Andrew Hoog
Executive Summary Recent reporting on the White House mobile app has overstated several security and privacy concerns by focusing on what the app could do rather than what it actually does in practice. NowSecure analyzed the app using static and dynamic mobile application security testing. We found no evidence of unauthorized location tracking described in […]
It doesn’t take a particle physicist to figure out that authenticated mobile app security testing will give you better results. But I never really had data to back it up. Recently, NowSecure CTO David Weinstein analyzed about 105,000 mobile app assessments — roughly 5,000 authenticated and 100,000 unauthenticated, across both Android and iOS — and […]
iVerify recently published a detailed technical analysis uncovering a new iMessage vulnerability — dubbed “NICKNAME” — that could be used in a zero-click attack to compromise iOS devices. The exploit abuses the way iOS handles iMessage contact profile updates (nicknames) to trigger memory corruption and potentially deliver spyware without any user interaction. What We Know […]
A NowSecure mobile application security and privacy assessment has uncovered multiple security and privacy issues in the DeepSeek iOS mobile app that lead us to urge enterprises to prohibit/forbid its usage in their organizations. As the top iOS app since Jan 25, 2025, the DeepSeek iOS app has already been downloaded and used on millions […]
The Hidden Risks in Mobile SDKs Many app developers are unaware of the potential misuse of their platforms for unauthorized data collection, especially through advertising networks embedded in Software Development Kits (SDKs) in their app’s supply chain. These hidden risks can lead to: By integrating third-party SDKs without proper vetting, developers may unknowingly introduce vulnerabilities […]
On Oct. 25, 2022, OpenSSL began pre-notifying organizations of two critical vulnerabilities in OpenSSL 3.0.x. On the positive side, OpenSSL 3.0 had not been widely deployed yet, and even better on Nov 1, 2022, the two vulnerabilities were downgraded from critical to high. However, on the heels of other recent highly impactful vulnerabilities like Log4j […]