#mobilesecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mobilesecurity, aggregated by home.social.
-
Android May Soon Restrict On-Device ADB
https://kitsumed.github.io/blog/posts/android-may-soon-restrict-on-device-adb/
Comments: https://news.ycombinator.com/item?id=49045159
#HackerNews #Android #ADB #Restrictions #MobileSecurity #TechNews #DeveloperUpdates
-
Porto, get ready! 🇵🇹
Join Abraham Aranguren on Sep 23 for a hands-on workshop on practical Android and iOS attacks.
-
RedWing Android malware is a rental spyware sold as malware-as-a-service on Telegram. It steals banking logins, intercepts 2FA, and hijacks phones.
#RedWing #AndroidMalware #MalwareAsAService #Spyware #BankingTrojan #MobileSecurity #InfoSec #Telegram
https://securityonline.info/redwing-android-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
CalyxOS is back! 📲 Release 7.2.2.0 is now online with full maintenance support—future updates will follow. If on older builds or other ROMs, a clean flash is required; 7.2.1.0 test users get OTA. 🚀 https://calyxos.org/news/2026/07/01/calyxos-official-release-is-back/ #CalyxOS #Android #Privacy #MobileSecurity
-
Android 17 launches first on Pixel with floating app Bubbles, temporary location sharing, selective contact access, and stronger device protections. 📱🔐
The release also adds foldable gaming improvements, app memory limits, creator tools, and expanded security features for eligible Android devices. 🎮⚙️🔗 https://blog.google/products-and-platforms/platforms/android/android-17-features/
#TechNews #Android17 #Android #Google #Pixel #Samsung #MobileSecurity #Privacy #OpenSource #Mobile #Smartphone #Smartphones #Technology #Security #Performance #FOSS
-
Android's new Advanced Protection Mode includes Intrusion Logging, a feature designed specifically to capture events relevant to security and related to possible intrusions, with the explicit goal of enabling consensual forensic analysis. This new feature is poised to significantly improve the ability of civil society investigators to identify and investigate sophisticated attacks on Android. https://securitylab.amnesty.org/latest/2026/05/android-intrusion-logging-as-a-new-source-of-data-for-consensual-forensic-analysis/ #mobilesecurity
-
Luma is here!
This week at the inaugural @owasp MAScon in Vienna, NowSecure security researcher @oleavr unveiled Luma: the official #Frida GUI. Persistent sessions, an interactive REPL, frida-trace, and real-time collaborative editing, all in one native app across macOS, iOS, Linux, and Windows.
Luma is free and open source. NowSecure is proud to sponsor the project and contribute engineering resources to its development.
Huge congratulations to @oleavr and the entire Frida team on an incredible launch and what this release represents for the community: https://loom.ly/KRIF_LI
#Luma #ReverseEngineering #MobileSecurity #DeveloperTools #OpenSource #NowSecure #OWASPMAScon
-
Your phone is the primary target for modern hackers. It holds more sensitive data than your laptop, so stop treating it like a secondary device. Time to lock down your mobile perimeter before you become the next statistic. 🛡️💻
-
Fileless RCE on stock Android (~2.5B devices). Reported to Google VRP, confirmed by their own engineering team, closed as NSBC anyway.
#AndroidSecurity #infosec #Android #MobileSecurity #VulnerabilityResearch #RCE #BugBounty #VRP #ResponsibleDisclosure #AppSec #ThreatIntel #WebView #ZeroDay #CVE
-
Looking forward to #OWASP Global AppSec EU and the inaugural #MAScon next week. Excited for the opportunity to learn from researchers and practitioners who are pushing mobile security forward.
Check out some of the sessions: https://loom.ly/qC3L65o
@owasp #OWASPGlobalAppSec #MobileApps #MobileSecurity #SecurityResearch
-
Google is rolling out a new opt-in feature in Android that aims to help security researchers investigate spyware attacks. The feature is called “Intrusion Logging” and is part of Android’s Advanced Protection Mode, which Google launched last year.. Advanced Protection Mode is designed to counter government spyware attacks and police forensic devices that try to extract data from a person’s phone. https://techcrunch.com/2026/05/12/google-launches-new-android-security-feature-to-help-uncover-spyware-attacks/ #mobilesecurity
-
Users worried their phone has a virus get a quick guide: signs, checks, cleanup, and prevention. Rapid battery drain, unknown apps, pop-ups, data spikes — act fast. Read more: https://proton.me/blog/phone-virus 🔍📱🛡️ #MobileSecurity #CyberSafety #Android #iPhone
-
I was tired of digging through endless random cybersecurity lists, so naturally I built another random cybersecurity list - just cleaner, prettier and actually organized.
Hack Hub is a curated directory of useful security resources.
#CyberSecurity #InfoSec #Hacking #EthicalHacking #Pentesting #RedTeam #BlueTeam #DFIR #OSINT #ThreatIntel #MalwareAnalysis #BugBounty #CloudSecurity #MobileSecurity #OpenSource #SecurityTools #SecurityResearch #Linux #Hackers #Tech
-
Mobile apps are not “just apps” anymore!
They’re connected platforms handling identities, payments, sessions, APIs, and critical business workflows.
In this special episode of @sharedsecurity I talked with Joel DeStefano, Senior Product Manager at Guardsquare, about the modern mobile application threat landscape and why organizations need to rethink mobile app security.
We covered runtime manipulation, API abuse, account takeover, fake apps, overlays, reverse engineering, iOS vs Android risk, AI-assisted attacks, and why backend-only security is not enough.
Learn more about Guardsquare:https://guardsquare.com
Watch on YouTube:
https://youtu.be/C5eWp9IB30UListen wherever you like to get your podcasts:
https://sharedsecurity.net/2026/06/10/mobile-application-security-what-every-organization-needs-to-know/ -
Reverse engineered the Mintegral MBridge SDK (common in gaming APKs with aggressive adv).
The SDK assembles exfiltration endpoints at runtime via AES/XOR decryption + Android IPC Intents. No hardcoded domain in the binary. MobSF classifies the package as Advertisement and stops there. Knox and Play Protect see legitimate inter-process communication between signed components — nothing to flag.
Extracted 6 C2/collection domains. Loaded them into AegisDNS as a SIGINT feed.
Both Knox and Play Protect: no block, no alert.
AegisDNS: all 6 blocked at resolution.
The IPC obfuscation chain is effective against every on-device analysis layer. It stops at port 53 — the one operation the OS cannot perform inside the obfuscation boundary.
Full write-up with architecture, the structural argument for perimeter DNS vs MTD, and operational trade-offs (block rate, DoH bypass mitigation via iptables, PCRE2/FFI trade-off): -
Prywatność i cyberbezpieczeństwo to nie są hobbystyczne fanaberie dla ludzi w foliowych czapeczkach. Skompromitowane urządzenie mobilne to bezpośrednie zagrożenie dla Twojego życia osobistego, finansów i spokoju psychicznego.
Właśnie ruszyłem ze swoim blogiem, a to mój pierwszy wpis:
🔗 https://meridian.bearblog.dev/droga_do_grapheneos/Opisuję w nim historię z ukrytym korporacyjnym MDM na moim telefonie i to, jak techniki Incident Response oraz przejście na GrapheneOS pozwoliły mi odzyskać kontrolę.
To mój debiut, dlatego bardzo zależy mi na Waszym feedbacku. Co myślicie o tym tekście? Dajcie znać w komentarzach, czy taka tematyka Was interesuje i czy chcecie kolejne wpisy o konfiguracji i hardeningu GrapheneOS! 🛡️📱
#GrapheneOS #Cybersecurity #Privacy #Prywatnosc #Bezpieczenstwo #FOSS #MobileSecurity #PlFediverse #Blog
-
Android 16 introduced a bug that allows a malicious app to send traffic outside the VPN tunnel, including with “Always-On VPN” + “Block connections without VPN” turned on. At the time of publishing, this affects all VPN apps. https://mullvad.net/en/blog/2026/5/12/any-app-on-recent-android-versions-can-leak-certain-traffic #mobilesecurity
-
Bypassing SSL Pinning on Play Store AVDs without Frida
https://www.mfumis.com/posts/bypassing-ssl-pinning-on-play-store-avds-without-frida/
#cybersecurity #informationsecurity #frida #mobiledevice #infosec #mobilesecurity #mobile