Sign in

Talsec

@talsecofficial.bsky.social
19 followers 20 following 187 posts

Mobile Application Security company, RASP and API protection for iOS and Android apps

PostsRepliesMedia
Talsec @talsecofficial.bsky.social · 25/08/2026
Hiding an encryption key in a mobile app is often like putting a spare key under the doormat. If a user roots their phone, they can find it. White-box cryptography helps by baking the key into the code. docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 17/08/2026
Picking a device ID is a trade-off between user privacy and app security. We've broken down how identifiers work on Android and iOS, from persistence to spoofing risks. Read the full guide here: docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 14/08/2026
New freeRASP update: we added bootloader detection. It uses hardware attestation to find at-risk Android devices before they're even rooted. Includes better KernelSU and Frida detection too. docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 26/06/2026
A simple newline character was enough to bypass Android's sandbox in CVE-2024-0044. It shows why relying only on the OS for security is risky. Here is how RASP provides a better safety net for production apps. docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 24/06/2026
Attackers don't need your source code. With Frida, they hook into your app at runtime - bypassing root detection, disabling SSL pinning, intercepting API secrets live. Akshit Singh breaks down how it works and what developers can actually do about it.
docs.talsec.app
Frida: Hacking and protecting mobile apps | AppSec Articles
Mobile applications are under constant attack. From runtime hooking and reverse engineering to bypassing security controls, attackers continue to evolve their techniques faster than many development…
000
Talsec @talsecofficial.bsky.social · 23/06/2026
Rokarolla doesn't attack your code; it attacks the phone's environment via overlays. See how to make your app environment-aware and stop these trojans. docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 22/06/2026
On Android 11+, PackageManager reports the exact installer package, which means your RASP & malware detection config is only as good as your trusted source list. We documented every relevant package ID: OEM stores, cloners, ADB markers, all with production vs. dev guidance.
docs.talsec.app
Installation Sources Cookbook | AppSec Articles
This section provides a categorized reference of Android package names that the operating system may report as an installation source. You can use these reference tables to copy and paste exact…
000
Talsec @talsecofficial.bsky.social · 18/06/2026
We scanned 56,000+ app hashes over 30 days. Result: 1,215 active threats living alongside legit apps — trojans disguised as game mods, fake videos, system tools. Your encryption doesn't matter if malware is reading the screen. Full case study 🔗 docs.talsec.app/appsec-artic... #MobileSecurity
000
Talsec @talsecofficial.bsky.social · 27/04/2026
🚀 Enjoy easier navigation, better security, and customizable dashboards to fit your workflow. It's all about making your experience better. Dive into the details here: docs.talsec.app/appsec-artic... #Talsec #Updates
docs.talsec.app
New features in Talsec Portal | AppSec Articles
Recently we've rolled out Talsec Portal 1.5, bringing improvements to data visibility, workflows, and overall user experience.
000
Talsec @talsecofficial.bsky.social · 23/04/2026
We are super pumped about our partnership with Gen Digital! 🚀 It’s all about taking malware detection to the next level with the awesome tech from Avast & Norton. This means even better security for you! Wanna know more? Check it out!
docs.talsec.app
How Our Partnership With Gen Digital Enabled Malware Detection v2 Powered by Avast and Norton DBs | AppSec Articles
Talsec partners with Gen Digital (Avast, Norton) to integrate their global threat intelligence into Malware Detection v2, enabling a live, high-confidence malware detection.
000
Talsec @talsecofficial.bsky.social · 17/04/2026
Cyber threats are evolving, and they're not just hitting the big players anymore. It's time to get our defenses up! Dive into the report and stay ahead of the game. Check it out.
docs.talsec.app
Talsec Global Threat Report 2025 | AppSec Articles
Where the Attacks Are and What They Look Like
000
Talsec @talsecofficial.bsky.social · 01/04/2026
The battle of skills: Panel Engineers vs. Reverse Engineers! 🛡️ While one builds the fortress, the other analyzes and strengthens it. Learn how these two roles support security in the app world and why both are essential. Check it out!
docs.talsec.app
Panel: Engineers vs. Reverse Engineers | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,...
000
Talsec @talsecofficial.bsky.social · 30/03/2026
AI impersonators are a growing threat! In Talsec's latest piece, Dmitri Bogatenkov talks about the importance of detecting and defending against machine-generated deception. It's a must-read to protect yourself online.
docs.talsec.app
TT: The AI Impersonator: Runtime Defense Against Machine-Generated Deception with Dmitri Bogatenkov | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,...
000
Talsec @talsecofficial.bsky.social · 27/03/2026
Read Talsec keynote on safety-security equilibrium. 🤔 It’s all about balancing user freedom with strong security. A must-read for anyone in tech! Let’s create a safer digital world together! Check it out! 👉
docs.talsec.app
Opening Keynote: Safety/Security Equilibrium with Sergiy Yakymchuk (Talsec) | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,...
000
Talsec @talsecofficial.bsky.social · 25/03/2026
Say goodbye to annoying CAPTCHAs! 🚫🤖 Check out this article on stopping bots without the hassle. Using techniques like behavioral analysis and fine-tuning rate limits can lighten the load on users while keeping your site secure!
docs.talsec.app
How to Stop Bots Without CAPTCHA | AppSec Articles
hashtagThe CAPTCHA problem
000
Talsec @talsecofficial.bsky.social · 23/03/2026
🔐 Wonder how to keep your app secure? Majid Hajian from Microsoft dives into the best practices for application safety. 🛡️ From proactive monitoring to regular updates, he covers it all! Don't leave your app's security to chance.
docs.talsec.app
TechTalk: Best Practices for Keeping Your App Safe with Majid Hajian (Microsoft) | AppSec Articles
hashtagThe Core Pillars of Modern App Defense
000
Talsec @talsecofficial.bsky.social · 20/03/2026
🚀 Exciting insights on predictive app protection! If you want to stay ahead of threats and secure your applications smarter than ever, this is a must-read. Tap into the future of security tech! 🔐
docs.talsec.app
TechTalk: Predictive Apps Protection with Sergiy Yakymchuk (Talsec) | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,...
000
Talsec @talsecofficial.bsky.social · 18/03/2026
Hey Flutter devs! 🚀 Did you know that insufficient cryptography is one of the biggest threats to your apps? It's #10 on the OWASP list! Protect your users by strengthening your encryption. Dive deeper into how you can secure your apps here in our last OWASP Top 10 for Flutter article.
docs.talsec.app
OWASP Top 10 For Flutter – M10: Insufficient Cryptography in Flutter & Dart | AppSec Articles
Welcome to the final article in our deep dive into the OWASP Mobile Top 10 for Flutter developers.
000
Talsec @talsecofficial.bsky.social · 17/03/2026
Hey devs! 🌟 Protect your users with the Android Malware Detection SDK! This tool helps you spot risky apps and defend against known malware. Security is key in today’s app world, so don’t miss out! docs.talsec.app/appsec-artic...
001
Talsec @talsecofficial.bsky.social · 13/03/2026
Hey Flutter & Dart devs! 🚀 Are you aware of the risks of Insecure Data Storage? It’s a top concern for app security! Learn how to secure your applications and keep user data safe. Check out the essential insights in our new article! 📲👇 docs.talsec.app/appsec-artic...
docs.talsec.app
OWASP Top 10 For Flutter – M9: Insecure Data Storage in Flutter & Dart | AppSec Articles
Welcome back to our deep dive into the OWASP Mobile Top 10 for Flutter developersarrow-up-right.
010
Talsec @talsecofficial.bsky.social · 11/03/2026
Hey Flutter developers! 🚀 Are you aware of the security misconfigurations that could jeopardize your apps? Check out the OWASP Top 10 for Flutter and Dart to fortify your coding practices and protect your users! 🛡️ Read more in our article.
docs.talsec.app
OWASP Top 10 For Flutter – M8: Security Misconfiguration in Flutter & Dart | AppSec Articles
Welcome back to our deep dive into the OWASP Mobile Top 10 for Flutter developersarrow-up-right. OWASP (Open Worldwide Application Security Project) maintains this industry-standard risk rankingarrow-up-right...
000
Talsec @talsecofficial.bsky.social · 09/03/2026
Hey devs! 🚀 Did you know that insufficient binary protection in Flutter and Dart can expose your apps to threats? 🔍 It's time to secure your code and protect your users. Check out this must-read article for tips on improving your app's security! 🔐
docs.talsec.app
OWASP Top 10 For Flutter – M7: Insufficient Binary Protection in Flutter & Dart | AppSec Articles
Welcome back to our deep dive into the OWASP Mobile Top 10 for Flutter developersarrow-up-right.
000
Talsec @talsecofficial.bsky.social · 06/03/2026
Protect your Apple TV apps with advanced RASP+ runtime defense and AppiCrypt API integrity. Go beyond basic checks to block tampering and API abuse. 🔒 Read more: docs.talsec.app/appsec-artic... #AppSecurity #DevSecOps
000
Talsec @talsecofficial.bsky.social · 04/03/2026
Explore how threshold cryptography redefines key security beyond single‑device trust — with insights from Jan Kvapil (MUNI). 🔐 Multi‑device signing, share‑based key protection, and real‑world defenses. 📖 Read here: docs.talsec.app/appsec-artic... #Security #Crypto #AppSec
000
Talsec @talsecofficial.bsky.social · 02/03/2026
📌 Read article on fingerprinting & device intelligence at Talsec AppSec — and it’s a must-think for anti-fraud strategy. 🎯 It’s not enough to collect data → you must interpret it with context + business logic to balance risk mitigation with user experience. 🔗 Article: buff.ly/LOEY9Ny
000
Talsec @talsecofficial.bsky.social · 13/02/2026
Video injection is one of the main attacks in KYC. Letting attackers feed fake video streams into verification systems to steal identities at scale. Our latest article describes how Talsec can help against this attack. 👉 docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 09/02/2026
Cloudflare’s Anatol Nikiforov shared powerful insights on today’s AppSec challenges — from AI-powered bots to the rise of residential proxies. If you care about real-world security trends and how defenders are responding, check out this recap: 🔗 docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 30/01/2026
Security works best as a team sport. 🤝🔐 Tomáš Soukal’s keynote breaks down community-driven security as collective defense—and why sharing insights strengthens mobile protection at scale. docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 22/01/2026
🚀 Can Flutter really be banking-grade secure? In this keynote recap from Talsec’s Mobile App Security Conference (Prague, Nov 3–4, 2025), Mateusz Wojtczak (Leancode) breaks down why the biggest “Flutter isn’t secure” argument is mostly a misconception. 📌 Article: docs.talsec.app/appsec-artic...
docs.talsec.app
Keynote: 20 Minutes to Banking-Grade with Mateusz Wojtczak (LeanCode) | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,…
000
Talsec @talsecofficial.bsky.social · 15/01/2026
In Béatrice Creusillet’s (Quarkslab) case study: Pwn2Own EV charger attack took ~33 person-days with only light protection. Layering defenses changes everything. Read the article:
docs.talsec.app
Keynote: Raising the Bar with Software Protection with Béatrice Creusillet (Quarkslab) | AppSec Articles
The Talsecarrow-up-right Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4,…
000
Talsec @talsecofficial.bsky.social · 08/01/2026
New platforms, smarter tools, and stronger security. In 2025, we brought Talsec to gaming engines and introduced the Talsec Portal for real-time security intelligence. We are ready for the next big thing in mobile development. Here is to a secure 2026! 🥂 Full summary here:
docs.talsec.app
Year in Talsec RASP SDK: Highlights from 2025 | AppSec Articles
This year, we confirmed our position as #1 RASP with top root detection. We embraced Kotlin Multiplatform and gaming engines like Unity and Unreal Engine, while finally delivering the long-awaited…
000
Talsec @talsecofficial.bsky.social · 05/01/2026
How do you hack a network with a perfect firewall? You walk in the front door. 🚪 Adam Žilla from Haxoris reveals how a "fire safety inspector" disguise and a hidden Raspberry Pi led to total domain compromise. Read the full attack chain👇 docs.talsec.app/appsec-artic...
docs.talsec.app
Keynote: Red Teaming in Practice with Adam Žilla (Haxoris) | AppSec Articles
The Talsec Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4, 2025, and…
010
Talsec @talsecofficial.bsky.social · 02/01/2026
AI Pentesting isn’t the future. It’s already here. @ethiack.com Hackian hackbot compromised a genetics platform in <4h, finding critical bugs humans missed. Key takeaway: AI finds different vulnerabilities. Test before “bad guys” do.
docs.talsec.app
Keynote: Discovering the Power of AI Pentesting with Pedro Conde (Ethiack) | AppSec Articles
The Talsec Mobile App Security Conference in Prague was a two-day, invite-only event on fraud, malware, and API abuse in modern mobile apps, held at Chateau St. Havel on November 3–4, 2025, and…
020
Talsec @talsecofficial.bsky.social · 12/12/2025
🚀 Big Update for freeRASP React Native! Secure your app against smarter threats with our latest release. Update now github.com/talsec/Free-... What's new?👇
github.com
Release freeRASP 4.3.0 · talsec/Free-RASP-ReactNative
Android SDK version: 17.0.1 iOS SDK version: 6.13.0 React Native Added Added killOnBypass to TalsecConfig that configures if the app should be terminated when the threat callbacks are suppressed/...
100
Talsec @talsecofficial.bsky.social · 10/12/2025
Jailbroken devices break the security model your Capacitor app relies on — sandboxing, code signing, filesystem integrity. freeRASP adds reliable jailbreak detection to Capacitor with zero native hassle. Full guide: docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 09/12/2025
Frida is one of the easiest ways to hook, patch, and reverse-engineer mobile apps — including Capacitor apps. FreeRASP for Capacitor lets you detect Frida and fight against it. Hybrid doesn’t have to mean unprotected. 🔗 docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 08/12/2025
🚀 Securing Kotlin Multiplatform apps just got easier! You can now integrate freeRASP directly into your KMP projects. Detect threats like tampering, hooking, and code injection, whether on Android or iOS. 🔗 Start protecting your KMP apps today: docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 05/12/2025
#Cloudflare went down today. Again. Your security doesn’t have to go down with it. AppiCryptWeb = cryptographic trust for your API, independent of your CDN or WAF 🔐 Full article here: 🔗 docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 04/12/2025
React Native apps need reliable detection to prevent data extraction, tampering, and traffic manipulation. This guide explains the basic detection methods and the integration of our SDK. Read more: 🔗 docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 01/12/2025
React Native apps are great... until they run on a jailbroken device. Here’s a clear, high-level look at how to detect it and why RASP fills the gaps iOS leaves open: 🔗 docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 28/11/2025
📱 Still relying on basic root checks for your Android app? Magisk's "systemless" root can easily bypass them. Learn why standard detection fails and how to implement robust protection against modern root hiding techniques. 🛡️ Read the guide here: 👇 docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 26/11/2025
Frida is one of the go-to tools attackers use to hook into mobile apps, bypass logic, or extract sensitive data. If your React Native app isn’t monitoring for these attacks, it’s basically running with the doors unlocked. 🔒 Learn how to detect Frida: docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 25/11/2025
Your app may be secure — but the Wi-Fi your users connect to might not be. Weak networks = MITM risks, data leaks, and broken trust. Here’s how to detect unsafe Wi-Fi inside your app 👇 docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 24/11/2025
If your Android app handles sensitive data, Developer Mode shouldn’t go unnoticed. A simple check can help you spot risky, debuggable environments before attackers do. Learn how 👉 docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 21/11/2025
💡 The future is data-driven, but is your app ready for it? As more systems shift toward data-centric architectures, one thing becomes clear: your application is only as secure as the APIs it talks to. And today’s attackers know it. 🔗 Full article: docs.talsec.app/appsec-artic...
000
Talsec @talsecofficial.bsky.social · 19/11/2025
App tampering and repackaging allow attackers to inject malware or bypass in-app purchases in your Android app. Learn how to detect integrity breaches and block repackaged apps in our latest article: 🔗 docs.talsec.app/appsec-artic... #AndroidDev #AppSec #Kotlin #MobileDevelopment #InfoSec
000
Talsec @talsecofficial.bsky.social · 18/11/2025
🎮 Game devs, are you leaving your revenue exposed? Discover FreeRASP for Unreal Engine – a free, lightweight RASP solution that protects your games from runtime attacks without slowing them down. 🔒⚡ Read more: docs.talsec.app/appsec-artic...
010
Talsec @talsecofficial.bsky.social · 18/11/2025
Magisk and Shamiko might sound cool… but in the wrong hands, they’re dangerous. Your Flutter app could be tampered with in seconds. Find out how to secure it: docs.talsec.app/appsec-artic... #Flutter #Android #Security #Root
010
Talsec @talsecofficial.bsky.social · 14/11/2025
New article out: How to Detect Jailbreak on Flutter — ideal for devs and AppSec pros who want to keep their Flutter apps secure on compromised devices. 🌐 docs.talsec.app/appsec-artic... #Flutter #MobileSecurity #AppSec #DevSecOps #Jailbreak
010
Talsec @talsecofficial.bsky.social · 14/11/2025
Exciting news for all Kotlin Multiplatform developers! 🚀 We’re proud to announce that freeRASP for Kotlin Multiplatform is launching soon. We heard the community’s call for a security solution built specifically for your KMP projects. Stay tuned! #kotlin #kmp #multiplatform
000