2026 Mobile App Risk Management Survey

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
Your Agentic Security Blueprint for iOS 27 Webinar Your Agentic Security Blueprint for iOS 27 Webinar Register Now
magnifying glass icon

Andrew Hoog

An Expert’s Perspective on the White House App — Putting Security Findings in Context

By Andrew Hoog / March 31, 2026 / Comments Off on An Expert’s Perspective on the White House App — Putting Security Findings in Context

Executive Summary Recent reporting on the White House mobile app has overstated several security and privacy concerns by focusing on what the app could do rather than what it actually does in practice. NowSecure analyzed the app using static and dynamic mobile application security testing. We found no evidence of unauthorized location tracking described in […]

Authenticated Mobile App Security Testing Finds 78% More Sensitive Data Risk

By Andrew Hoog / February 25, 2026 / Comments Off on Authenticated Mobile App Security Testing Finds 78% More Sensitive Data Risk

It doesn’t take a particle physicist to figure out that authenticated mobile app security  testing will give you better results. But I never really had data to back it up. Recently, NowSecure CTO David Weinstein analyzed about 105,000 mobile app assessments — roughly 5,000 authenticated and 100,000 unauthenticated, across both Android and iOS —  and […]

NowSecure Responds to ‘NICKNAME’ iMessage Exploit

By Andrew Hoog / June 5, 2025 / Comments Off on NowSecure Responds to ‘NICKNAME’ iMessage Exploit

iVerify recently published a detailed technical analysis uncovering a new iMessage vulnerability — dubbed “NICKNAME” — that could be used in a zero-click attack to compromise iOS devices. The exploit abuses the way iOS handles iMessage contact profile updates (nicknames) to trigger memory corruption and potentially deliver spyware without any user interaction. What We Know […]

NowSecure Uncovers Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App

By Andrew Hoog / February 6, 2025 / Comments Off on NowSecure Uncovers Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App

A NowSecure mobile application security and privacy assessment has uncovered multiple security and privacy issues in the DeepSeek iOS mobile app that lead us to urge enterprises to prohibit/forbid its usage in their organizations. As the top iOS app since Jan 25, 2025, the DeepSeek iOS app has already been downloaded and used on millions […]

Know Your SDKs: Protect Your Mobile Apps and Users from Hidden Risks

By Andrew Hoog / January 22, 2025 / Comments Off on Know Your SDKs: Protect Your Mobile Apps and Users from Hidden Risks

The Hidden Risks in Mobile SDKs Many app developers are unaware of the potential misuse of their platforms for unauthorized data collection, especially through advertising networks embedded in Software Development Kits (SDKs) in their app’s supply chain. These hidden risks can lead to: By integrating third-party SDKs without proper vetting, developers may unknowingly introduce vulnerabilities […]

Is Your Mobile App Exposed to OpenSSL Vulnerabilities?

By Andrew Hoog / November 3, 2022 / Comments Off on Is Your Mobile App Exposed to OpenSSL Vulnerabilities?

On Oct. 25, 2022, OpenSSL began pre-notifying organizations of two critical vulnerabilities in OpenSSL 3.0.x. On the positive side, OpenSSL 3.0 had not been widely deployed yet, and even better on Nov 1, 2022, the two vulnerabilities were downgraded from critical to high. However, on the heels of other recent highly impactful vulnerabilities like Log4j […]