home.social

#appsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #appsecurity, aggregated by home.social.

fetched live
  1. FYI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #AndroidApps #MobileAdvertising #AdFraud #PrivacyProtection #AppSecurity

  2. FYI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #AndroidApps #MobileAdvertising #AdFraud #PrivacyProtection #AppSecurity

  3. FYI: Samsung bans proxy SDKs as a quarter of Tizen apps route strangers' traffic: Mnemonic found Bright Data code inside an Editor's Choice Pac-Man game, and 42% of LG apps carry similar SDKs. CTV buyers now face a new invalid-traffic vector. ppc.land/samsung-bans-proxy-sd #Samsung #Tizen #ProxySDKs #AppSecurity #InvalidTraffic

  4. FYI: Samsung bans proxy SDKs as a quarter of Tizen apps route strangers' traffic: Mnemonic found Bright Data code inside an Editor's Choice Pac-Man game, and 42% of LG apps carry similar SDKs. CTV buyers now face a new invalid-traffic vector. ppc.land/samsung-bans-proxy-sd #Samsung #Tizen #ProxySDKs #AppSecurity #InvalidTraffic

  5. ICYMI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #Android #MobileAds #AppSecurity #AdFraud #CyberSecurity

  6. ICYMI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #Android #MobileAds #AppSecurity #AdFraud #CyberSecurity

  7. ICYMI: DoubleVerify finds dozens of Android apps a month showing ads after calls: Apps abuse Android's Display over other apps permission to fire ads when a call ends, then vanish from the recents list. Can pre-install scans catch them all? ppc.land/doubleverify-finds-do #Android #MobileAds #AppSecurity #AdFraud #CyberSecurity

  8. Samsung bans proxy SDKs as a quarter of Tizen apps route strangers' traffic: Mnemonic found Bright Data code inside an Editor's Choice Pac-Man game, and 42% of LG apps carry similar SDKs. CTV buyers now face a new invalid-traffic vector. ppc.land/samsung-bans-proxy-sd #Samsung #Tizen #ProxySDKs #AppSecurity #InvalidTraffic

  9. Samsung bans proxy SDKs as a quarter of Tizen apps route strangers' traffic: Mnemonic found Bright Data code inside an Editor's Choice Pac-Man game, and 42% of LG apps carry similar SDKs. CTV buyers now face a new invalid-traffic vector. ppc.land/samsung-bans-proxy-sd #Samsung #Tizen #ProxySDKs #AppSecurity #InvalidTraffic

  10. @percepticon @clemensg Die offizielle Gebets-App des Papstes (Click to Pray) soll monatelang die Daten von rund 720.000 Nutzer:innen preisgegeben haben: Namen, E-Mail-Adressen und Herkunftsland waren laut Sicherheitsforscher über eine simple Schwachstelle (IDOR) abrufbar. Besonders brisant: Der Fehler wurde bereits Anfang Januar gemeldet – eine Reaktion blieb offenbar aus, und die Lücke war bei Veröffentlichung des Berichts noch offen. Bereits 2019 war die App wegen gravierender Sicherheitsmängel aufgefallen. Sensible Anwendungen brauchen Sicherheitsprüfungen – nicht nur gute Absichten.

    #Datenschutz #ITSecurity #Cybersecurity #Papst #ClickToPray #AppSecurity #IDOR

  11. @percepticon @clemensg Die offizielle Gebets-App des Papstes (Click to Pray) soll monatelang die Daten von rund 720.000 Nutzer:innen preisgegeben haben: Namen, E-Mail-Adressen und Herkunftsland waren laut Sicherheitsforscher über eine simple Schwachstelle (IDOR) abrufbar. Besonders brisant: Der Fehler wurde bereits Anfang Januar gemeldet – eine Reaktion blieb offenbar aus, und die Lücke war bei Veröffentlichung des Berichts noch offen. Bereits 2019 war die App wegen gravierender Sicherheitsmängel aufgefallen. Sensible Anwendungen brauchen Sicherheitsprüfungen – nicht nur gute Absichten.

    #Datenschutz #ITSecurity #Cybersecurity #Papst #ClickToPray #AppSecurity #IDOR

  12. @percepticon @clemensg Die offizielle Gebets-App des Papstes (Click to Pray) soll monatelang die Daten von rund 720.000 Nutzer:innen preisgegeben haben: Namen, E-Mail-Adressen und Herkunftsland waren laut Sicherheitsforscher über eine simple Schwachstelle (IDOR) abrufbar. Besonders brisant: Der Fehler wurde bereits Anfang Januar gemeldet – eine Reaktion blieb offenbar aus, und die Lücke war bei Veröffentlichung des Berichts noch offen. Bereits 2019 war die App wegen gravierender Sicherheitsmängel aufgefallen. Sensible Anwendungen brauchen Sicherheitsprüfungen – nicht nur gute Absichten.

    #Datenschutz #ITSecurity #Cybersecurity #Papst #ClickToPray #AppSecurity #IDOR

  13. Loupe, an open-source iOS/iPadOS app by Mysk, exposes real device fingerprinting signals—passive, permissioned, and advanced—so users can see what apps can quietly read. Nothing leaves the device unless exported. Explore the code: github.com/mysk-research/loupe 🔍📱 #Privacy #iOS #AppSecurity

  14. Loupe, an open-source iOS/iPadOS app by Mysk, exposes real device fingerprinting signals—passive, permissioned, and advanced—so users can see what apps can quietly read. Nothing leaves the device unless exported. Explore the code: github.com/mysk-research/loupe 🔍📱 #Privacy #iOS #AppSecurity

  15. Loupe, an open-source iOS/iPadOS app by Mysk, exposes real device fingerprinting signals—passive, permissioned, and advanced—so users can see what apps can quietly read. Nothing leaves the device unless exported. Explore the code: github.com/mysk-research/loupe 🔍📱 #Privacy #iOS #AppSecurity

  16. See you all tomorrow at our meetup!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    #security #appsecurity #aisecurity

  17. See you all tomorrow at our meetup!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    #security #appsecurity #aisecurity

  18. See you all tomorrow at our meetup!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    #security #appsecurity #aisecurity

  19. Last chance to RSVP for our May meetup thanks to 7AI!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  20. Last chance to RSVP for our May meetup thanks to 7AI!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  21. Last chance to RSVP for our May meetup thanks to 7AI!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers shows us how the internet enables organized Cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  22. Thank you to 7AI for making our May meetup possible!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us How the internet enables organized cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  23. Thank you to 7AI for making our May meetup possible!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us How the internet enables organized cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  24. Thank you to 7AI for making our May meetup possible!

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us How the internet enables organized cyber-crime

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  25. Our May meetup is full but you might just get lucky and get a spot in. Make sure to RSVP to be on the waitlist.

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us how the internet enabled organized crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  26. Our May meetup is full but you might just get lucky and get a spot in. Make sure to RSVP to be on the waitlist.

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us how the internet enabled organized crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  27. Our May meetup is full but you might just get lucky and get a spot in. Make sure to RSVP to be on the waitlist.

    This month's meetup we have Anshumaan Mishra who will talk about securing FastAPI Email WebApp while Will Lefevers will show us how the internet enabled organized crime.

    Thank you to 7AI for hosting and sponsoring us this month!

    RSVP at - buff.ly/ydemfjY

    #security #appsecurity #aisecurity

  28. OpenAI Disrupts macOS App Signing Process After Supply Chain Breach

    OpenAI recently took swift action to protect its users by revoking a macOS app certificate after discovering a malicious library had been downloaded through a GitHub Actions workflow used to sign its applications. This move highlights the vulnerability of even trusted software signing processes to supply chain breaches, and the…

    osintsights.com/openai-disrupt

    #SupplyChain #Macos #AppSecurity #CertificateRevocation #GithubActions

  29. 🔐 Android is rolling out Developer Verification for all devs

    ✔️ Verified identities required
    ✔️ Safer app ecosystem
    ✔️ Still supports sideloading (with warnings)

    A big move toward trust without losing openness 👇
    android-developers.googleblog.

    #Android #AndroidDev #AppSecurity #MobileDev

  30. 🤔 Oh, look! The #hackers have beaten the White House to the punch by reverse engineering their "super secure" app, revealing shocking, yet unsurprising, details: cookie tricks, GPS stalking, and #GitHub shenanigans. 🙄 And all wrapped up with a WordPress backend – because who needs national security when you have a blog to run? 😂
    thereallo.dev/blog/decompiling #WhiteHouse #cybersecurity #reverseengineering #appsecurity #HackerNews #ngated

  31. 🤔 Oh, look! The #hackers have beaten the White House to the punch by reverse engineering their "super secure" app, revealing shocking, yet unsurprising, details: cookie tricks, GPS stalking, and #GitHub shenanigans. 🙄 And all wrapped up with a WordPress backend – because who needs national security when you have a blog to run? 😂
    thereallo.dev/blog/decompiling #WhiteHouse #cybersecurity #reverseengineering #appsecurity #HackerNews #ngated

  32. 🤔 Oh, look! The #hackers have beaten the White House to the punch by reverse engineering their "super secure" app, revealing shocking, yet unsurprising, details: cookie tricks, GPS stalking, and #GitHub shenanigans. 🙄 And all wrapped up with a WordPress backend – because who needs national security when you have a blog to run? 😂
    thereallo.dev/blog/decompiling #WhiteHouse #cybersecurity #reverseengineering #appsecurity #HackerNews #ngated

  33. What does 'we protect your data' actually mean?

    Most companies: a policy.
    We literally cannot read yours: that's math, not a promise.

    Our engineers see encrypted blobs. Nothing more. AES-256-GCM, key never leaves your device.

    wiggwigg.ca/en/security/applic

    #ZeroKnowledge #Privacy #InfoSec #Fediverse #CanadianTech #PrivacyCanada #IndieWeb #PasswordManager #Encryption #AppSecurity

    1/3

  34. Android is rolling out a new security system 🔒 for sideloading that includes developer verification, mandatory wait times, and device restarts. The goal? Disrupting scam tactics while keeping the platform open. Here's how the new flow actually works and what it means for users wanting to install apps outside official stores 📱

    Read the article to learn more: true-tech.net/android-sideload

    #Android #Cybersecurity #Sideloading #AppSecurity #MobileSecurity

    true-tech.net/android-sideload

  35. Android is rolling out a new security system 🔒 for sideloading that includes developer verification, mandatory wait times, and device restarts. The goal? Disrupting scam tactics while keeping the platform open. Here's how the new flow actually works and what it means for users wanting to install apps outside official stores 📱

    Read the article to learn more: true-tech.net/android-sideload

    #Android #Cybersecurity #Sideloading #AppSecurity #MobileSecurity

    true-tech.net/android-sideload

  36. Android is rolling out a new security system 🔒 for sideloading that includes developer verification, mandatory wait times, and device restarts. The goal? Disrupting scam tactics while keeping the platform open. Here's how the new flow actually works and what it means for users wanting to install apps outside official stores 📱

    Read the article to learn more: true-tech.net/android-sideload

    #Android #Cybersecurity #Sideloading #AppSecurity #MobileSecurity

    true-tech.net/android-sideload

  37. Google comienza a señalar a las «apps vampiro» – La Play Store ya muestra advertencias de alto consumo de batería

    Se acabó el anonimato para las aplicaciones mal optimizadas. Tal como se anunció a finales de 2025, Google ha comenzado a implementar este 5 de marzo de 2026 una de las funciones más esperadas por los usuarios: avisos visuales directos en la Play Store que alertan si una aplicación consume más batería de lo normal debido a una actividad excesiva en segundo plano (Fuente Google).

    Esta medida, busca presionar a los desarrolladores para que optimicen sus creaciones y ofrecer transparencia total a los usuarios antes de que pulsen el botón de instalar.

    ¿Cómo funciona la advertencia?

    La alerta aparece en un cuadro destacado justo debajo de la calificación por estrellas y los datos de descarga de la aplicación. El mensaje es claro: “Esta aplicación puede usar más batería de lo esperado debido a una alta actividad en segundo plano”.

    Este aviso no es aleatorio, sino que se basa en métricas técnicas estrictas recogidas por Android Vitals:

    • El umbral del «Wake Lock»: Google penaliza a las apps que mantienen el procesador encendido (mediante partial wake locks) durante más de dos horas acumuladas en un periodo de 24 horas mientras la pantalla está apagada.
    • Consistencia en el mal comportamiento: La advertencia solo aparece si el 5% de las sesiones de usuario de esa app superan dicho límite de consumo en los últimos 28 días.

    Castigo doble: Menos visibilidad y advertencias rojas

    Las aplicaciones que superen estos umbrales de «mala conducta» no solo recibirán el distintivo de advertencia, sino que también sufrirán en su posicionamiento:

    1. Exclusión de recomendaciones: Las apps identificadas como «vampiras de batería» dejarán de aparecer en las listas de recomendaciones y sugerencias de la Play Store.
    2. Impacto en búsquedas: Google reducirá su visibilidad en los resultados de búsqueda, priorizando alternativas que demuestren ser más eficientes energéticamente.

    Colaboración con Samsung

    Un dato relevante es que este nuevo sistema de medición ha sido desarrollado en conjunto con Samsung. El gigante coreano aportó datos del mundo real sobre la experiencia de sus usuarios con el drenaje de batería, ayudando a Google a ajustar los algoritmos para que la advertencia sea lo más precisa posible y no castigue injustamente a apps que necesitan procesos de fondo legítimos (como reproductores de música o navegadores GPS).

    ¿Qué deben hacer los desarrolladores?

    Para eliminar este «sello de la vergüenza», los desarrolladores deberán auditar sus procesos de fondo y reducir el uso innecesario de energía. Google ha proporcionado nuevas herramientas de depuración para que puedan identificar exactamente qué proceso está impidiendo que el teléfono entre en modo de suspensión (deep sleep).

    Con esta actualización, Google da un paso definitivo para resolver una de las quejas históricas de Android: la variabilidad en la duración de la batería causada por aplicaciones de terceros que «secuestran» los recursos del sistema sin que el usuario se dé cuenta.

    #android #AndroidVitals #AppSecurity #arielmcorg #Batería #google #infosertec #innovación #PlayStore #PORTADA #Samsung #TechNews2026 #tecnología
  38. Australia’s Under-16 Social Media Ban Begins Dec 10 - Major Compliance + Privacy Impact

    technadu.com/australia-social-

    Platforms will face $49.5M AUD penalties if they fail to enforce age checks. Verification pathways include biometrics, government IDs, financial details, and behavior-tracking signals. Experts highlight the privacy implications of scaling such data collection across multiple platforms.

    VPN-based workarounds are expected - but may expose young users to malicious apps or shady operators.

    #Australia #AgeVerification #Privacy #ChildSafety #Cybersecurity #AppSecurity #TechPolicy

  39. Australia’s Under-16 Social Media Ban Begins Dec 10 - Major Compliance + Privacy Impact

    technadu.com/australia-social-

    Platforms will face $49.5M AUD penalties if they fail to enforce age checks. Verification pathways include biometrics, government IDs, financial details, and behavior-tracking signals. Experts highlight the privacy implications of scaling such data collection across multiple platforms.

    VPN-based workarounds are expected - but may expose young users to malicious apps or shady operators.

    #Australia #AgeVerification #Privacy #ChildSafety #Cybersecurity #AppSecurity #TechPolicy

  40. Did anyone notice that the #Powershell 7.5.4.0 msi installer, as referred to by Microsoft, is flagged as a #trojan by 1 Vendor on Virustotal[.]com ?
    Is this a false positive?
    #Cybersecurity #malware #IT #AppSecurity #Rat

  41. Did anyone notice that the #Powershell 7.5.4.0 msi installer, as referred to by Microsoft, is flagged as a #trojan by 1 Vendor on Virustotal[.]com ?
    Is this a false positive?
    #Cybersecurity #malware #IT #AppSecurity #Rat

  42. Google is enabling sideloading of unverified apps for advanced users soon! 🚀🔓 This move opens new possibilities but also calls for caution with app security. Stay informed and explore new Android flexibility! 📱⚠️ #Google #Android #Sideloading #AppSecurity heise.de/news/Google-Unverifiz

  43. Google is enabling sideloading of unverified apps for advanced users soon! 🚀🔓 This move opens new possibilities but also calls for caution with app security. Stay informed and explore new Android flexibility! 📱⚠️ #Google #Android #Sideloading #AppSecurity heise.de/news/Google-Unverifiz

  44. 🔒 Verify app authenticity effortlessly with AppVerifier! This powerful tool checks app signing certificate hashes to ensure your apps are genuine and secure. Perfect for Android users who value safety and trust. 💪🔐 #AppSecurity #Android #TechSafety #OpenSource

    Explore more: github.com/soupslurpr/AppVerif

  45. 🔒 Verify app authenticity effortlessly with AppVerifier! This powerful tool checks app signing certificate hashes to ensure your apps are genuine and secure. Perfect for Android users who value safety and trust. 💪🔐 #AppSecurity #Android #TechSafety #OpenSource

    Explore more: github.com/soupslurpr/AppVerif

  46. NowSecure was featured in Help Net Security’s Infosec Products of the Month! 🔐 The new NowSecure Privacy offering helps teams find and fix mobile app #privacy risks fast - keeping data safe and compliant: loom.ly/ECgO2TQ

    #AppPrivacy #AppSecurity #MobileSecurity

  47. Neon, the app that *paid* for your call recordings, is now disabled thanks to a security flaw. Yet, it's still a top-downloaded iOS app. Paying for your data *and* exposing it? Now that's what I call a value proposition! What's the sketchiest app you've willingly given your data to? #AppSecurity #PrivacyFail #iOS #TechNews #DataPrivacy
    cnet.com/tech/services-and-sof

  48. 🔒🚀 Un super retour d’expérience d’Amadeus à Riviera DEV 🌴

    - Comment activer la sécurité dès les premières étapes du développement,
    - Automatiser la validation OAuth2 dans la CI grâce aux mocks #Microcks,
    - Garantir la sécurité de bout en bout des applications,
    - Et surtout, impliquer les développeurs dans une véritable approche #DevSecOps.

    👉 youtube.com/watch?v=kBYEwd1Zpz

    Un bel exemple concret d’intégration sécurité + dev dans la vie réelle 💡

    #CloudNative #OAuth2 #CI #AppSecurity #CNCF

  49. Google to verify all Android developers by Sept 2026, closing loopholes in sideloading & third-party stores to boost security & accountability.

    #Google #Android #AppSecurity #Developers #PlayStore #TECHi

    Read Full Article Here :- techi.com/google-verifies-andr