An old security bug in the Play library still affects 8% of apps in Google Play, Project Zero researcher spends six months to reboot an iPhone (in an epic manner), GitHub looks at the security of repos within its Octoverse, the OWASP Web Security Testing Guide gets a minor bump, and XS-Leaks get more attention.
Don't forget to check out our library of on-demand webcasts & technical trainings at securityweekly.com/ondemand.
Don't miss any of your favorite Security Weekly content! Visit https://securityweekly.com/subscribe to subscribe to any of our podcast feeds and have all new episodes downloaded right to your phone! You can also join our mailing list, Discord server, and follow us on social media & our streaming platforms!
Mike Shema
- 8% of all Google Play apps vulnerable to old security bugthat demonstrates once again the software supply chain challenge of applying updates that software vendors supply.
- Project Zero: An iOS zero-click radio proximity exploit odysseyis an epic read about the saga of radio, protocols, buffers, and surprising swarms of susceptible software that didn't see it coming.
- OWASP Web Security Testing Guide – v4.2this version must be the answer to life, the universe, and everything you wanted to know about web security testing!
- Cross-site leaks wikidescribes a vuln that's truly cross-site and truly sneaky. And, if you'd like to dive deeper into configuring effective site policies to protect your web app, check "Reining in the Web’s Inconsistencies with Site Policy" at https://publications.cispa.saarland/3214/7/calzavara2021reining.pdf
- The State of the Octoversesupplies a perspective on open source and security as seen by GitHub and shared with all of us.
- Open source software security vulnerabilities exist for over four years before detectionwhich is the other headline you could give to GitHub's State of the Octoverse.
- Antipatterns That Hurt DevOps Implementationsmight sound familiar and, fortunately, also sound like they can be turned into constructive collaboration.