NowSecure Platform Delivers Day-One iOS 27 Security Testing NowSecure Platform Delivers Day-One iOS 27 Security Testing See How →
magnifying glass icon

Amy Schurr

What OWASP Vulnerabilities in AI-Generated Code Mean for Mobile App Security

By / May 19, 2026 / Comments Off on What OWASP Vulnerabilities in AI-Generated Code Mean for Mobile App Security

Key Finding: 1 in 4 AI-generated code samples contain at least one confirmed OWASP vulnerability — and mobile apps face elevated risk due to their distributed, client-side execution model, direct exposure to untrusted devices and attack surfaces traditional AppSec tools are not designed to evaluate. Developers are increasingly turning to AI coding assistants to speed […]

Mobile App Privacy Risks Explained: SDKs, Data Collection & Hidden Exposure

By / May 13, 2026 / Comments Off on Mobile App Privacy Risks Explained: SDKs, Data Collection & Hidden Exposure

When regulators issue billion-dollar fines, enterprises can no longer ignore the mobile app privacy blind spot. Organizations face significant compliance exposure because mobile apps that power the business often rely on hidden third-party SDKs and data flows that security teams aren’t monitoring. Most organizations have invested heavily in securing web applications and cloud infrastructure. Mobile […]

The Third-Party Mobile App Risk Hidden Inside Your Approved Apps

By / April 28, 2026 / Comments Off on The Third-Party Mobile App Risk Hidden Inside Your Approved Apps

When Frederick County, Maryland, reviewed a mobile app used by its fire and rescue team, it passed every traditional check. The app connected to an ultrasound device, looked legitimate and had been approved. Binary-level analysis told a different story: the app was exposing protected health information, violating HIPAA in ways that no privacy label, MDM […]

How AI Models Like Mythos Are Changing Mobile AppSec Risk

By / April 20, 2026 / Comments Off on How AI Models Like Mythos Are Changing Mobile AppSec Risk

A Q&A with NowSecure Cofounder Andrew Hoog TL;DR: What this shift means for your AppSec program AI is compressing the time between vulnerability discovery and exploitation thanks to frontier models. Anthropic’s Claude Mythos, designed to reason about code, identify vulnerabilities and simulate attack paths, recently demonstrated it could autonomously discover and exploit vulnerabilities and execute […]

Mobile Shadow AI Risk: AI Governance for Third-Party Mobile Apps

By / March 25, 2026 / Comments Off on Mobile Shadow AI Risk: AI Governance for Third-Party Mobile Apps

How enterprise mobility teams can detect hidden AI features and reduce mobile app risk. Enterprise mobility and security teams face a growing challenge: AI capabilities quietly appear inside the mobile apps employees use every day, creating mobile shadow AI risk. TL;DR Enterprise mobility teams approve hundreds — sometimes thousands — of third‑party mobile apps for […]

Agentic AI Security Tools Are Only as Smart as Their Data — and They Are Missing Mobile Signals

By / March 18, 2026 / Comments Off on Agentic AI Security Tools Are Only as Smart as Their Data — and They Are Missing Mobile Signals

AI security platforms rely on telemetry to detect threats and correlate risk, but still lack visibility into mobile application behavior — one of the fastest-growing sources of security signals. In brief: TL;DR AI security platforms analyze networks, endpoints and cloud activity. Yet many cannot see mobile app behavior that bypasses these solutions.  That limitation matters […]