#mobilesecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mobilesecurity, aggregated by home.social.
-
13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.
The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…
-
13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.
The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…
-
13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.
The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…
-
13 malicious Composer themes on Packagist are being used on Vietnamese streaming sites. Installed on OphimCMS or KKPhim, they inject JavaScript and a hidden iframe: mobile visitors may be redirected to ad-fraud and gambling pages, while vulnerable iPhones can be targeted through Safari with an exploit chain reaching the kernel.
The campaign exploits CVE-2025-31277 and CVE-2025-43529, patched in iOS 18.6, 18.7.3…
-
Luma is here!
This week at the inaugural @owasp MAScon in Vienna, NowSecure security researcher @oleavr unveiled Luma: the official #Frida GUI. Persistent sessions, an interactive REPL, frida-trace, and real-time collaborative editing, all in one native app across macOS, iOS, Linux, and Windows.
Luma is free and open source. NowSecure is proud to sponsor the project and contribute engineering resources to its development.
Huge congratulations to @oleavr and the entire Frida team on an incredible launch and what this release represents for the community: https://loom.ly/KRIF_LI
#Luma #ReverseEngineering #MobileSecurity #DeveloperTools #OpenSource #NowSecure #OWASPMAScon
-
I was tired of digging through endless random cybersecurity lists, so naturally I built another random cybersecurity list - just cleaner, prettier and actually organized.
Hack Hub is a curated directory of useful security resources.
#CyberSecurity #InfoSec #Hacking #EthicalHacking #Pentesting #RedTeam #BlueTeam #DFIR #OSINT #ThreatIntel #MalwareAnalysis #BugBounty #CloudSecurity #MobileSecurity #OpenSource #SecurityTools #SecurityResearch #Linux #Hackers #Tech
-
Bypassing SSL Pinning on Play Store AVDs without Frida
https://www.mfumis.com/posts/bypassing-ssl-pinning-on-play-store-avds-without-frida/
#cybersecurity #informationsecurity #frida #mobiledevice #infosec #mobilesecurity #mobile
-
The first ever OWASP MAScon is happening inside OWASP Global AppSec EU 2026 in Vienna, June 25 to 26, during 25 years of OWASP. Organized by Carlos Holguera @grepharder and Sven Schleier, with talks from Carlos, Stefan Bernhardsgrütter, Sergi Alvarez @pancake, Jan Seredynski, Ole André Vadla Ravnås @oleavr, and Jeroen Beckers.
-
Teil 4: Mobile Unabhängigkeit 📱🔓
Nachdem der Desktop befreit war, ging es an das schwierigste Thema, das Smartphone mit Google Android 🚫
Die Hardware-Wahl überrascht viele: Ein Google Pixel 8 Pro.
Warum? Weil es (paradoxerweise) die einzige Hardware ist, die uns erlaubt, den Hersteller komplett auszusperren.
Das Zauberwort heißt GrapheneOS. 🛡️
Die Installation: Web-Installer, USB-Kabel, 10 Minuten Angstschweiß, fertig. Kein Hexenwerk.
Der Alltag: Kein Google-Konto Zwang. Kein Tracking im Hintergrund. Keine Spyware funkt.
Die Apps: F-Droid für FOSS, Aurora Store für den Rest. Und wenn eine App zickt (Banking), läuft sie in einer Sandbox ohne Rechte.
Es ist mein Gerät. Meine Daten. Mein Pixel gehört endlich mir.
Fortsetzung folgt...
#GrapheneOS #Pixel8Pro #Privacy #Android #DeGoogle #OpenSource #MobileSecurity #DigitaleSouveränität #FOSS -
A new Android security evaluation reveals that default protections miss a lot of stalkerware. 🕵️♀️🔍 Researchers warn that even built‑in tools can fail to detect covert stalkerware on devices. Learn more about this crucial finding and how to stay protected: https://cyberinsider.com/androids-default-security-tool-fails-to-detect-most-stalkerware-apps/ #Privacy #CyberSecurity #Android #Stalkerware #MobileSecurity #EFF #AVComparatives #privacy #security According to the EFF Malwarebyte had been the best software to detect it. #security
-
The Good, the Bad, and the Politics of Biden’s Cybersecurity Order – Source: securityboulevard.com https://ciso2ciso.com/the-good-the-bad-and-the-politics-of-bidens-cybersecurity-order-source-securityboulevard-com/ #BidenNationalCybersecurityStrategy #SecurityBoulevard(Original) #securesoftwaresupplychain #rssfeedpostgeneratorecho #foreignthreatactors #CyberSecurityNews #SecurityAwareness #SecurityBoulevard #NetworkSecurity #Risk&Compliance #MobileSecurity #SocialFacebook #SocialLinkedIn #DevOps