Best Practices
What Happened at OWASP MAScon Vienna? The inaugural OWASP MAScon in Vienna, Austria, demonstrated what many in the mobile application security community already suspected: demand for a dedicated, deeply technical mobile AppSec conference is strong. Held as part of OWASP Global AppSec EU 2026 at the Austria Center Vienna, MAScon brought together mobile security researchers, […]
MASTG v2.0 gives CISOs, auditors and regulators a measurable, evidence-based answer to mobile app risk. The OWASP Foundation released on June 30th the Mobile Application Security Testing Guide (MASTG) v2.0, marking a fundamental shift in how mobile security is defined and executed. This milestone release concludes a three-year, community-driven effort to transform the Mobile Application […]
Most vulnerability management programs are built on a simple assumption: vulnerabilities are discovered, assigned a CVE, analyzed, prioritized and remediated. A new federal audit suggests that model is under increasing strain. The National Vulnerability Database (NVD) backlog isn’t just a government process issue; it’s evidence that vulnerability volume, software supply-chain complexity and shrinking exploitation timelines […]
Why Line of Business and the CISO can finally be on the same team. AI is rapidly transforming how mobile applications are built. One emerging approach, often referred to as vibe coding — AI-assisted generation of mobile applications using natural language prompts — is enabling teams to create apps faster than ever before. But speed […]
Today Vercel confirmed a security incident but the real risk may not be where most teams are looking. Attackers reportedly pivoted through a compromised OAuth grant at Context AI, took over a Vercel employee’s Google account, and accessed customer API keys, source code and database contents. Vercel has advised customers to rotate anything marked “non-sensitive.” […]
AI-generated (“vibe coded”) mobile apps can be built in hours but often lack basic security controls like encryption, secure storage and compliance requirements. This blog series outlines the process I went through building my own app capturing key observations and lessons useful for those of us using AI for personal and business use. I am […]
OWASP Mobile Application Security provides an industry-recognized foundation for reducing mobile app risk, yet many organizations struggle to apply these standards in day-to-day practice. With multiple resources — the Mobile Application Security Verification Standard (MASVS), the Mobile Application Security Weakness Enumeration (MASWE) and the Mobile Application Security Testing Guide (MASTG) — teams often lack clarity […]
As mobile apps proliferate throughout the business, the attack surface and regulatory scrutiny expands just as quickly. For CISOs and VPs of AppSec, the question is no longer if mobile app security needs structure; it’s how soon you can adopt one. If your organization’s mobile app security efforts feel reactive, fragmented or manual, it’s time […]
AI Security in Mobile Apps: The Hidden Threat Multiplying Faster Than You Think Mobile applications have become the primary gateway to enterprise data, customer information and business operations. But there’s a rapidly evolving threat that most organizations are completely blind to: artificial intelligence (AI) embedded throughout their mobile app ecosystem. Recent analysis reveals a startling […]
Mobile applications power how we live and work, but behind the convenience lies a web of hidden data collection that puts users and enterprises at risk. Increased user profiling and real-time data harvesting (such as those implicated in the Gravy Analytics incident) has raised the stakes for protecting mobile app users from privacy leaks. Safeguarding […]