks you own or have explicit permission to test.

    💬 Comment “STRYKER” and I’ll send you the link. 📥🔥

    #Stryker #WiFiSecurity #CyberSecurity #AndroidSecurity #EthicalHacking

  2. 🔥 HOW SECURE IS YOUR Wi-Fi? TESTING IT WITH STRYKER v6 📱📡

    Stryker v6 is here — and this time I’m putting its Wi-Fi security capabilities to the test. ⚡ Watch the full process on my own test network and see what this mobile security toolkit can actually do. 🐉💥

    ⚠️ Tested in an authorized environment. Only audit networks you own or have explicit permission to test.

    💬 Comment “STRYKER” and I’ll send you the link. 📥🔥

    #Stryker #WiFiSecurity #CyberSecurity #AndroidSecurity #EthicalHacking

  3. 🔥 STRYKEROSS — YOUR MOBILE SECURITY LAB, ANYWHERE 📱⚡

    Turn your Android device into a powerful penetration testing platform. StrykerOSS brings Wi-Fi security, local network analysis, handshake management, Nmap, Nuclei, Metasploit integration, web scanning and more into one mobile toolkit. 🛡️🐉

    ⚡ Built for both ROOT & ROOTLESS Android devices — giving security researchers the flexibility to learn, test and experiment wherever they go. Rootless Wi-Fi testing can also work with a compatible external wireless adapter. 📡💻

    ⚠️ Use responsibly and only on devices, networks and systems you own or have explicit permission to test.

    💬 Comment “STRYKER” and I’ll send you the download link. 📥🔥

    #StrykerOSS #CyberSecurity #AndroidSecurity #Pentesting #EthicalHacking

  4. 🔥 STRYKEROSS — YOUR MOBILE SECURITY LAB, ANYWHERE 📱⚡

    Turn your Android device into a powerful penetration testing platform. StrykerOSS brings Wi-Fi security, local network analysis, handshake management, Nmap, Nuclei, Metasploit integration, web scanning and more into one mobile toolkit. 🛡️🐉

    ⚡ Built for both ROOT & ROOTLESS Android devices — giving security researchers the flexibility to learn, test and experiment wherever they go. Rootless Wi-Fi testing can also work with a compatible external wireless adapter. 📡💻

    ⚠️ Use responsibly and only on devices, networks and systems you own or have explicit permission to test.

    💬 Comment “STRYKER” and I’ll send you the download link. 📥🔥

    #StrykerOSS #CyberSecurity #AndroidSecurity #Pentesting #EthicalHacking

  5. 🚨 TODAY IS THE DAY — STRYKER v6 IS HERE! 🔥

    After all the testing, development and anticipation, the wait is finally over. 💥 Stryker v6 goes PUBLIC TODAY — completely FREE! 🐉📱 The new release brings its full toolkit together, built to work on both ROOTED and NON-ROOTED Android devices. ⚡🔐

    🎬 In this video, you’re getting a first look at Stryker v6 and its features in action. The next generation of Stryker is ready. 🚀

    👇 Comment “STRYKER” and I’ll send you the link to get the APK when the public release drops! 📥🔥

    #Stryker #CyberSecurity #AndroidSecurity #EthicalHacking #CyberKid

  6. 🚨 TODAY IS THE DAY — STRYKER v6 IS HERE! 🔥

    After all the testing, development and anticipation, the wait is finally over. 💥 Stryker v6 goes PUBLIC TODAY — completely FREE! 🐉📱 The new release brings its full toolkit together, built to work on both ROOTED and NON-ROOTED Android devices. ⚡🔐

    🎬 In this video, you’re getting a first look at Stryker v6 and its features in action. The next generation of Stryker is ready. 🚀

    👇 Comment “STRYKER” and I’ll send you the link to get the APK when the public release drops! 📥🔥

    #Stryker #CyberSecurity #AndroidSecurity #EthicalHacking #CyberKid

  7. 📱🔐 GrapheneOS says Revolut has started blocking customers using its privacy-focused Android OS, alleging the fintech markets the move as “security” while relying on Google Play/device-certification checks instead. Revolut reportedly hasn’t blocked all users already signed in. #GrapheneOS #Revolut #AndroidSecurity cyberinsider.com/grapheneos-sa

  8. 📱🔐 GrapheneOS says Revolut has started blocking customers using its privacy-focused Android OS, alleging the fintech markets the move as “security” while relying on Google Play/device-certification checks instead. Revolut reportedly hasn’t blocked all users already signed in. #GrapheneOS #Revolut #AndroidSecurity cyberinsider.com/grapheneos-sa

  9. Androids Datenschleuder in die USA stark einschränken: Wer sich wie ich nicht traut, sein Android-Smartphone aufzugeben, kann an seinem Gerät ordentlich was tun. Hier zum Beispiel die App RethinkDNS von F-Droid. Viele Funktionen von Google senden stetig Daten zu sich nach Hause. Ist das immer nötig? Klick aufs linke Bild... #Datenschutz #Android #Privacy #DigitalSouvereignty #DeGoogle #RethinkDNS #Firewall #TechTips #SelfHosting #PrivacyFirst #AndroidSecurity #DatenSparsamkeit #TechCommunity

  10. Androids Datenschleuder in die USA stark einschränken: Wer sich wie ich nicht traut, sein Android-Smartphone aufzugeben, kann an seinem Gerät ordentlich was tun. Hier zum Beispiel die App RethinkDNS von F-Droid. Viele Funktionen von Google senden stetig Daten zu sich nach Hause. Ist das immer nötig? Klick aufs linke Bild... #Datenschutz #Android #Privacy #DigitalSouvereignty #DeGoogle #RethinkDNS #Firewall #TechTips #SelfHosting #PrivacyFirst #AndroidSecurity #DatenSparsamkeit #TechCommunity

  11. أصدرت GrapheneOS تحديثاً مهماً (إصدار 2026071100) يستبدل ميزة "secure exec spawning" بتطبيق جديد يضيف خياراً لكل تطبيق لتعزيز التوافقية بشكل فعال. يرفع التحديث مستوى تصحيح الأمان إلى 5 يوليو 2026، ويتضمن أحدث برامج تشغيل Pixel والبرامج الثابتة. كما يعالج العديد من الأخطاء الأساسية التي تؤثر على خدمة الواي فاي متعددة المستخدمين، وتحديد المواقع الجغرافية، وعكس الشاشة الخارجية، وتسجيل الشاشة.

    #GrapheneOS #AndroidSecurity

  12. 🔥 Learn Android from practitioners who do it for a living.

    2 days. Hands-on: Frida, reverse engineering, pinning & root detection bypasses, CTFs, and real-world attacks.

    🎟️ Code: DCTLV26SAVE10 for 10% OFF (first 10)
    👉training.defcon.org/products/h

  13. El parche de seguridad de Samsung de junio 2026 corrige 45 vulnerabilidades

    La actualización incluye 33 correcciones de Google —cinco críticas y 28 de alta severidad— y 12 fixes propios de Samsung que afectan componentes como Samsung Account, Samsung Cloud, Smart Suggestions y Theme Manager. El despliegue comenzará en Corea del Sur y se extenderá en días al resto del mundo (Fuente Sammobile).

    Samsung detalló su actualización de seguridad Android para junio de 2026, y el número habla por sí solo. El parche aborda un total de 45 vulnerabilidades de seguridad en dispositivos Galaxy, incluyendo 33 correcciones de Google para problemas a nivel Android —cinco calificadas como críticas y 28 como de alta severidad— y 12 correcciones específicas de Samsung que cubren componentes como Samsung Account, Samsung Cloud, Smart Suggestions, Theme Manager, Settings y otros servicios de One UI.

    En el detalle técnico, 11 de los fixes son provistos por Samsung MX y uno por la división de semiconductores Samsung Exynos, que corrige una vulnerabilidad en el controlador DRM HDR. La mayoría de las correcciones propias de Samsung afectan dispositivos con Android 14, Android 15 y Android 16.

    Vale la pena destacar un dato adicional: este parche de seguridad está incluido también en la actualización beta de One UI 9.0 lanzada para el Galaxy S26, por lo que los usuarios del programa de pruebas ya lo tienen disponible.

    En cuanto al despliegue, la actualización aún no está llegando a los dispositivos al momento de publicación de este artículo, pero se espera que el rollout comience pronto, muy probablemente iniciando en Corea del Sur. Las actualizaciones de Samsung suelen expandirse a otros mercados en cuestión de días, por lo que la espera no debería ser prolongada. Los dispositivos más nuevos recibirán la actualización primero, aunque esto no es una regla fija.

    #Actualizacion #Android16 #AndroidSecurity #ciberseguridad #Exynos #GalaxyS26 #OneUI #parche #PORTADA #Samsung #SamsungAccount #seguridadMovil #SmartSuggestions #ThemeManager #vulnerabilidades
  14. Google Gemini on Android Exposed to Notification-Based Hijacking

    Researchers have uncovered a vulnerability in Google Gemini on Android that allows hackers to hijack the assistant using a single hostile notification, no malicious app required. This shocking exploit lets anyone able to push a notification to a device deliver a payload and take control.

    osintsights.com/google-gemini-

    #AndroidSecurity #GoogleGemini #NotificationbasedHijacking #EmergingThreats #MobileSecurity

  15. Google Bolsters Android Defenses Against AI-Powered Scam Calls

    Google's new fake call detection feature sends a silent signal to verify the caller, instantly warning you if a scammer tries to impersonate someone you know. If the signal is missing, your device double-checks with the caller's actual phone to keep you safe.

    osintsights.com/google-bolster

    #AipoweredScamCalls #FakeCallDetection #AndroidSecurity #Google #EmergingThreats

  16. Google Patches Actively Exploited Android Flaw Amid June Update

    Google just dropped a crucial security update for Android, fixing 124 vulnerabilities, including a high-severity flaw that's being actively exploited - don't wait, patch up your device now! This critical fix tackles a privilege escalation bug that can be triggered without any user interaction, putting your data at risk.

    osintsights.com/google-patches

    #AndroidSecurity #Cve202548595 #Google #EmergingThreats #PrivilegeEscalation

  17. Ein Konfigurationsfehler legt die komplette .de-Zone lahm. Drei Linux-Kernel-Exploits zielen auf dasselbe Angriffsmuster. Und Daniel Stenberg beschreibt, wie KI-generierte Bug-Reports curl gleichzeitig besser und anstrengender machen.
     
    Unser aktueller Security Digest ordnet ein, was die letzten Wochen wirklich relevant war:
    🔐 Copy Fail, Dirty Frag, Dirty Pipe: Local Privilege Escalation bleibt eine der häufigsten Schwachstellenklassen im Linux-Kernel. Unser Take: SELinux ist kein Nice-to-have, sondern die wirksamste Gegenmaßnahme. Nicht-privilegierte Accounts sollten nicht unter unconfined_u laufen. Punkt.
    🌐 DNSSEC-Ausfall der .de-Zone: Ein Signierfehler bei der DENIC hat am 05.05. gezeigt, wie fragil zentralisierte DNS-Infrastruktur sein kann.
    🤖 KI und Open Source: curl erlebt nach der AI-Slop-Welle jetzt hochwertige Meldungen. Gleichzeitig steigt die Last für Maintainerinnen und Maintainer massiv.
    📱 Android Intrusion Logging: Google liefert mit dem Advanced Protection Mode endlich eine echte Datenquelle für mobile Forensik. Wir empfehlen die Aktivierung für exponierte Personen und Organisationen mit erhöhtem Schutzbedarf.
     
    Das Security-Modell aus dem Mobilbereich wird zunehmend zum Vorbild für Desktop und Server. Wer heute noch ohne Mandatory Access Control arbeitet, liefert eine Angriffsfläche, die sich mit wenigen Konfigurationsschritten deutlich reduzieren ließe. Den vollständigen Digest mit allen Quellen und unserer Einordnung finden Sie hier: research.hisolutions.com/2026/
     
    Wie gehen Sie in Ihrer Organisation mit SELinux um? Und nutzt jemand von Ihnen bereits Android Intrusion Logging in der Vorfallsbehandlung?
     
    #Cybersecurity #SELinux #DNSSEC #AndroidSecurity #OpenSource @brahms @jrt

  18. Google Bolsters Android Security to Counter Spyware Vendors

    Google's new Intrusion Logging feature is a game-changer in the fight against spyware, helping digital forensics researchers uncover sophisticated attacks on Android devices. By recording security incidents like device unlocking and spyware installation, it provides crucial evidence to investigate and take down these threats.

    osintsights.com/google-bolster

    #AndroidSecurity #Spyware #IntrusionLogging #DigitalForensics #AdvancedProtectionMode

  19. Google Fortifies Ad Ecosystem, Cracks Down on 8.3B Policy-Violating Ads

    Google is taking a giant leap in protecting user privacy and cracking down on fraud, having blocked over 8.3 billion ads and suspended 24.9 million accounts in a single year. This bold move is part of a broader effort to reshape how apps handle sensitive data, with a focus on transparency and security.

    osintsights.com/google-fortifi

    #AdEcosystem #OnlineAdvertising #PolicyEnforcement #PrivacyUpdates #AndroidSecurity

  20. Mirax Android RAT:
    • 220K users via Meta ads
    • Full RAT + SOCKS5 proxy
    • Residential IP abuse
    • Multi-stage evasion
    Devices now double as infra.

    💬 Detection strategies?

    Source: thehackernews.com/2026/04/mira

    🔁 Share
    🔔 Follow @technadu

    #Infosec #AndroidSecurity #ThreatIntel

  21. EngageLab SDK Flaw Compromises 50M Android Users

    A security flaw in the EngageLab SDK has put a whopping 50 million Android users at risk, allowing apps on the same device to bypass Android's security sandbox and gain unauthorized access to sensitive information. This vulnerability, now patched, exposed cryptocurrency wallet users and others to potential data breaches.

    osintsights.com/engagelab-sdk-

    #EngagelabSdk #AndroidSecurity #MobileSecurity #ThirdpartySdkVulnerability #EmergingThreats

  22. I would strongly encourage everyone who has a Google account to enable Advanced Protection via Google's #AdvancedProtectionProgram google.com/advancedprotection and if you have an #AndroidPhone, you should also enable enable Advanced Protection on your device as well.

    On Pixel Devices:
    -> Settings
    -> Security and Privacy
    -> Advanced Protection

    And turn it on.

    This gives you Google's highest level of protection for your device and account.

    #GoogleSecurity #androidsecurity #securityforeveryone

    :D

  23. Android malware advisory
    WhatsApp droppers, Accessibility abuse
    Full device takeover
    OTP theft, overlays, persistence

    Source: i4c.mha.gov.in/theme/resources

    👉 Audit permissions
    🔔 Follow TechNadu

    #Infosec #AndroidSecurity #CyberSecurity

  24. Day 10 of #100VibeProjects 🔍

    Built a local web tool that does static security analysis of Android APKs — upload an APK and get a report covering permissions, hardcoded secrets, SDK fingerprinting, cert pinning, and crypto posture.

    The interesting part: the methodology came from reverse-engineering the WhiteHouse app teardown that went viral last week. Applied the same five-gate analysis framework to a real banking app.

    Found an expired certificate pin (silently disables TLS pinning for all users), a session replay SDK with no confirmed masking rules, and four Adobe tracking SDKs doing cross-device user stitching.

    The tool runs entirely locally. No data leaves your machine. APK deleted after analysis.

    Stack: Python · Flask · androguard · 380 lines

    📝 Blog: mrdee.in
    mrdee.in/writing/vibecoding-da

    💻 GitHub Repo: github.com/mr-dinesh/Offline-A

    #VibeCoding #AppSec #AndroidSecurity #MobileSecurity #Python #Flask #DFIR #InfoSec #ReverseEngineering #CyberSecurity

  25. Day 10 of #100VibeProjects 🔍

    Built a local web tool that does static security analysis of Android APKs — upload an APK and get a report covering permissions, hardcoded secrets, SDK fingerprinting, cert pinning, and crypto posture.

    The interesting part: the methodology came from reverse-engineering the WhiteHouse app teardown that went viral last week. Applied the same five-gate analysis framework to a real banking app.

    Found an expired certificate pin (silently disables TLS pinning for all users), a session replay SDK with no confirmed masking rules, and four Adobe tracking SDKs doing cross-device user stitching.

    The tool runs entirely locally. No data leaves your machine. APK deleted after analysis.

    Stack: Python · Flask · androguard · 380 lines

    📝 Blog: mrdee.in
    mrdee.in/writing/vibecoding-da

    💻 GitHub Repo: github.com/mr-dinesh/Offline-A

    #VibeCoding #AppSec #AndroidSecurity #MobileSecurity #Python #Flask #DFIR #InfoSec #ReverseEngineering #CyberSecurity

  26. This article more eloquently phrases how I feel about the new #android #sideloading rules: androidauthority.com/i-dont-re I pretty much agree with everything that this journalist is saying.

    The new rules might cause some friction -- but they generally make Android safer for everyone.

    And that's always a good thing.

    #googleandroid #androidsecurity

  27. This article more eloquently phrases how I feel about the new #android #sideloading rules: androidauthority.com/i-dont-re I pretty much agree with everything that this journalist is saying.

    The new rules might cause some friction -- but they generally make Android safer for everyone.

    And that's always a good thing.

    #googleandroid #androidsecurity

  28. Android sideloading is getting a new speed bump: Google will require a 24-hour wait before installing apps from unverified developers, a move supposedly meant to make malware and scam-driven installs harder to pull off.

    thehackernews.com/2026/03/goog

    #AndroidSecurity #Cybersecurity #Malware #MobileSecurity #Google

  29. Android sideloading is getting a new speed bump: Google will require a 24-hour wait before installing apps from unverified developers, a move supposedly meant to make malware and scam-driven installs harder to pull off.

    thehackernews.com/2026/03/goog

    #AndroidSecurity #Cybersecurity #Malware #MobileSecurity #Google

  30. Areizen présente «Reverse Engineering Android - Part II» (ENSIBS, 2019) — un must pour qui veut creuser le fonctionnement interne des apps Android ! Idéal pour devs & chercheurs en sécurité mobile. Slides et ressources incluses, à découvrir ! #ReverseEngineering #Android #AndroidSecurity #Sécurité #CyberSécurité #Hack2G2 #Areizen #French
    videos.hack2g2.fr/videos/watch

  31. Signal vs Wire — binary analysis of both APKs (apktool, strings, ELF inspection).

    The gap is larger than most people think:

    Signal: Rust core (libsignal_jni.so), Kyber-1024 post-quantum hybrid ratchet, SQLCipher for at-rest encryption, SVR with Intel SGX attestation, IME_FLAG_NO_PERSONALIZED_LEARNING (keyboard can't index your messages), zero third-party trackers.

    Wire: Kotlin/Ktor, no hardened native core (more accessible to Frida), no SQLCipher (messages extractable in plaintext on rooted devices), no post-quantum, Segment SDK for behavioural telemetry.

    But the finding that surprised me most:

    Wire APKs from unofficial stores (Uptodown et al.) contain additional tracking workers and ACCESS_SUPERUSER permission requests not present in the official build. Supply chain integrity is not a footnote — it's the threat model.

    Conclusion: Signal is the only one of the two suitable for threat models involving physical or administrative device compromise.

    soon the full paper

    #infosec #AndroidSecurity #Signal #Wire #ReverseEngineering #mobileforensics #supplychain #MASA

  32. Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.

    Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR — MREnclave verification means even a compromised Signal server can't extract your PIN hash.

    But two things stood out:

    1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.

    2. Certificate revocation endpoints hit g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs — without touching message content.

    Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.

    Soon the full analysis

    #infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics

  33. Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.

    Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR — MREnclave verification means even a compromised Signal server can't extract your PIN hash.

    But two things stood out:

    1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.

    2. Certificate revocation endpoints hit g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs — without touching message content.

    Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.

    Soon the full analysis

    #infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics

  34. Android 17 is tightening Accessibility API access to stop malware from abusing system permissions.

    The update integrates with Advanced Protection Mode to reduce privilege escalation and limit sensitive data access.

    technadu.com/android-17-restri

    #AndroidSecurity #Infosec #MobileSecurity

  35. Android 17 is tightening Accessibility API access to stop malware from abusing system permissions.

    The update integrates with Advanced Protection Mode to reduce privilege escalation and limit sensitive data access.

    technadu.com/android-17-restri

    #AndroidSecurity #Infosec #MobileSecurity

  36. 🚨 Your Android Phone Can Turn Into a Cybersecurity Lab… 📱🐉

    Most people think penetration testing requires a powerful computer.
    But tools like ANDRAX-NG are changing that.

    The new ANDRAX-NG v1002 pre-stable update brings improvements that turn your Android device into a portable security testing environment.

    ⚡ In this reel you’ll see:

    📱 A mobile pentesting platform running on Android
    ⚔️ Powerful cybersecurity tools in your pocket
    🚀 A preview of the new ANDRAX-NG update

    Your smartphone can become a portable hacking lab for learning cybersecurity.

    ⚠️ Demonstration for educational and authorized security research only.

    👉 Don’t comment yet
    🔁 Share this reel first to support my work
    💬 Then comment ANDRAX and tell me what you want to see next

    #CyberSecurity #EthicalHacking #AndroidSecurity #Pentesting #Infosec