NowSecure Marketing
OWASP AppSec USA kicks off in San Jose on Monday, Oct. 8, and NowSecure is proud to participate in the event as a Platinum Sponsor. To help you plan your time during the general sessions on Thursday and Friday, we’ve highlighted several sessions that we’re eager to attend.
In the quest to speed development of secure mobile apps, many of our customers plug automated appsec testing directly into their CI/CD toolchain. NowSecure embraces the fundamental principles of secure DevOps — leverage automation, integration, and speed to reduce friction and drive continuous improvement. Because mobile app development is fundamentally different than web app development, […]
On the eve of the ATARC Federal Mobile Technology Summit on August 30, 2018, NowSecure analyzed 88 publicly available mobile apps from across multiple U.S. federal government agencies. Overall, we found that 25% of 88 mobile apps have high and/or critical CVSS-scored vulnerabilities and over 20% do not comply with National Information Assurance Partnership (NIAP) requirements. Read the blog to see more data.
To help security analysts and developers craft a more effective list of mobile testing requirements, we’ve assembled a Mobile App Security Testing Checklist of three key questions to address
A staggering 85% of the 45,000 mobile apps reviewed for this benchmark analysis violated at least 1 or more of the OWASP MASVS. This benchmark report identifies significant risks of data leakage in mobile apps with insecure data storage, insecure network communications and insecure coding practices that all organizations must address in their risk models and app security programs.
As with all things mobile, there are both secure and insecure ways of downloading and using zipped content. Back in 2014, NowSecure identified and properly disclosed zip file download and remote code execution (RCE) vulnerabilities on Android for Samsung and Vungle. Now Pangu has posted about iOS zipfile download issues identified as ZipperDown.