iOS security testing just hit a wall. For the first time, there are no public jailbreaks for current iOS versions. Security teams that relied on them for runtime analysis are now operating blind.
iOS security testing just hit a wall. For the first time, there are no public jailbreaks for current iOS versions. Security teams that relied on them for runtime analysis are now operating blind.
40,009 CVEs published in 2024. That's 100+ new vulnerabilities every single day.
For mobile teams, the real question isn't "what's broken" - it's "are WE actually vulnerable?"
Most can't answer that. Here's why 🧵
40,009 CVEs published in 2024. That's 100+ new vulnerabilities every single day.
For mobile teams, the real question isn't "what's broken" - it's "are WE actually vulnerable?"
Most can't answer that. Here's why 🧵
That new iOS 26 jailbreak everyone's talking about? It's fake. And it's stealing your data.
Here's what @corellium.bsky.social Labs found when they tore apart #nekoJB Online 🧵
That new iOS 26 jailbreak everyone's talking about? It's fake. And it's stealing your data.
Here's what @corellium.bsky.social Labs found when they tore apart #nekoJB Online 🧵
How are security teams supposed to test their apps thoroughly? 🧵
How are security teams supposed to test their apps thoroughly? 🧵
The secret: ASLR (Address Space Layout Randomization) - Apple's invisible shield that randomizes memory locations, making exploitation nearly impossible.
Here's how it works 🧵👇
The secret: ASLR (Address Space Layout Randomization) - Apple's invisible shield that randomizes memory locations, making exploitation nearly impossible.
Here's how it works 🧵👇
Just found another app doing this. Their defense? "We encrypt it!"
That's not how PCI DSS works...
Just found another app doing this. Their defense? "We encrypt it!"
That's not how PCI DSS works...
🚨 High-severity bugs in mobile apps = BIG payouts 💰
But most hunters focus on web apps. Mobile is a goldmine if you know where to look. Here's how 👇
🚨 High-severity bugs in mobile apps = BIG payouts 💰
But most hunters focus on web apps. Mobile is a goldmine if you know where to look. Here's how 👇
🔐 Most iOS app pentests fail before they even start.
Why? People try to analyze encrypted IPAs.
Here’s why that’s a mistake - and how to do it right. 🧵
🔐 Most iOS app pentests fail before they even start.
Why? People try to analyze encrypted IPAs.
Here’s why that’s a mistake - and how to do it right. 🧵
🚨 Your mobile app could be perfectly coded… and still wide open to attack.
Why? Because of the 20+ third-party SDKs most apps rely on. Analytics, ads, payments, social - each one could be a backdoor.
#MobileSecurity #OWASP #SupplyChainSecurity #MobileApp
🚨 Your mobile app could be perfectly coded… and still wide open to attack.
Why? Because of the 20+ third-party SDKs most apps rely on. Analytics, ads, payments, social - each one could be a backdoor.
#MobileSecurity #OWASP #SupplyChainSecurity #MobileApp
Here’s how a small security gap in the Authy app turned into a massive breach 🧵
Here’s how a small security gap in the Authy app turned into a massive breach 🧵
⚠️ 91% of organizations faced a software supply chain attack in 2024.
Mobile apps aren’t immune.
The SpinOK malware case proves it:
101 Android apps infected via a malicious ad SDK.
43 still live on Google Play-some with over 5M downloads.
⚠️ 91% of organizations faced a software supply chain attack in 2024.
Mobile apps aren’t immune.
The SpinOK malware case proves it:
101 Android apps infected via a malicious ad SDK.
43 still live on Google Play-some with over 5M downloads.
Building a new iOS app? Your choice between React Native and Swift could seriously affect your app’s security.
Just helped a fintech team make this call-here’s what most devs miss about the security side.
Building a new iOS app? Your choice between React Native and Swift could seriously affect your app’s security.
Just helped a fintech team make this call-here’s what most devs miss about the security side.
A new invisible Android attack just dropped… and it's sneaky.
Researchers from TU Wien & University of Bayreuth discovered TapTrap – a tapjacking technique that tricks users into giving dangerous permissions without knowing.
#TapTrap #mobilesecurity
A new invisible Android attack just dropped… and it's sneaky.
Researchers from TU Wien & University of Bayreuth discovered TapTrap – a tapjacking technique that tricks users into giving dangerous permissions without knowing.
#TapTrap #mobilesecurity
The world is in a mobile security crisis 📱⚠️
A recent AP investigation revealed that hackers are silently targeting smartphones of officials, journalists, and tech workers using zero-click attacks.
These attacks leave no trace.
The world is in a mobile security crisis 📱⚠️
A recent AP investigation revealed that hackers are silently targeting smartphones of officials, journalists, and tech workers using zero-click attacks.
These attacks leave no trace.
In April 2025, a researcher bought a budget smartphone online. Looked legit. Pre-installed messaging apps. No red flags.
Then they tried sending crypto… and it was silently hijacked.
#SupplyChainSecurity #MobileSecurity #RuntimeTesting #Corellium
In April 2025, a researcher bought a budget smartphone online. Looked legit. Pre-installed messaging apps. No red flags.
Then they tried sending crypto… and it was silently hijacked.
#SupplyChainSecurity #MobileSecurity #RuntimeTesting #Corellium
Step 1: Get a jailbroken device
unc0ver (iOS 11-14.8)
palera1n (newer versions)
Check Can I Jailbreak? for compatibility
⚠️ New iPhones come with latest iOS = no public jailbreak. Buy older devices!
#iOSSecurity
Step 1: Get a jailbroken device
unc0ver (iOS 11-14.8)
palera1n (newer versions)
Check Can I Jailbreak? for compatibility
⚠️ New iPhones come with latest iOS = no public jailbreak. Buy older devices!
#iOSSecurity
🚨 SparkCat Malware Alert: "Safe" apps on Google Play and Apple App Store were stealing crypto wallet recovery phrases from your photos. Here's what happened and how to stay safe 🧵
#CyberSecurity #MobileSecurity #Cryptocurrency #AppSecurity #Corellium
🚨 SparkCat Malware Alert: "Safe" apps on Google Play and Apple App Store were stealing crypto wallet recovery phrases from your photos. Here's what happened and how to stay safe 🧵
#CyberSecurity #MobileSecurity #Cryptocurrency #AppSecurity #Corellium
Most teams are not testing for it, and it is surprisingly easy to exploit.
#MobileSecurity #Corellium #VulnerabilityResearch #CyberSecurity #AppSec
Most teams are not testing for it, and it is surprisingly easy to exploit.
#MobileSecurity #Corellium #VulnerabilityResearch #CyberSecurity #AppSec
Reverse engineering iOS apps is tough - no public jailbreaks, code signing issues, and getting decrypted IPAs is a pain.
It gets even harder with iOS 18+.
But using Ghidra + a virtual iPhone changed everything for me. 🧵
Reverse engineering iOS apps is tough - no public jailbreaks, code signing issues, and getting decrypted IPAs is a pain.
It gets even harder with iOS 18+.
But using Ghidra + a virtual iPhone changed everything for me. 🧵
The new SANS product review of @corellium.bsky.social validates what we've all been dealing with - iOS security testing with physical devices just isn't working anymore.
The new SANS product review of @corellium.bsky.social validates what we've all been dealing with - iOS security testing with physical devices just isn't working anymore.
“10 iPhones in my luggage” — that’s what iOS security training used to look like.
Throwback to AppSec USA when I had to bring 8–10 physical devices to every session. It was… a process.
“10 iPhones in my luggage” — that’s what iOS security training used to look like.
Throwback to AppSec USA when I had to bring 8–10 physical devices to every session. It was… a process.