Meet us at Black Hat 2026

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
New: AI-native capabilities built for the speed and risk of AI-driven app development. New: AI-native capabilities built for the speed and risk of AI-driven app development. Learn More.
magnifying glass icon

Industry News

What AppSec Teams Need to Know About App Intents, Siri AI and the New iOS 27 Attack Surface

By Jeff Kneis / August 5, 2026 / Comments Off on What AppSec Teams Need to Know About App Intents, Siri AI and the New iOS 27 Attack Surface

Apple is changing how AI interacts with mobile apps. Siri AI can now discover application functionality, invoke actions and orchestrate workflows across apps. Here’s what that means for mobile application security and what AppSec teams should do before these capabilities reach production. Apple has done something most security teams haven’t fully clocked yet. With iOS […]

AI Is Already in Your Mobile Apps. Most Security Programs Haven’t Caught Up.

By Amy Schurr / July 15, 2026 / Comments Off on AI Is Already in Your Mobile Apps. Most Security Programs Haven’t Caught Up.

Mobile apps have already made the jump to AI. Security programs haven’t. NowSecure’s 2026 Mobile App Risk Management (MARM) Survey of 485 senior security leaders across finance, healthcare, high tech and retail found that every single respondent now rates mobile apps as very important or critical to the business, and 95% deploy AI inside them […]

OWASP MAScon Vienna Showed the Future of Mobile Application Security

By Jeff Kneis / July 2, 2026 / Comments Off on OWASP MAScon Vienna Showed the Future of Mobile Application Security

What Happened at OWASP MAScon Vienna? The inaugural OWASP MAScon in Vienna, Austria, demonstrated what many in the mobile application security community already suspected: demand for a dedicated, deeply technical mobile AppSec conference is strong. Held as part of OWASP Global AppSec EU 2026 at the Austria Center Vienna, MAScon brought together mobile security researchers, […]

OWASP Releases MASTG v2.0 — NowSecure Contributed 320+ Pull Requests to Make It Happen

By Jeff Kneis / June 26, 2026 / Comments Off on OWASP Releases MASTG v2.0 — NowSecure Contributed 320+ Pull Requests to Make It Happen

MASTG v2.0 gives CISOs, auditors and regulators a measurable, evidence-based answer to mobile app risk. The OWASP Foundation released on June 30th the Mobile Application Security Testing Guide (MASTG) v2.0, marking a fundamental shift in how mobile security is defined and executed. This milestone release concludes a three-year, community-driven effort to transform the Mobile Application […]

iOS 27 Security: What WWDC 2026’s AI Features Mean for Mobile App Risk

By Jeff Kneis / June 11, 2026 / Comments Off on iOS 27 Security: What WWDC 2026’s AI Features Mean for Mobile App Risk

Apple’s most AI-intensive developer conference ever just redefined the attack surface for every iOS app — and the security implications are immediate. What happened at WWDC 2026? Apple announced a sweeping transformation of its developer platform at the Worldwide Developers Conference (WWDC) 2026 technology showcase. On-device large language models, agentic workflows that take real-world actions, […]

How AI Models Like Mythos Are Changing Mobile AppSec Risk

By Amy Schurr / April 20, 2026 / Comments Off on How AI Models Like Mythos Are Changing Mobile AppSec Risk

A Q&A with NowSecure Cofounder Andrew Hoog TL;DR: What this shift means for your AppSec program AI is compressing the time between vulnerability discovery and exploitation thanks to frontier models. Anthropic’s Claude Mythos, designed to reason about code, identify vulnerabilities and simulate attack paths, recently demonstrated it could autonomously discover and exploit vulnerabilities and execute […]

Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026

By Amy Schurr / January 7, 2026 / Comments Off on Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026

Mobile apps often surface security risks earlier than other enterprise systems. Because mobile app code ships publicly through app stores, attackers can download, reverse engineer and analyze it, gaining a head start in finding data leaks and security vulnerabilities. For mobile AppSec and DevSecOps leaders, this reality makes mobile app security a critical focus for […]

AI Governance for Mobile Apps: How to Secure AI, Data and Compliance and Scale

By NowSecure Marketing / December 15, 2025 / Comments Off on AI Governance for Mobile Apps: How to Secure AI, Data and Compliance and Scale

AI Security in Mobile Apps: The Hidden Threat Multiplying Faster Than You Think Mobile applications have become the primary gateway to enterprise data, customer information and business operations. But there’s a rapidly evolving threat that most organizations are completely blind to: artificial intelligence (AI) embedded throughout their mobile app ecosystem. Recent analysis reveals a startling […]

iOS 26 Security & Privacy Features Explained: Essential Insights for Developers and Users

By Jeff Kneis / September 19, 2025 / Comments Off on iOS 26 Security & Privacy Features Explained: Essential Insights for Developers and Users

Apple continues to double down on security and privacy in iOS 26. This release introduces new frameworks, expands cryptographic protections and strengthens parental controls in ways both end users and developers will notice. Below is a breakdown of the most important updates, with a focus on how they work under the hood and what developers […]

New NPM Supply Chain-Attack Hits 187 Packages — Here’s Why Mobile Apps Are Still at Risk

By Jeff Kneis / September 16, 2025 / Comments Off on New NPM Supply Chain-Attack Hits 187 Packages — Here’s Why Mobile Apps Are Still at Risk

Executive Summary Last week, we reported on a near-miss incident involving npm software supply-chain attacks impacting mobile applications. Unfortunately, a new wave of NPM supply chain compromises has been discovered affecting 187 packages including critical frameworks used in mobile app development.  The good news? Our ongoing analysis of public mobile apps from the Google Play […]