Amy Schurr
A Q&A with NowSecure Cofounder Andrew Hoog TL;DR: What this shift means for your AppSec program AI is compressing the time between vulnerability discovery and exploitation thanks to frontier models. Anthropic’s Claude Mythos, designed to reason about code, identify vulnerabilities and simulate attack paths, recently demonstrated it could autonomously discover and exploit vulnerabilities and execute […]
How enterprise mobility teams can detect hidden AI features and reduce mobile app risk. Enterprise mobility and security teams face a growing challenge: AI capabilities quietly appear inside the mobile apps employees use every day, creating mobile shadow AI risk. TL;DR Enterprise mobility teams approve hundreds — sometimes thousands — of third‑party mobile apps for […]
AI security platforms rely on telemetry to detect threats and correlate risk, but still lack visibility into mobile application behavior — one of the fastest-growing sources of security signals. In brief: TL;DR AI security platforms analyze networks, endpoints and cloud activity. Yet many cannot see mobile app behavior that bypasses these solutions. That limitation matters […]
What is Mobile App Risk Intelligence? Mobile App Risk Intelligence analyzes mobile applications to identify security, privacy and behavioral risks that could expose enterprise data. It evaluates issues such as insecure data storage, dangerous permissions, third-party SDK vulnerabilities and risky network communications. For enterprise security teams, this matters because mobile apps can: As mobile devices […]
OWASP Mobile Application Security provides an industry-recognized foundation for reducing mobile app risk, yet many organizations struggle to apply these standards in day-to-day practice. With multiple resources — the Mobile Application Security Verification Standard (MASVS), the Mobile Application Security Weakness Enumeration (MASWE) and the Mobile Application Security Testing Guide (MASTG) — teams often lack clarity […]
Mobile apps often surface security risks earlier than other enterprise systems. Because mobile app code ships publicly through app stores, attackers can download, reverse engineer and analyze it, gaining a head start in finding data leaks and security vulnerabilities. For mobile AppSec and DevSecOps leaders, this reality makes mobile app security a critical focus for […]