2026 Mobile App Risk Management Survey

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
Your Agentic Security Blueprint for iOS 27 Webinar Your Agentic Security Blueprint for iOS 27 Webinar Register Now
magnifying glass icon

David Weinstein

1-in-2 phones sold in Africa exfiltrate telemetry to China

By / July 8, 2026 / Comments Off on 1-in-2 phones sold in Africa exfiltrate telemetry to China

What the Transsion Telemetry Research Means for Mobile Security Transsion is the world’s fourth-largest smartphone manufacturer. Its brands — TECNO, Infinix, and itel — dominate markets across Africa, South Asia, Southeast Asia, and Latin America. Every one of these devices ships with a first-party Android telemetry framework: Athena for event collection and oneID for cross-app […]

The Vercel Breach Is a Mobile Supply-Chain Problem, Too

By / April 20, 2026 / Comments Off on The Vercel Breach Is a Mobile Supply-Chain Problem, Too

Today Vercel confirmed a security incident but the real risk may not be where most teams are looking. Attackers reportedly pivoted through a compromised OAuth grant at Context AI, took over a Vercel employee’s Google account, and accessed customer API keys, source code and database contents. Vercel has advised customers to rotate anything marked “non-sensitive.” […]

Inside a Mobile App’s Data Overreach: What Our Phia Safari Extension Analysis Reveals

By / November 19, 2025 / Comments Off on Inside a Mobile App’s Data Overreach: What Our Phia Safari Extension Analysis Reveals

Mobile apps collect more data than most users expect. Developers race to personalize experiences, train AI models and optimize revenue. That pressure pushes many apps to grab as much behavioral data as possible. During a recent NowSecure investigation, we analyzed the AI-powered Phia iOS shopping app and discovered how quickly helpful features can turn into […]

New NPM Supply Chain-Attack Hits 187 Packages — Here’s Why Mobile Apps Are Still at Risk

By / September 16, 2025 / Comments Off on New NPM Supply Chain-Attack Hits 187 Packages — Here’s Why Mobile Apps Are Still at Risk

Executive Summary Last week, we reported on a near-miss incident involving npm software supply-chain attacks impacting mobile applications. Unfortunately, a new wave of NPM supply chain compromises has been discovered affecting 187 packages including critical frameworks used in mobile app development.  The good news? Our ongoing analysis of public mobile apps from the Google Play […]

Major NPM Supply-Chain Attack: Potential Impact on Mobile Applications

By / September 8, 2025 / Comments Off on Major NPM Supply-Chain Attack: Potential Impact on Mobile Applications

Today, security researchers revealed details of a massive supply-chain attack affecting some of the most popular NPM packages in the JavaScript ecosystem. The attack, which compromised packages including chalk, debug, ansi-styles and others with a combined 2+ billion weekly downloads, represents one of the most significant supply-chain incidents in recent memory. This is a big […]

The AI Expansion of the Mobile App Attack Surface

By / November 13, 2024 / Comments Off on The AI Expansion of the Mobile App Attack Surface

Artificial Intelligence (AI) is transforming technology, and mobile apps are no exception. Organizations across verticals and size are racing to embrace AI technologies to drive productivity, but surveys indicate many consumers remain suspicious of the technology. The security, reliability and privacy implications of AI experiences face a laundry list of questions: Risks Introduced by Generative […]