Industry News
Apple is changing how AI interacts with mobile apps. Siri AI can now discover application functionality, invoke actions and orchestrate workflows across apps. Here’s what that means for mobile application security and what AppSec teams should do before these capabilities reach production. Apple has done something most security teams haven’t fully clocked yet. With iOS […]
Mobile apps have already made the jump to AI. Security programs haven’t. NowSecure’s 2026 Mobile App Risk Management (MARM) Survey of 485 senior security leaders across finance, healthcare, high tech and retail found that every single respondent now rates mobile apps as very important or critical to the business, and 95% deploy AI inside them […]
What Happened at OWASP MAScon Vienna? The inaugural OWASP MAScon in Vienna, Austria, demonstrated what many in the mobile application security community already suspected: demand for a dedicated, deeply technical mobile AppSec conference is strong. Held as part of OWASP Global AppSec EU 2026 at the Austria Center Vienna, MAScon brought together mobile security researchers, […]
MASTG v2.0 gives CISOs, auditors and regulators a measurable, evidence-based answer to mobile app risk. The OWASP Foundation released on June 30th the Mobile Application Security Testing Guide (MASTG) v2.0, marking a fundamental shift in how mobile security is defined and executed. This milestone release concludes a three-year, community-driven effort to transform the Mobile Application […]
Apple’s most AI-intensive developer conference ever just redefined the attack surface for every iOS app — and the security implications are immediate. What happened at WWDC 2026? Apple announced a sweeping transformation of its developer platform at the Worldwide Developers Conference (WWDC) 2026 technology showcase. On-device large language models, agentic workflows that take real-world actions, […]
A Q&A with NowSecure Cofounder Andrew Hoog TL;DR: What this shift means for your AppSec program AI is compressing the time between vulnerability discovery and exploitation thanks to frontier models. Anthropic’s Claude Mythos, designed to reason about code, identify vulnerabilities and simulate attack paths, recently demonstrated it could autonomously discover and exploit vulnerabilities and execute […]
Mobile apps often surface security risks earlier than other enterprise systems. Because mobile app code ships publicly through app stores, attackers can download, reverse engineer and analyze it, gaining a head start in finding data leaks and security vulnerabilities. For mobile AppSec and DevSecOps leaders, this reality makes mobile app security a critical focus for […]
AI Security in Mobile Apps: The Hidden Threat Multiplying Faster Than You Think Mobile applications have become the primary gateway to enterprise data, customer information and business operations. But there’s a rapidly evolving threat that most organizations are completely blind to: artificial intelligence (AI) embedded throughout their mobile app ecosystem. Recent analysis reveals a startling […]
Apple continues to double down on security and privacy in iOS 26. This release introduces new frameworks, expands cryptographic protections and strengthens parental controls in ways both end users and developers will notice. Below is a breakdown of the most important updates, with a focus on how they work under the hood and what developers […]
Executive Summary Last week, we reported on a near-miss incident involving npm software supply-chain attacks impacting mobile applications. Unfortunately, a new wave of NPM supply chain compromises has been discovered affecting 187 packages including critical frameworks used in mobile app development. The good news? Our ongoing analysis of public mobile apps from the Google Play […]