home.social

#mobilesecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mobilesecurity, aggregated by home.social.

fetched live
  1. Porto, get ready! 🇵🇹

    Join Abraham Aranguren on Sep 23 for a hands-on workshop on practical Android and iOS attacks.

    appsecdays.pt/trainings/mobile

  2. CalyxOS is back! 📲 Release 7.2.2.0 is now online with full maintenance support—future updates will follow. If on older builds or other ROMs, a clean flash is required; 7.2.1.0 test users get OTA. 🚀 calyxos.org/news/2026/07/01/ca #CalyxOS #Android #Privacy #MobileSecurity

  3. Android 17 launches first on Pixel with floating app Bubbles, temporary location sharing, selective contact access, and stronger device protections. 📱🔐
    The release also adds foldable gaming improvements, app memory limits, creator tools, and expanded security features for eligible Android devices. 🎮⚙️

    🔗 blog.google/products-and-platf

    #TechNews #Android17 #Android #Google #Pixel #Samsung #MobileSecurity #Privacy #OpenSource #Mobile #Smartphone #Smartphones #Technology #Security #Performance #FOSS

  4. Android's new Advanced Protection Mode includes Intrusion Logging, a feature designed specifically to capture events relevant to security and related to possible intrusions, with the explicit goal of enabling consensual forensic analysis. This new feature is poised to significantly improve the ability of civil society investigators to identify and investigate sophisticated attacks on Android. securitylab.amnesty.org/latest #mobilesecurity

  5. Luma is here!

    This week at the inaugural @owasp MAScon in Vienna, NowSecure security researcher @oleavr unveiled Luma: the official #Frida GUI. Persistent sessions, an interactive REPL, frida-trace, and real-time collaborative editing, all in one native app across macOS, iOS, Linux, and Windows.

    Luma is free and open source. NowSecure is proud to sponsor the project and contribute engineering resources to its development.

    Huge congratulations to @oleavr and the entire Frida team on an incredible launch and what this release represents for the community: loom.ly/KRIF_LI

    #Luma #ReverseEngineering #MobileSecurity #DeveloperTools #OpenSource #NowSecure #OWASPMAScon

  6. Your phone is the primary target for modern hackers. It holds more sensitive data than your laptop, so stop treating it like a secondary device. Time to lock down your mobile perimeter before you become the next statistic. 🛡️💻

    #CyberSecurity #MobileSecurity #InfoSec

    bdking71.wordpress.com/2026/06

  7. Looking forward to #OWASP Global AppSec EU and the inaugural #MAScon next week. Excited for the opportunity to learn from researchers and practitioners who are pushing mobile security forward.

    Check out some of the sessions: loom.ly/qC3L65o

    @owasp #OWASPGlobalAppSec #MobileApps #MobileSecurity #SecurityResearch

  8. Google is rolling out a new opt-in feature in Android that aims to help security researchers investigate spyware attacks. The feature is called “Intrusion Logging” and is part of Android’s Advanced Protection Mode, which Google launched last year.. Advanced Protection Mode is designed to counter government spyware attacks and police forensic devices that try to extract data from a person’s phone. techcrunch.com/2026/05/12/goog #mobilesecurity

  9. Users worried their phone has a virus get a quick guide: signs, checks, cleanup, and prevention. Rapid battery drain, unknown apps, pop-ups, data spikes — act fast. Read more: proton.me/blog/phone-virus 🔍📱🛡️ #MobileSecurity #CyberSafety #Android #iPhone

  10. I was tired of digging through endless random cybersecurity lists, so naturally I built another random cybersecurity list - just cleaner, prettier and actually organized.

    Hack Hub is a curated directory of useful security resources.

    hackhub.fyi

    #CyberSecurity #InfoSec #Hacking #EthicalHacking #Pentesting #RedTeam #BlueTeam #DFIR #OSINT #ThreatIntel #MalwareAnalysis #BugBounty #CloudSecurity #MobileSecurity #OpenSource #SecurityTools #SecurityResearch #Linux #Hackers #Tech

  11. Mobile apps are not “just apps” anymore!

    They’re connected platforms handling identities, payments, sessions, APIs, and critical business workflows.

    In this special episode of @sharedsecurity I talked with Joel DeStefano, Senior Product Manager at Guardsquare, about the modern mobile application threat landscape and why organizations need to rethink mobile app security.

    We covered runtime manipulation, API abuse, account takeover, fake apps, overlays, reverse engineering, iOS vs Android risk, AI-assisted attacks, and why backend-only security is not enough.

    Learn more about Guardsquare:guardsquare.com

    Watch on YouTube:
    youtu.be/C5eWp9IB30U

    Listen wherever you like to get your podcasts:
    sharedsecurity.net/2026/06/10/

    #podcast #cybersecurity #mobilesecurity

  12. Reverse engineered the Mintegral MBridge SDK (common in gaming APKs with aggressive adv).
    The SDK assembles exfiltration endpoints at runtime via AES/XOR decryption + Android IPC Intents. No hardcoded domain in the binary. MobSF classifies the package as Advertisement and stops there. Knox and Play Protect see legitimate inter-process communication between signed components — nothing to flag.
    Extracted 6 C2/collection domains. Loaded them into AegisDNS as a SIGINT feed.
    Both Knox and Play Protect: no block, no alert.
    AegisDNS: all 6 blocked at resolution.
    The IPC obfuscation chain is effective against every on-device analysis layer. It stops at port 53 — the one operation the OS cannot perform inside the obfuscation boundary.
    Full write-up with architecture, the structural argument for perimeter DNS vs MTD, and operational trade-offs (block rate, DoH bypass mitigation via iptables, PCRE2/FFI trade-off):

    cariagiovannib.wordpress.com/2

    #dns #android #reverseengineering #infosec #mobilesecurity

  13. Prywatność i cyberbezpieczeństwo to nie są hobbystyczne fanaberie dla ludzi w foliowych czapeczkach. Skompromitowane urządzenie mobilne to bezpośrednie zagrożenie dla Twojego życia osobistego, finansów i spokoju psychicznego.

    Właśnie ruszyłem ze swoim blogiem, a to mój pierwszy wpis:
    🔗 meridian.bearblog.dev/droga_do

    Opisuję w nim historię z ukrytym korporacyjnym MDM na moim telefonie i to, jak techniki Incident Response oraz przejście na GrapheneOS pozwoliły mi odzyskać kontrolę.

    To mój debiut, dlatego bardzo zależy mi na Waszym feedbacku. Co myślicie o tym tekście? Dajcie znać w komentarzach, czy taka tematyka Was interesuje i czy chcecie kolejne wpisy o konfiguracji i hardeningu GrapheneOS! 🛡️📱

    #GrapheneOS #Cybersecurity #Privacy #Prywatnosc #Bezpieczenstwo #FOSS #MobileSecurity #PlFediverse #Blog

  14. Android 16 introduced a bug that allows a malicious app to send traffic outside the VPN tunnel, including with “Always-On VPN” + “Block connections without VPN” turned on. At the time of publishing, this affects all VPN apps. mullvad.net/en/blog/2026/5/12/ #mobilesecurity