Amy Schurr
Before NowSecure fielded its 2026 Mobile App Risk Management (MARM) Survey, we ran an experiment most survey research skips. We asked three leading AI models, Claude Sonnet, ChatGPT and Gemini, to predict how senior mobile application security leaders would answer the survey. Then we compared those predictions with the survey responses. We weren’t asking AI […]
TL;DR: OWASP released MASWE v1.0.0 on Aug. 17, 2026, the first stable version of the Mobile Application Security Weakness Enumeration and the missing middle layer between the OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP Mobile Application Security Testing Guide (MASTG). Two years of beta feedback produced 78 clearly defined organized as a […]
During its recent hackathon, NowSecure’s research and engineering teams built working prototypes of AI-powered tools spanning the mobile app security lifecycle: agentic reverse engineering and finding validation, real-device exploit confirmation, AI-generated mobile device management (MDM) policy guidance and dramatically expanded vulnerability database coverage. Each prototype built on NowSecure’s research, specialized mobile application security testing tooling […]
Mobile apps have already made the jump to AI. Security programs haven’t. NowSecure’s 2026 Mobile App Risk Management (MARM) Survey of 485 senior security leaders across finance, healthcare, high tech and retail found that every single respondent now rates mobile apps as very important or critical to the business, and 95% deploy AI inside them […]
Most vulnerability management programs are built on a simple assumption: vulnerabilities are discovered, assigned a CVE, analyzed, prioritized and remediated. A new federal audit suggests that model is under increasing strain. The National Vulnerability Database (NVD) backlog isn’t just a government process issue; it’s evidence that vulnerability volume, software supply-chain complexity and shrinking exploitation timelines […]
Key Finding: 1 in 4 AI-generated code samples contain at least one confirmed OWASP vulnerability — and mobile apps face elevated risk due to their distributed, client-side execution model, direct exposure to untrusted devices and attack surfaces traditional AppSec tools are not designed to evaluate. Developers are increasingly turning to AI coding assistants to speed […]