Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

Mobile Device Security Isn't All About Devices

50%
50%

Roberto Medrano, executive vice president of SOA Software, explains why securing mobile applications and APIs is so essential.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
KristianHartmann
50%
50%
KristianHartmann,
User Rank: Apprentice
1/11/2021 | 7:33:04 AM
Good Post, protecting the device is not the point.
Very true points, the device itself isn't even the value that needs to be protected. But with the increasing usage of mobile devices in companies and the BYOD strategy corporate data can be accessed so easily. We also just started to enroll our devices in a mobile device management software. That way we can secure corporate data and who has access to that. 
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
9/22/2014 | 11:44:20 AM
Re: Protecting the access of data
@Stratustician Great point here: "it is so important to ensure the right policies are in place to ensure not only are you securely accessing these resources, but that any data transmitted to the [mobile] devices is protected too." Question for you: do you think we have the technology necessary to really enforce those policies yet? 
Stratustician
100%
0%
Stratustician,
User Rank: Moderator
9/22/2014 | 11:17:00 AM
Protecting the access of data
Some great points here.  Mobile Device Security is really not so much about protecting the device contents itself, but as these devices start to replace laptops and desktops as a method of accessing corporate data, it is so important to ensure the right policies are in place to ensure not only are you securely accessing these resources, but that any data transmitted to the devices is protected too. 
Commentary
What the FedEx Logo Taught Me About Cybersecurity
Matt Shea, Head of Federal @ MixMode,  6/4/2021
Edge-DRsplash-10-edge-articles
A View From Inside a Deception
Sara Peters, Senior Editor at Dark Reading,  6/2/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23394
PUBLISHED: 2021-06-13
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
CVE-2021-34682
PUBLISHED: 2021-06-12
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.
CVE-2021-31811
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-31812
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-32552
PUBLISHED: 2021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.