Towerwall's InfoSec Blog

Content Type

See all

5 Open Source Intrusion Detection Tools That Are Too Good to Ignore

Android , OSSEC , Open DLP , Phishing , Data Loss Prevention (DLP) , Application Security , Snort , malware , Bro , Windows , Kismet , iOS , cannabis , Enterprise , Open Source

Michelle Drolet

Everyone should employ an intrusion detection system (IDS) to monitor their network and flag any suspicious activity or automatically shut down potentially malicious traffic. We look at five of the best open source options. As cybersecurity professionals, we try to prevent attackers from gaining access to our networks but protecting perimeters that have grown exponentially with the rise of mobile devices, distributed teams, and the internet of things (IoT) is not easy. The unpalatable truth isfalse

Michelle Drolet published in NetworkWorld - Are mobile apps putting your data at risk?

Android , Information Security , Application Security , Mobile Apps , Cloud Security , Mobile Security , Data Breach , Gap Assessment

Michelle Drolet

Our Michelle Drolet is quoted in NetworkWorld's article "Are mobile apps putting your data at risk?". Read more below:

First malicious apps to exploit critical Android bug found in the wild

Android , network security , Security Regulations , Mobile Devices , Security Threat , Phishing , Security Program , Information Security , Application Security , Security , Mobile Apps , Hackers , cyber-attack , security policy , cybercriminals , Tablets , Mobile Protection , security research , Mobile Security , cybersecurity , Enterprise

Michelle Drolet

Researchers have spotted the first in-the-wild apps to exploit a critical Android vulnerability allowing attackers to inject malicious code into legitimate programs without invalidating their digital signature. The two apps, distributed on unofficial Android marketplaces in China, help people find doctors and make appointments, according to a blog post published Tuesday by researchers from security firm Symantec. By exploiting the recently disclosed "master key" vulnerability—or possibly a false

How to ensure mobile apps are secure for the enterprise

Android , Security Services , security software , Data Security , Security Regulations , threat landscape , Mobile Devices , Security Threat , Security Program , Application Security , Security , malware , iPhone , Mobile Apps , T-Mobile , security policy , Big Data , Mobile Protection , Data Privacy , security research , Mobile Security , cannabis , Enterprise , Data Breach

Michelle Drolet

As the app revolution has gathered pace and smartphones and tablets have become ubiquitous, the importance of testing app security has grown. Many companies have embraced the BYOD trend. They may even have developed applications that enable employees to have 24/7 access to business data and tools. The benefits can be counted in productivity boosts and flexibility, but there is a real and present danger that is being ignored all too often. How many of these enterprise apps have undergonefalse

Library file in certain Android Apps connects C&C servers

Android , network security , Data Security , Security Regulations , threat landscape , Security Threat , Security Program , Security , cyber-attack , security policy , cybercriminals , Security Alert , security research , Mobile Security , cannabis , cybersecurity , Enterprise

Michelle Drolet

TrendMicro has uncovered certain Android apps (detected as ANDROIDOS_BOTPANDA.A) containing a malicious library file, which when executed, renders the infected device as a zombie device that connects to specific command and control (C&C) servers. What is also noteworthy about this file is that it hides its routines in the dynamic library, making it difficult to analyze. The malicious library libvadgo contained in ANDROIDOS_BOTPANDA.A was developed via NDK and loaded using Java Native Interface.false