The first ever OWASP MAScon is happening inside OWASP Global AppSec EU 2026 in Vienna, June 25 to 26, during 25 years of OWASP. Organized by Carlos Holguera @grepharder and Sven Schleier, with talks from Carlos, Stefan Bernhardsgrütter, Sergi Alvarez @pancake, Jan Seredynski, Ole André Vadla Ravnås @oleavr, and Jeroen Beckers.

https://mas.owasp.org/news/2026/03/20/owasp-mascon-is-here/

#OWASP #MobileSecurity #AppSec #MASVS #MASWE #MASTG #Frida

2/7 Key findings:
- 976 proxy classes intercepting 208 system API categories (GPS, camera, clipboard, crypto)
- 97.1% of internal APIs (396/408) have ZERO access control
- PatchProxy: every security method remotely replaceable without app update
- SM4 encryption remotely disableable by server config

Full analysis: github.com/sgInnora/alipay-securityguard-analysis

#mobilesecurity #reverseengineering

#introduction I'm Jiqiang Feng, independent security researcher at Innora AI. I found 17 vulnerabilities (CVSS up to 9.3) in Alipay, a payment app used by 1B+ people. 18 CVEs filed with MITRE. Peer-reviewed paper published by IACR.

My Twitter/X account was permanently suspended during this disclosure. 8 research articles were also deleted from WeChat by the vendor's lawyers.

innora.ai | github.com/sgInnora

#infosec #security #vulnerability #mobilesecurity

Android sideloading is getting a new speed bump: Google will require a 24-hour wait before installing apps from unverified developers, a move supposedly meant to make malware and scam-driven installs harder to pull off.

https://thehackernews.com/2026/03/google-adds-24-hour-wait-for-unverified.html

#AndroidSecurity #Cybersecurity #Malware #MobileSecurity #Google

Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams

Google adds 24-hour sideloading delay amid 17 malware families in 4 months, reducing scam-driven installs and device compromise risk.

The Hacker News

Android is rolling out a new security system 🔒 for sideloading that includes developer verification, mandatory wait times, and device restarts. The goal? Disrupting scam tactics while keeping the platform open. Here's how the new flow actually works and what it means for users wanting to install apps outside official stores 📱

Read the article to learn more: https://true-tech.net/android-sideloading-security-update-2026/

#Android #Cybersecurity #Sideloading #AppSecurity #MobileSecurity

https://true-tech.net/android-sideloading-security-update-2026/

Android sideloading security update 2026 introduces new advanced flow

Google introduces a new Android sideloading security system with an advanced flow that protects users from scams while allowing safe app installation from unverified developers.

TrueTech Technology Magazine
Google Adds Friction to Android Sideloading to Block Scammers

Google details "advanced flow" for Android power users to sideload unverified apps with multi-step security checks and one-day waiting period

The Daily Perspective
Hundreds of millions of iPhones vulnerable to DarkSword hack

Russian hackers deployed DarkSword exploit targeting iPhones running iOS 18.4-18.7. Up to 270 million devices potentially affected. Update to iOS 26.3 or later.

The Daily Perspective

Coruna iOS web malware kit: JavaScript payloads targeting iPhones via browser. iPhone users aren't immune—just differently targeted. Web exploits ignore OS loyalty. 🍱📱

https://otx.alienvault.com/pulse/69b891c1dc6a9f2f666e3cc5

#ios #malware #mobilesecurity

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Android 17 is tightening Accessibility API access to stop malware from abusing system permissions.

The update integrates with Advanced Protection Mode to reduce privilege escalation and limit sensitive data access.

https://www.technadu.com/android-17-restricts-accessibility-api-to-prevent-malware-from-requesting-excessive-permissions/623574/

#AndroidSecurity #Infosec #MobileSecurity

🔐 Is Your Business Protected from Cyber Threats?

Websites, APIs, and mobile apps are constant targets for cyber attacks.

With solutions powered by Bitdefender, SARC Infosolution helps businesses secure:

✔ Mobile Applications
✔ Websites
✔ APIs
✔ Endpoints

Cybersecurity is no longer optional — it is essential.

Hashtags

#CyberSecurity
#DataProtection
#APIsecurity
#MobileSecurity
#DigitalSecurity