Can We Detect APT Attacks?

In the previous post, we learned what is and how APT (Advanced Persistent Threat) attacks work. But the interesting part comes when we think about: How can we detect such complex attacks? And is…
Advanced Persistent Threat Attack and Its Morphology

The number of cyber attacks is increasing on the internet nowadays. It is not surprising that the World Economic Forum and Global Risk Report placed in 2018 cyber attacks as the third most likely…
CA and Bypass SSL Pinning Protection on Android

Adding CA to an Android system and bypass SSL pinning protections are two very important steps in testing the security of different applications. After my latest article – How To Install And Root…
How to Install and Root Your Android Emulator

Mobile applications became an essential part of our lives, somehow we are dependent of them. We are using a lot of mobile applications every day. If you are lost in a new city, Google Maps gets you…
CTFs in Cyber-Security

CTFs from the Cyber Security domain, or Capture-The-Flag competitions, have nothing to do with games that imply physical activity (e.g Paintball , Airsoft ), but are perfect for hands-on and…
CISM Certified team member

We are more than happy to announce that our colleague, Alexandru Armean received the CISM (Certified Information Security Manager) certification.
Penetration Testing and Vulnerability Assessment

Usually, penetration testing is required for big applications, where security has already been taken into consideration from the beginning of the development process and the customer is hiring external testers, which might have a different view and therefore, might get more creative. The purpose would be to simulate a real attack and track the behavior of the system and how the team maintaining it is able to respond.
Opportunity through Cyber Security

Changes that occur in the EU legislation that address software security provided us a great opportunity to discuss about the future of cyber security.
Our Senior pentester Andrei, held a presentation about the opportunities that occur from legislation such as GDPR and how the software development companies can benefit from it, by increasing the security of their products and assuring the clients that they are safe.
Mobile security workshop by Daniel

This year our senior Security Engineer, Daniel, held a mobile security workshop showing how weak are mobile applications that do not take into consideration the most basic security principles.
The workshop was held in the office of Evozon Systems a software development company from Cluj-Napoca, that invests a lot of effort in the security of their products which together with the members of OWASP Cluj-Napoca decided to offer this one day training to anyone interested in cyber security.
PIN Code Authentication Bypass

We managed to bypass the authentication login page in less than 5 minutes, even if in theory, this level of architecture within the application had a great start (using SMSes as a factor of authentication).