Hiding an encryption key in a mobile app is often like putting a spare key under the doormat. If a user roots their phone, they can find it. White-box cryptography helps by baking the key into the code. docs.talsec.app/appsec-artic...
Talsec
@talsecofficial.bsky.social
Mobile Application Security company, RASP and API protection for iOS and Android apps
Picking a device ID is a trade-off between user privacy and app security. We've broken down how identifiers work on Android and iOS, from persistence to spoofing risks. Read the full guide here: docs.talsec.app/appsec-artic...
New freeRASP update: we added bootloader detection. It uses hardware attestation to find at-risk Android devices before they're even rooted. Includes better KernelSU and Frida detection too. docs.talsec.app/appsec-artic...
A simple newline character was enough to bypass Android's sandbox in CVE-2024-0044. It shows why relying only on the OS for security is risky. Here is how RASP provides a better safety net for production apps. docs.talsec.app/appsec-artic...
Attackers don't need your source code. With Frida, they hook into your app at runtime - bypassing root detection, disabling SSL pinning, intercepting API secrets live. Akshit Singh breaks down how it works and what developers can actually do about it.
Frida: Hacking and protecting mobile apps | AppSec Articles
Mobile applications are under constant attack. From runtime hooking and reverse engineering to bypassing security controls, attackers continue to evolve their techniques faster than many development…
docs.talsec.app
Rokarolla doesn't attack your code; it attacks the phone's environment via overlays. See how to make your app environment-aware and stop these trojans. docs.talsec.app/appsec-artic...
On Android 11+, PackageManager reports the exact installer package, which means your RASP & malware detection config is only as good as your trusted source list. We documented every relevant package ID: OEM stores, cloners, ADB markers, all with production vs. dev guidance.
Installation Sources Cookbook | AppSec Articles
This section provides a categorized reference of Android package names that the operating system may report as an installation source. You can use these reference tables to copy and paste exact…
docs.talsec.app
We scanned 56,000+ app hashes over 30 days. Result: 1,215 active threats living alongside legit apps — trojans disguised as game mods, fake videos, system tools. Your encryption doesn't matter if malware is reading the screen. Full case study 🔗 docs.talsec.app/appsec-artic... #MobileSecurity
🚀 Enjoy easier navigation, better security, and customizable dashboards to fit your workflow. It's all about making your experience better. Dive into the details here: docs.talsec.app/appsec-artic... #Talsec #Updates
New features in Talsec Portal | AppSec Articles
Recently we've rolled out Talsec Portal 1.5, bringing improvements to data visibility, workflows, and overall user experience.
docs.talsec.app
We are super pumped about our partnership with Gen Digital! 🚀 It’s all about taking malware detection to the next level with the awesome tech from Avast & Norton. This means even better security for you! Wanna know more? Check it out!
How Our Partnership With Gen Digital Enabled Malware Detection v2 Powered by Avast and Norton DBs | AppSec Articles
Talsec partners with Gen Digital (Avast, Norton) to integrate their global threat intelligence into Malware Detection v2, enabling a live, high-confidence malware detection.
docs.talsec.app
Cyber threats are evolving, and they're not just hitting the big players anymore. It's time to get our defenses up! Dive into the report and stay ahead of the game. Check it out.
Talsec Global Threat Report 2025 | AppSec Articles
Where the Attacks Are and What They Look Like
docs.talsec.app
The battle of skills: Panel Engineers vs. Reverse Engineers! 🛡️ While one builds the fortress, the other analyzes and strengthens it. Learn how these two roles support security in the app world and why both are essential. Check it out!
Panel: Engineers vs. Reverse Engineers | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,...
docs.talsec.app
AI impersonators are a growing threat! In Talsec's latest piece, Dmitri Bogatenkov talks about the importance of detecting and defending against machine-generated deception. It's a must-read to protect yourself online.
TT: The AI Impersonator: Runtime Defense Against Machine-Generated Deception with Dmitri Bogatenkov | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,...
docs.talsec.app
Read Talsec keynote on safety-security equilibrium. 🤔 It’s all about balancing user freedom with strong security. A must-read for anyone in tech! Let’s create a safer digital world together! Check it out! 👉
Opening Keynote: Safety/Security Equilibrium with Sergiy Yakymchuk (Talsec) | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,...
docs.talsec.app
Say goodbye to annoying CAPTCHAs! 🚫🤖 Check out this article on stopping bots without the hassle. Using techniques like behavioral analysis and fine-tuning rate limits can lighten the load on users while keeping your site secure!
How to Stop Bots Without CAPTCHA | AppSec Articles
hashtagThe CAPTCHA problem
docs.talsec.app
🔐 Wonder how to keep your app secure? Majid Hajian from Microsoft dives into the best practices for application safety. 🛡️ From proactive monitoring to regular updates, he covers it all! Don't leave your app's security to chance.
TechTalk: Best Practices for Keeping Your App Safe with Majid Hajian (Microsoft) | AppSec Articles
hashtagThe Core Pillars of Modern App Defense
docs.talsec.app
🚀 Exciting insights on predictive app protection! If you want to stay ahead of threats and secure your applications smarter than ever, this is a must-read. Tap into the future of security tech! 🔐
TechTalk: Predictive Apps Protection with Sergiy Yakymchuk (Talsec) | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,...
docs.talsec.app
Hey Flutter devs! 🚀 Did you know that insufficient cryptography is one of the biggest threats to your apps? It's #10 on the OWASP list! Protect your users by strengthening your encryption. Dive deeper into how you can secure your apps here in our last OWASP Top 10 for Flutter article.
OWASP Top 10 For Flutter – M10: Insufficient Cryptography in Flutter & Dart | AppSec Articles
Welcome to the final article in our deep dive into the OWASP Mobile Top 10 for Flutter developers.
docs.talsec.app
Hey devs! 🌟 Protect your users with the Android Malware Detection SDK! This tool helps you spot risky apps and defend against known malware. Security is key in today’s app world, so don’t miss out! docs.talsec.app/appsec-artic...
Hey Flutter & Dart devs! 🚀 Are you aware of the risks of Insecure Data Storage? It’s a top concern for app security! Learn how to secure your applications and keep user data safe. Check out the essential insights in our new article! 📲👇 docs.talsec.app/appsec-artic...
OWASP Top 10 For Flutter – M9: Insecure Data Storage in Flutter & Dart | AppSec Articles
Welcome back to our deep dive into the OWASP Mobile Top 10 for Flutter developersarrow-up-right.
docs.talsec.app
Hey Flutter developers! 🚀 Are you aware of the security misconfigurations that could jeopardize your apps? Check out the OWASP Top 10 for Flutter and Dart to fortify your coding practices and protect your users! 🛡️ Read more in our article.
OWASP Top 10 For Flutter – M8: Security Misconfiguration in Flutter & Dart | AppSec Articles
Welcome back to our deep dive into the OWASP Mobile Top 10 for Flutter developersarrow-up-right. OWASP (Open Worldwide Application Security Project) maintains this industry-standard risk rankingarrow-up-right...
docs.talsec.app
Hey devs! 🚀 Did you know that insufficient binary protection in Flutter and Dart can expose your apps to threats? 🔍 It's time to secure your code and protect your users. Check out this must-read article for tips on improving your app's security! 🔐
OWASP Top 10 For Flutter – M7: Insufficient Binary Protection in Flutter & Dart | AppSec Articles
Welcome back to our deep dive into the OWASP Mobile Top 10 for Flutter developersarrow-up-right.
docs.talsec.app
Protect your Apple TV apps with advanced RASP+ runtime defense and AppiCrypt API integrity. Go beyond basic checks to block tampering and API abuse. 🔒 Read more: docs.talsec.app/appsec-artic... #AppSecurity #DevSecOps
Explore how threshold cryptography redefines key security beyond single‑device trust — with insights from Jan Kvapil (MUNI). 🔐 Multi‑device signing, share‑based key protection, and real‑world defenses. 📖 Read here: docs.talsec.app/appsec-artic... #Security #Crypto #AppSec
📌 Read article on fingerprinting & device intelligence at Talsec AppSec — and it’s a must-think for anti-fraud strategy. 🎯 It’s not enough to collect data → you must interpret it with context + business logic to balance risk mitigation with user experience. 🔗 Article: buff.ly/LOEY9Ny
Video injection is one of the main attacks in KYC. Letting attackers feed fake video streams into verification systems to steal identities at scale. Our latest article describes how Talsec can help against this attack. 👉 docs.talsec.app/appsec-artic...
Cloudflare’s Anatol Nikiforov shared powerful insights on today’s AppSec challenges — from AI-powered bots to the rise of residential proxies. If you care about real-world security trends and how defenders are responding, check out this recap: 🔗 docs.talsec.app/appsec-artic...
Security works best as a team sport. 🤝🔐 Tomáš Soukal’s keynote breaks down community-driven security as collective defense—and why sharing insights strengthens mobile protection at scale. docs.talsec.app/appsec-artic...
🚀 Can Flutter really be banking-grade secure? In this keynote recap from Talsec’s Mobile App Security Conference (Prague, Nov 3–4, 2025), Mateusz Wojtczak (Leancode) breaks down why the biggest “Flutter isn’t secure” argument is mostly a misconception. 📌 Article: docs.talsec.app/appsec-artic...
Keynote: 20 Minutes to Banking-Grade with Mateusz Wojtczak (LeanCode) | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,…
docs.talsec.app
In Béatrice Creusillet’s (Quarkslab) case study: Pwn2Own EV charger attack took ~33 person-days with only light protection. Layering defenses changes everything. Read the article:
Keynote: Raising the Bar with Software Protection with Béatrice Creusillet (Quarkslab) | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,…
docs.talsec.app