Industry News
TL;DR: OWASP released MASWE v1.0.0 on Aug. 17, 2026, the first stable version of the Mobile Application Security Weakness Enumeration and the missing middle layer between the OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP Mobile Application Security Testing Guide (MASTG). Two years of beta feedback produced 78 clearly defined organized as a […]
Apple is changing how AI interacts with mobile apps. Siri AI can now discover application functionality, invoke actions and orchestrate workflows across apps. Here’s what that means for mobile application security and what AppSec teams should do before these capabilities reach production. Apple has done something most security teams haven’t fully clocked yet. With iOS […]
Mobile apps have already made the jump to AI. Security programs haven’t. NowSecure’s 2026 Mobile App Risk Management (MARM) Survey of 485 senior security leaders across finance, healthcare, high tech and retail found that every single respondent now rates mobile apps as very important or critical to the business, and 95% deploy AI inside them […]
What Happened at OWASP MAScon Vienna? The inaugural OWASP MAScon in Vienna, Austria, demonstrated what many in the mobile application security community already suspected: demand for a dedicated, deeply technical mobile AppSec conference is strong. Held as part of OWASP Global AppSec EU 2026 at the Austria Center Vienna, MAScon brought together mobile security researchers, […]
MASTG v2.0 gives CISOs, auditors and regulators a measurable, evidence-based answer to mobile app risk. The OWASP Foundation released on June 30th the Mobile Application Security Testing Guide (MASTG) v2.0, marking a fundamental shift in how mobile security is defined and executed. This milestone release concludes a three-year, community-driven effort to transform the Mobile Application […]
Apple’s most AI-intensive developer conference ever just redefined the attack surface for every iOS app — and the security implications are immediate. What happened at WWDC 2026? Apple announced a sweeping transformation of its developer platform at the Worldwide Developers Conference (WWDC) 2026 technology showcase. On-device large language models, agentic workflows that take real-world actions, […]
A Q&A with NowSecure Cofounder Andrew Hoog TL;DR: What this shift means for your AppSec program AI is compressing the time between vulnerability discovery and exploitation thanks to frontier models. Anthropic’s Claude Mythos, designed to reason about code, identify vulnerabilities and simulate attack paths, recently demonstrated it could autonomously discover and exploit vulnerabilities and execute […]
Mobile apps often surface security risks earlier than other enterprise systems. Because mobile app code ships publicly through app stores, attackers can download, reverse engineer and analyze it, gaining a head start in finding data leaks and security vulnerabilities. For mobile AppSec and DevSecOps leaders, this reality makes mobile app security a critical focus for […]
AI Security in Mobile Apps: The Hidden Threat Multiplying Faster Than You Think Mobile applications have become the primary gateway to enterprise data, customer information and business operations. But there’s a rapidly evolving threat that most organizations are completely blind to: artificial intelligence (AI) embedded throughout their mobile app ecosystem. Recent analysis reveals a startling […]
Apple continues to double down on security and privacy in iOS 26. This release introduces new frameworks, expands cryptographic protections and strengthens parental controls in ways both end users and developers will notice. Below is a breakdown of the most important updates, with a focus on how they work under the hood and what developers […]