Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Register Now →
magnifying glass icon

Amy Schurr

8 Mobile AppSec & Privacy Predictions for 2021

By / January 6, 2021 / Comments Off on 8 Mobile AppSec & Privacy Predictions for 2021

What should you expect for mobile appsec in 2021? NowSecure mobile application security experts make our top 8 predictions for the new year. Learn more and see how we can help reduce risk for your organization.

The Top 5 Mobile AppSec & Privacy Breaches of 2020

By / December 21, 2020 / Comments Off on The Top 5 Mobile AppSec & Privacy Breaches of 2020

In 2020, several mobile application security threats put customer data at risk and jeopardized revenue and brand reputation. Here are five mobile app security issues and privacy breaches that stood out in a year of rapid digital transformation.

New OWASP Android Crack-Me App Sponsored by NowSecure

By / October 21, 2020 / Comments Off on New OWASP Android Crack-Me App Sponsored by NowSecure

As a proud sponsor of the OWASP Mobile Security Project and the Global AppSec conference, NowSecure researchers helped develop and maintain the Radare2 Pay v1.0 Android crack-me app featured in the OWASP Mobile Security Testing Guide (MSTG). Intended to be similar to popular mobile payment applications, the Radare2 Pay app is difficult to crack. It features layers and layers of obfuscation and protection and anti-rooting technology in order to delay attacks.

Mobile AppSec Q&A: From Breaker to Builder

By / October 7, 2020 / Comments Off on Mobile AppSec Q&A: From Breaker to Builder

Before joining the NowSecure research team this year, Grant Douglas worked as a mobile security consultant and has hundreds of mobile app pen tests under his belt. In this Q&A discussion, he shares insight about the differences between an attack and builder mindset, his favorite mobile appsec tools and technologies and his passion for CTF competitions.

How To Evaluate an Automated NIAP Vetting Tool for Mobile Apps

By / September 2, 2020 / Comments Off on How To Evaluate an Automated NIAP Vetting Tool for Mobile Apps

Evaluating mobile applications for compliance with National Information Assurance Partnership (NIAP) security requirements can be a lengthy, costly process without automation. But not all NIAP mobile app vetting tools are created equally, so federal government agencies should choose carefully. Some solutions only support partial implementation of NIAP requirements, use an older version or lack complete detail and accuracy that leaves your organization at risk. Learn what questions to ask vendors to choose a tool that meets your needs.

Q&A: Adventures in iOS App Security Research

By / August 20, 2020 / Comments Off on Q&A: Adventures in iOS App Security Research

NowSecure Mobile Security Researcher Dawn Isabel has been an avid contributor to bug bounties over the years and has earned many accolades. Before joining the expert research team at NowSecure, Isabel amassed well-rounded experience at IOActive, Hewlett Packard Enterprise, the University of Michigan and Ford Motor Company. We recently spoke with
Isabel about testing the security of iOS and Apple Watch apps, the bug bounty community, and the tools she uses most.