home.social

#appsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #appsecurity, aggregated by home.social.

fetched live
  1. FYI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #AndroidApps #MobileAdvertising #AdFraud #PrivacyProtection #AppSecurity

  2. FYI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #AndroidApps #MobileAdvertising #AdFraud #PrivacyProtection #AppSecurity

  3. FYI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #AndroidApps #MobileAdvertising #AdFraud #PrivacyProtection #AppSecurity

  4. FYI: Samsung bans proxy SDKs as a quarter of Tizen apps route strangers' traffic: Mnemonic found Bright Data code inside an Editor's Choice Pac-Man game, and 42% of LG apps carry similar SDKs. CTV buyers now face a new invalid-traffic vector. ppc.land/samsung-bans-proxy-sd #Samsung #Tizen #ProxySDKs #AppSecurity #InvalidTraffic

  5. FYI: Samsung bans proxy SDKs as a quarter of Tizen apps route strangers' traffic: Mnemonic found Bright Data code inside an Editor's Choice Pac-Man game, and 42% of LG apps carry similar SDKs. CTV buyers now face a new invalid-traffic vector. ppc.land/samsung-bans-proxy-sd #Samsung #Tizen #ProxySDKs #AppSecurity #InvalidTraffic

  6. FYI: Samsung bans proxy SDKs as a quarter of Tizen apps route strangers' traffic: Mnemonic found Bright Data code inside an Editor's Choice Pac-Man game, and 42% of LG apps carry similar SDKs. CTV buyers now face a new invalid-traffic vector. ppc.land/samsung-bans-proxy-sd #Samsung #Tizen #ProxySDKs #AppSecurity #InvalidTraffic

  7. ICYMI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #Android #MobileAds #AppSecurity #AdFraud #CyberSecurity

  8. ICYMI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #Android #MobileAds #AppSecurity #AdFraud #CyberSecurity

  9. ICYMI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #Android #MobileAds #AppSecurity #AdFraud #CyberSecurity

  10. ICYMI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #Android #MobileAds #AppSecurity #AdFraud #CyberSecurity

  11. ICYMI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #Android #MobileAds #AppSecurity #AdFraud #CyberSecurity

  12. Samsung bans proxy SDKs as a quarter of Tizen apps route strangers' traffic: Mnemonic found Bright Data code inside an Editor's Choice Pac-Man game, and 42% of LG apps carry similar SDKs. CTV buyers now face a new invalid-traffic vector. ppc.land/samsung-bans-proxy-sd #Samsung #Tizen #ProxySDKs #AppSecurity #InvalidTraffic

  13. Samsung bans proxy SDKs as a quarter of Tizen apps route strangers' traffic: Mnemonic found Bright Data code inside an Editor's Choice Pac-Man game, and 42% of LG apps carry similar SDKs. CTV buyers now face a new invalid-traffic vector. ppc.land/samsung-bans-proxy-sd #Samsung #Tizen #ProxySDKs #AppSecurity #InvalidTraffic

  14. Samsung bans proxy SDKs as a quarter of Tizen apps route strangers' traffic: Mnemonic found Bright Data code inside an Editor's Choice Pac-Man game, and 42% of LG apps carry similar SDKs. CTV buyers now face a new invalid-traffic vector. ppc.land/samsung-bans-proxy-sd #Samsung #Tizen #ProxySDKs #AppSecurity #InvalidTraffic

  15. @percepticon @clemensg Die offizielle Gebets-App des Papstes (Click to Pray) soll monatelang die Daten von rund 720.000 Nutzer:innen preisgegeben haben: Namen, E-Mail-Adressen und Herkunftsland waren laut Sicherheitsforscher über eine simple Schwachstelle (IDOR) abrufbar. Besonders brisant: Der Fehler wurde bereits Anfang Januar gemeldet – eine Reaktion blieb offenbar aus, und die Lücke war bei Veröffentlichung des Berichts noch offen. Bereits 2019 war die App wegen gravierender Sicherheitsmängel aufgefallen. Sensible Anwendungen brauchen Sicherheitsprüfungen – nicht nur gute Absichten.

    #Datenschutz #ITSecurity #Cybersecurity #Papst #ClickToPray #AppSecurity #IDOR

  16. @percepticon @clemensg Die offizielle Gebets-App des Papstes (Click to Pray) soll monatelang die Daten von rund 720.000 Nutzer:innen preisgegeben haben: Namen, E-Mail-Adressen und Herkunftsland waren laut Sicherheitsforscher über eine simple Schwachstelle (IDOR) abrufbar. Besonders brisant: Der Fehler wurde bereits Anfang Januar gemeldet – eine Reaktion blieb offenbar aus, und die Lücke war bei Veröffentlichung des Berichts noch offen. Bereits 2019 war die App wegen gravierender Sicherheitsmängel aufgefallen. Sensible Anwendungen brauchen Sicherheitsprüfungen – nicht nur gute Absichten.

    #Datenschutz #ITSecurity #Cybersecurity #Papst #ClickToPray #AppSecurity #IDOR

  17. @percepticon @clemensg Die offizielle Gebets-App des Papstes (Click to Pray) soll monatelang die Daten von rund 720.000 Nutzer:innen preisgegeben haben: Namen, E-Mail-Adressen und Herkunftsland waren laut Sicherheitsforscher über eine simple Schwachstelle (IDOR) abrufbar. Besonders brisant: Der Fehler wurde bereits Anfang Januar gemeldet – eine Reaktion blieb offenbar aus, und die Lücke war bei Veröffentlichung des Berichts noch offen. Bereits 2019 war die App wegen gravierender Sicherheitsmängel aufgefallen. Sensible Anwendungen brauchen Sicherheitsprüfungen – nicht nur gute Absichten.

    #Datenschutz #ITSecurity #Cybersecurity #Papst #ClickToPray #AppSecurity #IDOR

  18. @percepticon @clemensg Die offizielle Gebets-App des Papstes (Click to Pray) soll monatelang die Daten von rund 720.000 Nutzer:innen preisgegeben haben: Namen, E-Mail-Adressen und Herkunftsland waren laut Sicherheitsforscher über eine simple Schwachstelle (IDOR) abrufbar. Besonders brisant: Der Fehler wurde bereits Anfang Januar gemeldet – eine Reaktion blieb offenbar aus, und die Lücke war bei Veröffentlichung des Berichts noch offen. Bereits 2019 war die App wegen gravierender Sicherheitsmängel aufgefallen. Sensible Anwendungen brauchen Sicherheitsprüfungen – nicht nur gute Absichten.

    #Datenschutz #ITSecurity #Cybersecurity #Papst #ClickToPray #AppSecurity #IDOR

  19. @percepticon @clemensg Die offizielle Gebets-App des Papstes (Click to Pray) soll monatelang die Daten von rund 720.000 Nutzer:innen preisgegeben haben: Namen, E-Mail-Adressen und Herkunftsland waren laut Sicherheitsforscher über eine simple Schwachstelle (IDOR) abrufbar. Besonders brisant: Der Fehler wurde bereits Anfang Januar gemeldet – eine Reaktion blieb offenbar aus, und die Lücke war bei Veröffentlichung des Berichts noch offen. Bereits 2019 war die App wegen gravierender Sicherheitsmängel aufgefallen. Sensible Anwendungen brauchen Sicherheitsprüfungen – nicht nur gute Absichten.

    #Datenschutz #ITSecurity #Cybersecurity #Papst #ClickToPray #AppSecurity #IDOR

  20. Loupe, an open-source iOS/iPadOS app by Mysk, exposes real device fingerprinting signals—passive, permissioned, and advanced—so users can see what apps can quietly read. Nothing leaves the device unless exported. Explore the code: github.com/mysk-research/loupe 🔍📱 #Privacy #iOS #AppSecurity

  21. Loupe, an open-source iOS/iPadOS app by Mysk, exposes real device fingerprinting signals—passive, permissioned, and advanced—so users can see what apps can quietly read. Nothing leaves the device unless exported. Explore the code: github.com/mysk-research/loupe 🔍📱 #Privacy #iOS #AppSecurity

  22. Loupe, an open-source iOS/iPadOS app by Mysk, exposes real device fingerprinting signals—passive, permissioned, and advanced—so users can see what apps can quietly read. Nothing leaves the device unless exported. Explore the code: github.com/mysk-research/loupe 🔍📱 #Privacy #iOS #AppSecurity

  23. Loupe, an open-source iOS/iPadOS app by Mysk, exposes real device fingerprinting signals—passive, permissioned, and advanced—so users can see what apps can quietly read. Nothing leaves the device unless exported. Explore the code: github.com/mysk-research/loupe 🔍📱

  24. Loupe, an open-source iOS/iPadOS app by Mysk, exposes real device fingerprinting signals—passive, permissioned, and advanced—so users can see what apps can quietly read. Nothing leaves the device unless exported. Explore the code: github.com/mysk-research/loupe 🔍📱 #Privacy #iOS #AppSecurity

  25. See you all tomorrow at our meetup!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    #security #appsecurity #aisecurity

  26. See you all tomorrow at our meetup!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    #security #appsecurity #aisecurity

  27. See you all tomorrow at our meetup!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    #security #appsecurity #aisecurity

  28. See you all tomorrow at our meetup!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    #security #appsecurity #aisecurity

  29. See you all tomorrow at our meetup!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    #security #appsecurity #aisecurity

  30. Last chance to RSVP for our May meetup thanks to 7AI!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  31. Last chance to RSVP for our May meetup thanks to 7AI!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  32. Last chance to RSVP for our May meetup thanks to 7AI!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  33. Last chance to RSVP for our May meetup thanks to 7AI!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  34. Last chance to RSVP for our May meetup thanks to 7AI!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  35. Thank you to 7AI for making our May meetup possible!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us How the internet enables organized cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  36. Thank you to 7AI for making our May meetup possible!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us How the internet enables organized cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  37. Thank you to 7AI for making our May meetup possible!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us How the internet enables organized cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  38. Thank you to 7AI for making our May meetup possible!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us How the internet enables organized cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  39. Thank you to 7AI for making our May meetup possible!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us How the internet enables organized cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  40. Our May meetup is full but you might just get lucky and get a spot in. Make sure to RSVP to be on the waitlist.

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us how the internet enabled organized crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  41. Our May meetup is full but you might just get lucky and get a spot in. Make sure to RSVP to be on the waitlist.

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us how the internet enabled organized crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  42. Our May meetup is full but you might just get lucky and get a spot in. Make sure to RSVP to be on the waitlist.

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us how the internet enabled organized crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  43. Our May meetup is full but you might just get lucky and get a spot in. Make sure to RSVP to be on the waitlist.

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us how the internet enabled organized crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  44. Our May meetup is full but you might just get lucky and get a spot in. Make sure to RSVP to be on the waitlist.

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us how the internet enabled organized crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  45. OpenAI Disrupts macOS App Signing Process After Supply Chain Breach

    OpenAI recently took swift action to protect its users by revoking a macOS app certificate after discovering a malicious library had been downloaded through a GitHub Actions workflow used to sign its applications. This move highlights the vulnerability of even trusted software signing processes to supply chain breaches, and the…

    osintsights.com/openai-disrupt

    #SupplyChain #Macos #AppSecurity #CertificateRevocation #GithubActions

  46. 🔐 Android is rolling out Developer Verification for all devs

    ✔️ Verified identities required
    ✔️ Safer app ecosystem
    ✔️ Still supports sideloading (with warnings)

    A big move toward trust without losing openness 👇
    android-developers.googleblog.

    #Android #AndroidDev #AppSecurity #MobileDev

  47. 🔐 Android is rolling out Developer Verification for all devs

    ✔️ Verified identities required
    ✔️ Safer app ecosystem
    ✔️ Still supports sideloading (with warnings)

    A big move toward trust without losing openness 👇
    android-developers.googleblog.

    #Android #AndroidDev #AppSecurity #MobileDev

  48. 🤔 Oh, look! The #hackers have beaten the White House to the punch by reverse engineering their "super secure" app, revealing shocking, yet unsurprising, details: cookie tricks, GPS stalking, and #GitHub shenanigans. 🙄 And all wrapped up with a WordPress backend – because who needs national security when you have a blog to run? 😂
    thereallo.dev/blog/decompiling #WhiteHouse #cybersecurity #reverseengineering #appsecurity #HackerNews #ngated

  49. 🤔 Oh, look! The #hackers have beaten the White House to the punch by reverse engineering their "super secure" app, revealing shocking, yet unsurprising, details: cookie tricks, GPS stalking, and #GitHub shenanigans. 🙄 And all wrapped up with a WordPress backend – because who needs national security when you have a blog to run? 😂
    thereallo.dev/blog/decompiling #WhiteHouse #cybersecurity #reverseengineering #appsecurity #HackerNews #ngated

  50. 🤔 Oh, look! The #hackers have beaten the White House to the punch by reverse engineering their "super secure" app, revealing shocking, yet unsurprising, details: cookie tricks, GPS stalking, and #GitHub shenanigans. 🙄 And all wrapped up with a WordPress backend – because who needs national security when you have a blog to run? 😂
    thereallo.dev/blog/decompiling #WhiteHouse #cybersecurity #reverseengineering #appsecurity #HackerNews #ngated

  51. 🤔 Oh, look! The #hackers have beaten the White House to the punch by reverse engineering their "super secure" app, revealing shocking, yet unsurprising, details: cookie tricks, GPS stalking, and #GitHub shenanigans. 🙄 And all wrapped up with a WordPress backend – because who needs national security when you have a blog to run? 😂
    thereallo.dev/blog/decompiling #WhiteHouse #cybersecurity #reverseengineering #appsecurity #HackerNews #ngated

  52. 🤔 Oh, look! The #hackers have beaten the White House to the punch by reverse engineering their "super secure" app, revealing shocking, yet unsurprising, details: cookie tricks, GPS stalking, and #GitHub shenanigans. 🙄 And all wrapped up with a WordPress backend – because who needs national security when you have a blog to run? 😂
    thereallo.dev/blog/decompiling #WhiteHouse #cybersecurity #reverseengineering #appsecurity #HackerNews #ngated

  53. What does 'we protect your data' actually mean?

    Most companies: a policy.
    We literally cannot read yours: that's math, not a promise.

    Our engineers see encrypted blobs. Nothing more. AES-256-GCM, key never leaves your device.

    wiggwigg.ca/en/security/applic

    #ZeroKnowledge #Privacy #InfoSec #Fediverse #CanadianTech #PrivacyCanada #IndieWeb #PasswordManager #Encryption #AppSecurity

    1/3

  54. What does 'we protect your data' actually mean?

    Most companies: a policy.
    We literally cannot read yours: that's math, not a promise.

    Our engineers see encrypted blobs. Nothing more. AES-256-GCM, key never leaves your device.

    wiggwigg.ca/en/security/applic

    #ZeroKnowledge #Privacy #InfoSec #Fediverse #CanadianTech #PrivacyCanada #IndieWeb #PasswordManager #Encryption #AppSecurity

    1/3

  55. What does 'we protect your data' actually mean?

    Most companies: a policy.
    We literally cannot read yours: that's math, not a promise.

    Our engineers see encrypted blobs. Nothing more. AES-256-GCM, key never leaves your device.

    wiggwigg.ca/en/security/applic

    #ZeroKnowledge #Privacy #InfoSec #Fediverse #CanadianTech #PrivacyCanada #IndieWeb #PasswordManager #Encryption #AppSecurity

    1/3

  56. Android is rolling out a new security system 🔒 for sideloading that includes developer verification, mandatory wait times, and device restarts. The goal? Disrupting scam tactics while keeping the platform open. Here's how the new flow actually works and what it means for users wanting to install apps outside official stores 📱

    Read the article to learn more: true-tech.net/android-sideload

    #Android #Cybersecurity #Sideloading #AppSecurity #MobileSecurity

    true-tech.net/android-sideload

  57. Android is rolling out a new security system 🔒 for sideloading that includes developer verification, mandatory wait times, and device restarts. The goal? Disrupting scam tactics while keeping the platform open. Here's how the new flow actually works and what it means for users wanting to install apps outside official stores 📱

    Read the article to learn more: true-tech.net/android-sideload

    #Android #Cybersecurity #Sideloading #AppSecurity #MobileSecurity

    true-tech.net/android-sideload

  58. Android is rolling out a new security system 🔒 for sideloading that includes developer verification, mandatory wait times, and device restarts. The goal? Disrupting scam tactics while keeping the platform open. Here's how the new flow actually works and what it means for users wanting to install apps outside official stores 📱

    Read the article to learn more: true-tech.net/android-sideload

    #Android #Cybersecurity #Sideloading #AppSecurity #MobileSecurity

    true-tech.net/android-sideload

  59. Android is rolling out a new security system 🔒 for sideloading that includes developer verification, mandatory wait times, and device restarts. The goal? Disrupting scam tactics while keeping the platform open. Here's how the new flow actually works and what it means for users wanting to install apps outside official stores 📱

    Read the article to learn more: true-tech.net/android-sideload

    #Android #Cybersecurity #Sideloading #AppSecurity #MobileSecurity

    true-tech.net/android-sideload