#MASVS
How to pass the OWASP MASVS verification by design?

In Admincontrol, our Android app and IOS app passed the @owasp.org MASVS verification by deciding security requirements and -controls using a game. Here is how...https://dev.to/owasp/how-to-pass-the-owasp-masvs-verification-by-design-2cf9 #appsec
February 14, 2025 at 8:35 AM
Hehe masvs voce ném sabe. Tenho crâshe em vc, sabiar? Aposto que nak sabiar
March 19, 2025 at 12:39 AM
Did you know that ISO27001 says that "application security requirements should be identified" and include requirements you find in #OWASP #ASVS and #MASVS ?

OWASP Cornucopia help you define these requirements.

Play the game at copi.owasp.org ?

#cybersec #appsec #infosec #threatmodeling #isms
Copi · Play Cornucopia Online
copi.owasp.org
December 4, 2024 at 9:09 AM
Play Mobile OWASP Cornucopia to pass the MASVS verification and pentest with flying colors.

agilestationery.com/products/owa...

Part of the profit goes to the OWASP Foundation. Btw. I am not getting a single dime.

#appsec #cybersec #infosec #mobile #masvs #threatmodeling #owasp
OWASP® Cornucopia Mobile App Edition - Threat Modeling Cards
The Mobile App Edition is the second Cornucopia deck specifically for threat modeling mobile applications and adheres to the same principles and game rules as the original OWASP Cornucopia. This editi...
agilestationery.com
November 29, 2024 at 6:12 AM
Happy new year and welcome to 2025! 🎊🥂

The year 2024 for a OWASP Cornucopia co-leader was as following.

From MASVS checks to firewall talks
Through grumpy devs and skeptic walks
We turned security into a game to play
Making threats less scary day by day
January 5, 2025 at 9:17 PM
Docs/ARF EUDI NON impongono a wallet-provider nazionali precise librerie/API per check integrità ambiente+app né vincolano distribuzione solo ad Apple App Store + Google Play Store.

Richiedono che scelte siano high-level compliant con OWASP MASVS
mas.owasp.org/MASVS/

⬇️2/6
July 28, 2025 at 8:12 PM
🎉📱 Mobile security doesn’t have to be scary!
Our friends @NowSecureMobile turned MASVS, MASTG and MASWE into a super-easy, infographic, perfect for devs, testers and security pros alike!
Check it out:
www.nowsecure.com/bl...

March 11, 2026 at 4:54 PM
🙇🏼‍♀️🎶🌔✨
Late night music and reading
mas.owasp.org/MASVS/
somafm.com/groovesalad/
OWASP MASVS - OWASP Mobile Application Security
mas.owasp.org
July 24, 2026 at 4:22 AM
Fill out descriptions for the OWASP Cornucopia mobile app edition cards on the website based on the MASVS, MASTG and physical card descriptions.

The mobile app edition lacks descriptions for each of the cards in the edition on the website. e.g: cornucopia.owasp.org/card/mobilea...
OWASP Cornucopia - Mobile App Edition - Authentication & Authorization (AA4)
Vandana can bypass biometric authentication because the authentication is misconfigured or not implemented correctly
cornucopia.owasp.org
January 31, 2026 at 1:07 PM
🚀 Celebrating 3 years of partnership with @nowsecure.bsky.social as an OWASP MAS Advocate! From 320+ PRs to driving key milestones like MASVS v2.0.0, MASWE, and more, their impact on mobile app security is unmatched. THANK YOU!

mas.owasp.org/news/2025/04...
Celebrating 3 Years of NowSecure as an OWASP MAS Advocate - OWASP Mobile Application Security
mas.owasp.org
April 9, 2025 at 3:39 PM
iOSSecuritySuite
A Swift library for iOS app security and anti-tampering.

It detects jailbreaks, debuggers, emulators, reverse engineering tools, and more - aligned with OWASP MASVS v8. Free for small teams, and easy to integrate via CocoaPods, SwiftPM, or Carthage.
github.com/securing/IOS...
GitHub - securing/IOSSecuritySuite: iOS platform security & anti-tampering Swift library
iOS platform security & anti-tampering Swift library - securing/IOSSecuritySuite
github.com
June 4, 2025 at 4:44 AM
🔥 Hack Android, iOS & IoT Apps!
Train with Abraham Aranguren in a 3-day intensive course at OWASP London Training Days.
CTFs, real challenges, Frida & Objection, built on OWASP MSTG & MASVS.
👉 londonowasptrainingd...

#appsec #mobilesecurity #iot #owasp
January 20, 2026 at 11:49 AM
Each of the cards are also represented on our website at cornucopia.owasp.org/cards with the MASVS and MASTG mapping going to mas.owasp.org It’s thanks to @owasp-mas.bsky.social and @grepharder.bsky.social that we found the applicable threats for the mobile version of OWASP Cornucopia.
cornucopia.owasp.org
February 14, 2025 at 1:43 PM
A cool, comprehensive guide to securing iOS apps with practical tactics: TLS/SSL pinning, safe storage via Keychain/Secure Enclave, CryptoKit encryption and key agreement, and TOTP 2FA - aligned with OWASP MASVS

medium.com/@Sergey.Zhur...
Securing iOS Apps: Best Practices, Tools, and Techniques
Hi everyone! My name is Sergey. I work as an iOS Tech Lead at Futurra Group, where I lead the development of mobile solutions and drive…
medium.com
September 21, 2025 at 12:56 PM
Android Malware in 2026: Why Overlay Attacks Still Bypass Your Pentests – And How to Stop Them with Frida & Native Lib Analysis + Video

Introduction: Modern Android malware no longer hides solely in decompiled Java code; threat actors embed malicious logic in native libraries, dynamically loaded…
Android Malware in 2026: Why Overlay Attacks Still Bypass Your Pentests – And How to Stop Them with Frida & Native Lib Analysis + Video
Introduction: Modern Android malware no longer hides solely in decompiled Java code; threat actors embed malicious logic in native libraries, dynamically loaded DEX files, and runtime-decrypted strings that evade static analysis. For penetration testers, this means checking OWASP MASVS checkboxes is insufficient – you must simulate real-world scenarios where a banking trojan like Cerberus or SharkBot shares the device and uses overlay attacks, keylogging, and SMS interception to compromise your app.
undercodetesting.com
June 10, 2026 at 6:48 AM
In case you missed it, you can also read about our release of Mobile App Edition v2.0: dev.to/owasp/owasp-...

It's possible to pre-order the latest edition from CyberSec Games at: cybersecgames.com/collections/...
OWASP® Cornucopia 2.0 Mobile App Edition - Threat Modeling Cards
OWASP® Cornucopia Mobile App Edition v2.0 is a practical threat modelling card game designed to help teams identify and discuss security risks in mobile applications. Updated for MASVS v2.1, MASTG v2....
cybersecgames.com
September 12, 2026 at 10:32 AM
We are happy to announce the release of the OWASP Cornucopia Mobile App Edition v2.0. The latest edition is compatible with MASVS v2.1, MASTG v2.0, and MASWE v1.0, and features 80 threats that cover all the requirements, tests, and weaknesses of the OWASP Mobile Application Security Project. (2/3)
September 10, 2026 at 10:02 AM
It’s #CybersecurityAwarenessMonth!

We’re kicking off with mobile app security testing (MAST) - a critical step in the development lifecycle, helping devs spot vulnerabilities in their apps.

This paper covers both OWASP MASVS and MASTG: hubs.la/Q03LHpSd0
#OWASP #MASVS #MobileAppSecurity
OWASP Mobile App Security Standards and Guidelines | Guardsquare
Explore OWASP’s mobile app security best practices, privacy standards, and testing framework in our OWASP Verification and Guidelines Report.
www.guardsquare.com
October 1, 2025 at 1:01 PM
Static analysis for Android apps based on the OWASP MASVS framework
November 14, 2025 at 8:36 AM