Amy Schurr
Taking the perspective of an attacker and attempting to exploit mobile apps offers valuable insights into app security and privacy vulnerabilities. In fact, many organizations’ risk management programs require regular manual pen testing assessments of mobile apps to ensure they’re secure. Security analysts and pen testers rely on an arsenal of mobile app security testing […]
Mobile application security professionals following best practices for OWASP Mobile Application Security Testing now have a new resource to enhance their efficiency. As part of a series of updates to the OWASP MASVS and OWASP MASTG, the OWASP Mobile Application Security Project recently released a new fully automated version of its OWASP Mobile Application Security […]
Hurrying to meet an aggressive deadline, your mobile application development team will soon complete major updates to the company’s flagship Android and iOS applications. The project progresses smoothly until you discover that one major obstacle stands in the way of on-time release: nobody remembered to line up mobile penetration testing to validate mobile application security. […]
Escalating software supply-chain attacks pose a serious threat to the public sector and organizationes. Adversaries exploit vulnerabilities in third-party code to compromise a supplier to the vast digital ecosystem downstream. The ripple effect causes widespread disruption, financial loss and reputational damage and even endangers national security. Consider the enormous impact the SolarWinds software supply chain […]
Organizations face an ever-increasing volume of security and privacy risks associated with mobile applications. Challenges include ensuring mobile app security without slowing down developers, guarding against software supply chain risk and regulatory compliance violations, and upskilling security and dev teams with best practices for secure coding. Whether you seek to speed releases, improve quality, manage […]
With the global shortages of millions of software developers and millions of cybersecurity professionals, it’s clear that the global community needs more training capacity. As such, today we are proud to launch NowSecure Academy, our new free training and paid certification resource to upskill developers, architects, QA and security teams.