#android-security — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #android-security, aggregated by home.social.
-
🔥 HOW SECURE IS YOUR Wi-Fi? TESTING IT WITH STRYKER v6 📱📡
Stryker v6 is here — and this time I’m putting its Wi-Fi security capabilities to the test. ⚡ Watch the full process on my own test network and see what this mobile security toolkit can actually do. 🐉💥
⚠️ Tested in an authorized environment. Only audit networks you own or have explicit permission to test.
💬 Comment “STRYKER” and I’ll send you the link. 📥🔥
#Stryker #WiFiSecurity #CyberSecurity #AndroidSecurity #EthicalHacking
-
🔥 HOW SECURE IS YOUR Wi-Fi? TESTING IT WITH STRYKER v6 📱📡
Stryker v6 is here — and this time I’m putting its Wi-Fi security capabilities to the test. ⚡ Watch the full process on my own test network and see what this mobile security toolkit can actually do. 🐉💥
⚠️ Tested in an authorized environment. Only audit networks you own or have explicit permission to test.
💬 Comment “STRYKER” and I’ll send you the link. 📥🔥
#Stryker #WiFiSecurity #CyberSecurity #AndroidSecurity #EthicalHacking
-
🔥 STRYKEROSS — YOUR MOBILE SECURITY LAB, ANYWHERE 📱⚡
Turn your Android device into a powerful penetration testing platform. StrykerOSS brings Wi-Fi security, local network analysis, handshake management, Nmap, Nuclei, Metasploit integration, web scanning and more into one mobile toolkit. 🛡️🐉
⚡ Built for both ROOT & ROOTLESS Android devices — giving security researchers the flexibility to learn, test and experiment wherever they go. Rootless Wi-Fi testing can also work with a compatible external wireless adapter. 📡💻
⚠️ Use responsibly and only on devices, networks and systems you own or have explicit permission to test.
💬 Comment “STRYKER” and I’ll send you the download link. 📥🔥
#StrykerOSS #CyberSecurity #AndroidSecurity #Pentesting #EthicalHacking
-
🔥 STRYKEROSS — YOUR MOBILE SECURITY LAB, ANYWHERE 📱⚡
Turn your Android device into a powerful penetration testing platform. StrykerOSS brings Wi-Fi security, local network analysis, handshake management, Nmap, Nuclei, Metasploit integration, web scanning and more into one mobile toolkit. 🛡️🐉
⚡ Built for both ROOT & ROOTLESS Android devices — giving security researchers the flexibility to learn, test and experiment wherever they go. Rootless Wi-Fi testing can also work with a compatible external wireless adapter. 📡💻
⚠️ Use responsibly and only on devices, networks and systems you own or have explicit permission to test.
💬 Comment “STRYKER” and I’ll send you the download link. 📥🔥
#StrykerOSS #CyberSecurity #AndroidSecurity #Pentesting #EthicalHacking
-
🚨 TODAY IS THE DAY — STRYKER v6 IS HERE! 🔥
After all the testing, development and anticipation, the wait is finally over. 💥 Stryker v6 goes PUBLIC TODAY — completely FREE! 🐉📱 The new release brings its full toolkit together, built to work on both ROOTED and NON-ROOTED Android devices. ⚡🔐
🎬 In this video, you’re getting a first look at Stryker v6 and its features in action. The next generation of Stryker is ready. 🚀
👇 Comment “STRYKER” and I’ll send you the link to get the APK when the public release drops! 📥🔥
#Stryker #CyberSecurity #AndroidSecurity #EthicalHacking #CyberKid
-
🚨 TODAY IS THE DAY — STRYKER v6 IS HERE! 🔥
After all the testing, development and anticipation, the wait is finally over. 💥 Stryker v6 goes PUBLIC TODAY — completely FREE! 🐉📱 The new release brings its full toolkit together, built to work on both ROOTED and NON-ROOTED Android devices. ⚡🔐
🎬 In this video, you’re getting a first look at Stryker v6 and its features in action. The next generation of Stryker is ready. 🚀
👇 Comment “STRYKER” and I’ll send you the link to get the APK when the public release drops! 📥🔥
#Stryker #CyberSecurity #AndroidSecurity #EthicalHacking #CyberKid
-
📱🔐 GrapheneOS says Revolut has started blocking customers using its privacy-focused Android OS, alleging the fintech markets the move as “security” while relying on Google Play/device-certification checks instead. Revolut reportedly hasn’t blocked all users already signed in. #GrapheneOS #Revolut #AndroidSecurity https://cyberinsider.com/grapheneos-says-revolut-is-blocking-its-users-over-google-play-checks/
-
📱🔐 GrapheneOS says Revolut has started blocking customers using its privacy-focused Android OS, alleging the fintech markets the move as “security” while relying on Google Play/device-certification checks instead. Revolut reportedly hasn’t blocked all users already signed in. #GrapheneOS #Revolut #AndroidSecurity https://cyberinsider.com/grapheneos-says-revolut-is-blocking-its-users-over-google-play-checks/
-
Androids Datenschleuder in die USA stark einschränken: Wer sich wie ich nicht traut, sein Android-Smartphone aufzugeben, kann an seinem Gerät ordentlich was tun. Hier zum Beispiel die App RethinkDNS von F-Droid. Viele Funktionen von Google senden stetig Daten zu sich nach Hause. Ist das immer nötig? Klick aufs linke Bild... #Datenschutz #Android #Privacy #DigitalSouvereignty #DeGoogle #RethinkDNS #Firewall #TechTips #SelfHosting #PrivacyFirst #AndroidSecurity #DatenSparsamkeit #TechCommunity
-
Androids Datenschleuder in die USA stark einschränken: Wer sich wie ich nicht traut, sein Android-Smartphone aufzugeben, kann an seinem Gerät ordentlich was tun. Hier zum Beispiel die App RethinkDNS von F-Droid. Viele Funktionen von Google senden stetig Daten zu sich nach Hause. Ist das immer nötig? Klick aufs linke Bild... #Datenschutz #Android #Privacy #DigitalSouvereignty #DeGoogle #RethinkDNS #Firewall #TechTips #SelfHosting #PrivacyFirst #AndroidSecurity #DatenSparsamkeit #TechCommunity
-
أصدرت GrapheneOS تحديثاً مهماً (إصدار 2026071100) يستبدل ميزة "secure exec spawning" بتطبيق جديد يضيف خياراً لكل تطبيق لتعزيز التوافقية بشكل فعال. يرفع التحديث مستوى تصحيح الأمان إلى 5 يوليو 2026، ويتضمن أحدث برامج تشغيل Pixel والبرامج الثابتة. كما يعالج العديد من الأخطاء الأساسية التي تؤثر على خدمة الواي فاي متعددة المستخدمين، وتحديد المواقع الجغرافية، وعكس الشاشة الخارجية، وتسجيل الشاشة.
-
The feature can automatically detect and block malicious websites, suspicious calls, phishing attempts and other harmful activities. https://english.mathrubhumi.com/lifestyle/how-to/how-to-enable-advanced-protection-on-android-16-jjga157g?utm_source=dlvr.it&utm_medium=mastodon #HowTo #AndroidUpdate #Google #AndroidSecurity
-
Fileless RCE on stock Android (~2.5B devices). Reported to Google VRP, confirmed by their own engineering team, closed as NSBC anyway.
#AndroidSecurity #infosec #Android #MobileSecurity #VulnerabilityResearch #RCE #BugBounty #VRP #ResponsibleDisclosure #AppSec #ThreatIntel #WebView #ZeroDay #CVE
-
🔥 Learn Android #hacking from practitioners who do it for a living.
2 days. Hands-on: Frida, reverse engineering, pinning & root detection bypasses, CTFs, and real-world attacks.
🎟️ Code: DCTLV26SAVE10 for 10% OFF (first 10)
👉https://training.defcon.org/products/hacking-android-apps-by-example-abraham-aranguren-abhishek-j-m-anirudh-anand-dctlv2026 -
El parche de seguridad de Samsung de junio 2026 corrige 45 vulnerabilidades
La actualización incluye 33 correcciones de Google —cinco críticas y 28 de alta severidad— y 12 fixes propios de Samsung que afectan componentes como Samsung Account, Samsung Cloud, Smart Suggestions y Theme Manager. El despliegue comenzará en Corea del Sur y se extenderá en días al resto del mundo (Fuente Sammobile).
Samsung detalló su actualización de seguridad Android para junio de 2026, y el número habla por sí solo. El parche aborda un total de 45 vulnerabilidades de seguridad en dispositivos Galaxy, incluyendo 33 correcciones de Google para problemas a nivel Android —cinco calificadas como críticas y 28 como de alta severidad— y 12 correcciones específicas de Samsung que cubren componentes como Samsung Account, Samsung Cloud, Smart Suggestions, Theme Manager, Settings y otros servicios de One UI.
En el detalle técnico, 11 de los fixes son provistos por Samsung MX y uno por la división de semiconductores Samsung Exynos, que corrige una vulnerabilidad en el controlador DRM HDR. La mayoría de las correcciones propias de Samsung afectan dispositivos con Android 14, Android 15 y Android 16.
Vale la pena destacar un dato adicional: este parche de seguridad está incluido también en la actualización beta de One UI 9.0 lanzada para el Galaxy S26, por lo que los usuarios del programa de pruebas ya lo tienen disponible.
En cuanto al despliegue, la actualización aún no está llegando a los dispositivos al momento de publicación de este artículo, pero se espera que el rollout comience pronto, muy probablemente iniciando en Corea del Sur. Las actualizaciones de Samsung suelen expandirse a otros mercados en cuestión de días, por lo que la espera no debería ser prolongada. Los dispositivos más nuevos recibirán la actualización primero, aunque esto no es una regla fija.
#Actualizacion #Android16 #AndroidSecurity #ciberseguridad #Exynos #GalaxyS26 #OneUI #parche #PORTADA #Samsung #SamsungAccount #seguridadMovil #SmartSuggestions #ThemeManager #vulnerabilidades -
Google Gemini on Android Exposed to Notification-Based Hijacking
Researchers have uncovered a vulnerability in Google Gemini on Android that allows hackers to hijack the assistant using a single hostile notification, no malicious app required. This shocking exploit lets anyone able to push a notification to a device deliver a payload and take control.
#AndroidSecurity #GoogleGemini #NotificationbasedHijacking #EmergingThreats #MobileSecurity
-
Google Bolsters Android Defenses Against AI-Powered Scam Calls
Google's new fake call detection feature sends a silent signal to verify the caller, instantly warning you if a scammer tries to impersonate someone you know. If the signal is missing, your device double-checks with the caller's actual phone to keep you safe.
#AipoweredScamCalls #FakeCallDetection #AndroidSecurity #Google #EmergingThreats
-
Google Patches Actively Exploited Android Flaw Amid June Update
Google just dropped a crucial security update for Android, fixing 124 vulnerabilities, including a high-severity flaw that's being actively exploited - don't wait, patch up your device now! This critical fix tackles a privilege escalation bug that can be triggered without any user interaction, putting your data at risk.
#AndroidSecurity #Cve202548595 #Google #EmergingThreats #PrivilegeEscalation
-
Network Monitoring with Termux
In this article, I cover practical network monitoring with Termux, packet capture workflows for cybersecurity
https://denizhalil.com/2025/06/16/termux-network-monitoring-android-guide/
#CyberSecurity #Termux #AndroidSecurity #NetworkMonitoring #NetworkSecurity #Linux #tcpdump
-
Network Monitoring with Termux
In this article, I cover practical network monitoring with Termux, packet capture workflows for cybersecurity
https://denizhalil.com/2025/06/16/termux-network-monitoring-android-guide/
#CyberSecurity #Termux #AndroidSecurity #NetworkMonitoring #NetworkSecurity #Linux #tcpdump
-
Ein Konfigurationsfehler legt die komplette .de-Zone lahm. Drei Linux-Kernel-Exploits zielen auf dasselbe Angriffsmuster. Und Daniel Stenberg beschreibt, wie KI-generierte Bug-Reports curl gleichzeitig besser und anstrengender machen.
Unser aktueller Security Digest ordnet ein, was die letzten Wochen wirklich relevant war:
🔐 Copy Fail, Dirty Frag, Dirty Pipe: Local Privilege Escalation bleibt eine der häufigsten Schwachstellenklassen im Linux-Kernel. Unser Take: SELinux ist kein Nice-to-have, sondern die wirksamste Gegenmaßnahme. Nicht-privilegierte Accounts sollten nicht unter unconfined_u laufen. Punkt.
🌐 DNSSEC-Ausfall der .de-Zone: Ein Signierfehler bei der DENIC hat am 05.05. gezeigt, wie fragil zentralisierte DNS-Infrastruktur sein kann.
🤖 KI und Open Source: curl erlebt nach der AI-Slop-Welle jetzt hochwertige Meldungen. Gleichzeitig steigt die Last für Maintainerinnen und Maintainer massiv.
📱 Android Intrusion Logging: Google liefert mit dem Advanced Protection Mode endlich eine echte Datenquelle für mobile Forensik. Wir empfehlen die Aktivierung für exponierte Personen und Organisationen mit erhöhtem Schutzbedarf.
Das Security-Modell aus dem Mobilbereich wird zunehmend zum Vorbild für Desktop und Server. Wer heute noch ohne Mandatory Access Control arbeitet, liefert eine Angriffsfläche, die sich mit wenigen Konfigurationsschritten deutlich reduzieren ließe. Den vollständigen Digest mit allen Quellen und unserer Einordnung finden Sie hier: https://research.hisolutions.com/2026/05/
Wie gehen Sie in Ihrer Organisation mit SELinux um? Und nutzt jemand von Ihnen bereits Android Intrusion Logging in der Vorfallsbehandlung?
#Cybersecurity #SELinux #DNSSEC #AndroidSecurity #OpenSource @brahms @jrt -
Google Bolsters Android Security to Counter Spyware Vendors
Google's new Intrusion Logging feature is a game-changer in the fight against spyware, helping digital forensics researchers uncover sophisticated attacks on Android devices. By recording security incidents like device unlocking and spyware installation, it provides crucial evidence to investigate and take down these threats.
#AndroidSecurity #Spyware #IntrusionLogging #DigitalForensics #AdvancedProtectionMode
-
🎯 Google mette in palio $1,5 Milioni per bucare Android! Prova a superare la sfida. #HackerChallenge #AndroidSecurity ⚔️💰
🔗 https://www.tomshw.it/smartphone/google-android-premi-exploit
-
Google Fortifies Ad Ecosystem, Cracks Down on 8.3B Policy-Violating Ads
Google is taking a giant leap in protecting user privacy and cracking down on fraud, having blocked over 8.3 billion ads and suspended 24.9 million accounts in a single year. This bold move is part of a broader effort to reshape how apps handle sensitive data, with a focus on transparency and security.
#AdEcosystem #OnlineAdvertising #PolicyEnforcement #PrivacyUpdates #AndroidSecurity
-
Mirax Android RAT:
• 220K users via Meta ads
• Full RAT + SOCKS5 proxy
• Residential IP abuse
• Multi-stage evasion
Devices now double as infra.💬 Detection strategies?
Source: https://thehackernews.com/2026/04/mirax-android-rat-turns-devices-into.html
🔁 Share
🔔 Follow @technadu -
Google reveals Pixel 10 modem firmware now uses Rust to reduce baseband security risks
https://fed.brid.gy/r/https://nerds.xyz/2026/04/pixel-10-rust-baseband/
-
EngageLab SDK Flaw Compromises 50M Android Users
A security flaw in the EngageLab SDK has put a whopping 50 million Android users at risk, allowing apps on the same device to bypass Android's security sandbox and gain unauthorized access to sensitive information. This vulnerability, now patched, exposed cryptocurrency wallet users and others to potential data breaches.
#EngagelabSdk #AndroidSecurity #MobileSecurity #ThirdpartySdkVulnerability #EmergingThreats
-
I would strongly encourage everyone who has a Google account to enable Advanced Protection via Google's #AdvancedProtectionProgram https://google.com/advancedprotection and if you have an #AndroidPhone, you should also enable enable Advanced Protection on your device as well.
On Pixel Devices:
-> Settings
-> Security and Privacy
-> Advanced ProtectionAnd turn it on.
This gives you Google's highest level of protection for your device and account.
#GoogleSecurity #androidsecurity #securityforeveryone
:D
-
Android malware advisory
WhatsApp droppers, Accessibility abuse
Full device takeover
OTP theft, overlays, persistence👉 Audit permissions
🔔 Follow TechNadu -
Day 10 of #100VibeProjects 🔍
Built a local web tool that does static security analysis of Android APKs — upload an APK and get a report covering permissions, hardcoded secrets, SDK fingerprinting, cert pinning, and crypto posture.
The interesting part: the methodology came from reverse-engineering the WhiteHouse app teardown that went viral last week. Applied the same five-gate analysis framework to a real banking app.
Found an expired certificate pin (silently disables TLS pinning for all users), a session replay SDK with no confirmed masking rules, and four Adobe tracking SDKs doing cross-device user stitching.
The tool runs entirely locally. No data leaves your machine. APK deleted after analysis.
Stack: Python · Flask · androguard · 380 lines
📝 Blog: mrdee.in
https://mrdee.in/writing/vibecoding-day010-offline-apk-security-analyzer/💻 GitHub Repo: https://github.com/mr-dinesh/Offline-APK-Analyzer
#VibeCoding #AppSec #AndroidSecurity #MobileSecurity #Python #Flask #DFIR #InfoSec #ReverseEngineering #CyberSecurity
-
Day 10 of #100VibeProjects 🔍
Built a local web tool that does static security analysis of Android APKs — upload an APK and get a report covering permissions, hardcoded secrets, SDK fingerprinting, cert pinning, and crypto posture.
The interesting part: the methodology came from reverse-engineering the WhiteHouse app teardown that went viral last week. Applied the same five-gate analysis framework to a real banking app.
Found an expired certificate pin (silently disables TLS pinning for all users), a session replay SDK with no confirmed masking rules, and four Adobe tracking SDKs doing cross-device user stitching.
The tool runs entirely locally. No data leaves your machine. APK deleted after analysis.
Stack: Python · Flask · androguard · 380 lines
📝 Blog: mrdee.in
https://mrdee.in/writing/vibecoding-day010-offline-apk-security-analyzer/💻 GitHub Repo: https://github.com/mr-dinesh/Offline-APK-Analyzer
#VibeCoding #AppSec #AndroidSecurity #MobileSecurity #Python #Flask #DFIR #InfoSec #ReverseEngineering #CyberSecurity
-
Google clamps down on Android developers with mandatory verification
https://fed.brid.gy/r/https://nerds.xyz/2026/03/android-developer-verification/
-
This article more eloquently phrases how I feel about the new #android #sideloading rules: https://www.androidauthority.com/i-dont-recognize-android-i-fell-in-love-with-3650462/ I pretty much agree with everything that this journalist is saying.
The new rules might cause some friction -- but they generally make Android safer for everyone.
And that's always a good thing.
-
This article more eloquently phrases how I feel about the new #android #sideloading rules: https://www.androidauthority.com/i-dont-recognize-android-i-fell-in-love-with-3650462/ I pretty much agree with everything that this journalist is saying.
The new rules might cause some friction -- but they generally make Android safer for everyone.
And that's always a good thing.
-
Android sideloading is getting a new speed bump: Google will require a 24-hour wait before installing apps from unverified developers, a move supposedly meant to make malware and scam-driven installs harder to pull off.
https://thehackernews.com/2026/03/google-adds-24-hour-wait-for-unverified.html
#AndroidSecurity #Cybersecurity #Malware #MobileSecurity #Google
-
Android sideloading is getting a new speed bump: Google will require a 24-hour wait before installing apps from unverified developers, a move supposedly meant to make malware and scam-driven installs harder to pull off.
https://thehackernews.com/2026/03/google-adds-24-hour-wait-for-unverified.html
#AndroidSecurity #Cybersecurity #Malware #MobileSecurity #Google
-
Perseus Android trojan scans notes for crypto seeds & enables full device takeover via Accessibility abuse.
Advanced evasion marks next-gen mobile threats.
-
Areizen présente «Reverse Engineering Android - Part II» (ENSIBS, 2019) — un must pour qui veut creuser le fonctionnement interne des apps Android ! Idéal pour devs & chercheurs en sécurité mobile. Slides et ressources incluses, à découvrir ! #ReverseEngineering #Android #AndroidSecurity #Sécurité #CyberSécurité #Hack2G2 #Areizen #French
https://videos.hack2g2.fr/videos/watch/989d8cb2-fb53-48b2-8b87-05c74ecaa601 -
Signal vs Wire — binary analysis of both APKs (apktool, strings, ELF inspection).
The gap is larger than most people think:
Signal: Rust core (libsignal_jni.so), Kyber-1024 post-quantum hybrid ratchet, SQLCipher for at-rest encryption, SVR with Intel SGX attestation, IME_FLAG_NO_PERSONALIZED_LEARNING (keyboard can't index your messages), zero third-party trackers.
Wire: Kotlin/Ktor, no hardened native core (more accessible to Frida), no SQLCipher (messages extractable in plaintext on rooted devices), no post-quantum, Segment SDK for behavioural telemetry.
But the finding that surprised me most:
Wire APKs from unofficial stores (Uptodown et al.) contain additional tracking workers and ACCESS_SUPERUSER permission requests not present in the official build. Supply chain integrity is not a footnote — it's the threat model.
Conclusion: Signal is the only one of the two suitable for threat models involving physical or administrative device compromise.
soon the full paper
#infosec #AndroidSecurity #Signal #Wire #ReverseEngineering #mobileforensics #supplychain #MASA
-
Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.
Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR — MREnclave verification means even a compromised Signal server can't extract your PIN hash.
But two things stood out:
1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.
2. Certificate revocation endpoints hit http://g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs — without touching message content.
Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.
Soon the full analysis
#infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics
-
Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.
Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR — MREnclave verification means even a compromised Signal server can't extract your PIN hash.
But two things stood out:
1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.
2. Certificate revocation endpoints hit http://g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs — without touching message content.
Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.
Soon the full analysis
#infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics
-
Android 17 is tightening Accessibility API access to stop malware from abusing system permissions.
The update integrates with Advanced Protection Mode to reduce privilege escalation and limit sensitive data access.
-
Android 17 is tightening Accessibility API access to stop malware from abusing system permissions.
The update integrates with Advanced Protection Mode to reduce privilege escalation and limit sensitive data access.
-
🚨 Your Android Phone Can Turn Into a Cybersecurity Lab… 📱🐉
Most people think penetration testing requires a powerful computer.
But tools like ANDRAX-NG are changing that.The new ANDRAX-NG v1002 pre-stable update brings improvements that turn your Android device into a portable security testing environment.
⚡ In this reel you’ll see:
📱 A mobile pentesting platform running on Android
⚔️ Powerful cybersecurity tools in your pocket
🚀 A preview of the new ANDRAX-NG updateYour smartphone can become a portable hacking lab for learning cybersecurity.
⚠️ Demonstration for educational and authorized security research only.
👉 Don’t comment yet
🔁 Share this reel first to support my work
💬 Then comment ANDRAX and tell me what you want to see next#CyberSecurity #EthicalHacking #AndroidSecurity #Pentesting #Infosec