logo

Mobile apps: An Achilles' heel for web security?

ID: 89b1d919-84e5-5253-81f0-32cfc57a9f9f

STIX ID: report--89b1d919-84e5-5253-81f0-32cfc57a9f9f

Feed Name: Zscaler Security Research Blog

Threat Score
50/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

The report demonstrates that JotNot Scanner Pro stores authentication credentials (Evernote, Google Docs, iDisk/WebDAV) in cleartext within its com.mobitech3000.JotNotIPhone.plist inside iTunes backups, meaning an attacker with access to a user's backup can obtain usernames and passwords and potentially access linked services; the author uses this as an example of wider mobile app security failures and urges better developer practices and token-based APIs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.