home.social

#mobileappsecurity โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mobileappsecurity, aggregated by home.social.

fetched live
  1. Oversecured Flags 1,575 Issues in Android Mental Health Apps
    Oversecured identified 54 high-severity vulnerabilities across 10 apps totaling 14.7M+ installs.
    Technical concerns include:
    โ€ข Improper use of Intent.parseUri()
    โ€ข Insecure PRNG via java.util.Random
    โ€ข Local storage exposure
    โ€ข Plaintext API endpoints in APK
    โ€ข Missing root detection
    These apps handle highly sensitive mental health records, including CBT notes and therapy transcripts.

    Threat modeling implication:
    Mobile health apps may represent high-value data reservoirs with weaker security maturity than regulated healthcare systems.

    Should digital health apps undergo mandatory security audits before distribution?

    Engage below.
    Follow TechNadu for deep-dive cybersecurity reporting.

    #Infosec #MobileAppSecurity #AndroidSecurity #SecureCoding #DigitalHealth #ThreatModeling #AppSec #CyberRisk #DataProtection

  2. ๐Ÿ‹๏ธ ๐—ก๐—ผ๐—ฟ๐˜๐—ต๐—ฆ๐—ฒ๐—ฐ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ ๐—™๐—ผ๐—ฟ๐—บ๐—ฎ๐˜ต๐—ถ๐—ผ๐—ป๐˜ด/๐—ง๐—ฟ๐—ฎ๐—ถ๐—ป๐—ถ๐—ป๐—ด๐˜ด (6/12): "Reverse, Bypass, Exploit: Mobile Hacking Workshop" ๐—ฝ๐—ฎ๐—ฟ/๐—ฏ๐˜† David Backer & Steven Smiley (Corellium)

    ๐Ÿ“… Date: May 11, 2026 (1 day)
    ๐Ÿ“Š Difficulty: Medium
    ๐Ÿ–ฅ๏ธ Mode: On-Site

    Description: Master mobile app security techniques covering iOS and Android platforms. Learn real-time network traffic analysis, reverse engineering, SSL pinning bypass, and security control bypasses including biometrics and jailbreak detection. Manipulate runtime behavior with Frida and tackle real-world mobile security challenges. Perfect for penetration testers and security professionals. Bonus: One week Corellium Viper trial and mobile CTF access.

    About the trainers:
    David Backer is a systems engineer focused on mobile application security testing. He works across various of layers of the Corellium tech stack to help customers adopt the platform's many features. Before Corellium, he fabricated cutting edge microprocessors in high-volume factories as well as designed, modeled, and fabricated novel silicon research devices. David also has experience with distributed systems, cryptography, data visualization, and business management.

    Steven Smiley is a Senior Product Manager at MAST Solutions with over a decade of experience in mobile penetration testing and mobile application security. He holds a degree in Computer Security and Investigations from Fleming College and maintains two SANS certifications in mobile security and forensics (GMOB, GASF). Prior to joining the Corellium team, Steven worked as an independent consultant, leading mobile security assessments and penetration testing engagements for a wide range of organizations.

    ๐Ÿ”— Training details: nsec.io/training/2026-reverse-

    #NorthSec #cybersecurity #mobileappsecurity #penetrationtesting

  3. ๐Ÿ‹๏ธ ๐—ก๐—ผ๐—ฟ๐˜๐—ต๐—ฆ๐—ฒ๐—ฐ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ ๐—™๐—ผ๐—ฟ๐—บ๐—ฎ๐˜ต๐—ถ๐—ผ๐—ป๐˜ด/๐—ง๐—ฟ๐—ฎ๐—ถ๐—ป๐—ถ๐—ป๐—ด๐˜ด (6/12): "Reverse, Bypass, Exploit: Mobile Hacking Workshop" ๐—ฝ๐—ฎ๐—ฟ/๐—ฏ๐˜† David Backer & Steven Smiley (Corellium)

    ๐Ÿ“… Date: May 11, 2026 (1 day)
    ๐Ÿ“Š Difficulty: Medium
    ๐Ÿ–ฅ๏ธ Mode: On-Site

    Description: Master mobile app security techniques covering iOS and Android platforms. Learn real-time network traffic analysis, reverse engineering, SSL pinning bypass, and security control bypasses including biometrics and jailbreak detection. Manipulate runtime behavior with Frida and tackle real-world mobile security challenges. Perfect for penetration testers and security professionals. Bonus: One week Corellium Viper trial and mobile CTF access.

    About the trainers:
    David Backer is a systems engineer focused on mobile application security testing. He works across various of layers of the Corellium tech stack to help customers adopt the platform's many features. Before Corellium, he fabricated cutting edge microprocessors in high-volume factories as well as designed, modeled, and fabricated novel silicon research devices. David also has experience with distributed systems, cryptography, data visualization, and business management.

    Steven Smiley is a Senior Product Manager at MAST Solutions with over a decade of experience in mobile penetration testing and mobile application security. He holds a degree in Computer Security and Investigations from Fleming College and maintains two SANS certifications in mobile security and forensics (GMOB, GASF). Prior to joining the Corellium team, Steven worked as an independent consultant, leading mobile security assessments and penetration testing engagements for a wide range of organizations.

    ๐Ÿ”— Training details: nsec.io/training/2026-reverse-

    #NorthSec #cybersecurity #mobileappsecurity #penetrationtesting

  4. How VAPT Strengthens Mobile App Security: Essential Insights for Business Owners

    Discover how VAPT enhances mobile app security, identifies vulnerabilities, ensures compliance, and protects business data from cyber threats for business owners.

    ๐Ÿ“– Read here: linkedin.com/pulse/how-vapt-st

    #MobileAppSecurity #VAPT #CyberSecurity #DataProtection #BusinessSecurity #PenetrationTesting #VulnerabilityAssessment #AppSecurity #ECSInfotech #ECS

  5. Thank you @promon for contributing to support the #OWASP mission by joining as a Gold Corporate Supporter. owasp.org/supporters/list We are excited to work with you this year! #appsec #mobileapp #cybersecurity #mobileappsecurity

  6. Thank you @promon for contributing to support the #OWASP mission by joining as a Gold Corporate Supporter. owasp.org/supporters/list We are excited to work with you this year! #appsec #mobileapp #cybersecurity #mobileappsecurity

  7. Thank you @Promon_Shield for contributing to support the #OWASP mission by joining as a Gold Corporate Supporter. owasp.org/supporters/list We are excited to work with you this year! #appsec #mobileapp #cybersecurity #mobileappsecurity

  8. Thank you @Promon_Shield for contributing to support the #OWASP mission by joining as a Gold Corporate Supporter. owasp.org/supporters/list We are excited to work with you this year! #appsec #mobileapp #cybersecurity #mobileappsecurity

  9. ๐Ÿ”’๐Ÿ“ฑ The best way to test mobile app security isn't just within the confines of Xcode; it's about thinking and acting like an attacker.

    ๐Ÿ”ง Burp Suite's proxy listener allows you to intercept, inspect, and modify traffic between your mobile app and the backend server.

    ๐Ÿ› ๏ธ The Frida toolkit lets you inject scripts into running processes to explore and manipulate the internals of the application in real-time.

    ๐Ÿ” Use tools like MobSF for automated, all-in-one mobile application (Android/iOS) pen-testing.

    ๐Ÿ“ก Wireshark can help you analyze network traffic and look for potential data leaks or vulnerabilities.

    ๐Ÿ”‘ And don't forget about tools like John the Ripper for testing the strength of your app's password policies.

    Think like a hacker, because your adversary certainly will. #CyberSecurity #MobileAppSecurity #InfoSec