Industry News
Mobile app security is critical to daily operations as remote work becomes the new reality. NowSecure tested the mobile app security and privacy of 25 mobile apps on iOS and Android platforms. See which mobile apps are the safest for remote workforce security.
The California Consumer Privacy Act (CCPA) took effect on Jan. 1, 2020, and is currently the toughest, most comprehensive privacy law in the United States. It has also spawned state privacy laws and proposed legislation. Given the level of personal data that mobile apps collect, store and transmit, companies must ensure their apps safeguard sensitive information and comply with CCPA and other relevant privacy laws.
As a longtime innovator of automated mobile appsec testing software and services, NowSecure continues to embrace emerging technology by delivering the world’s first Interactive Application Security Testing (IAST) technology purpose-built for mobile. Sometimes called DAST 2.0 or the next generation of DAST by the security industry, this advancement provides security analysts and app developers with greater visibility into app vulnerabilities and privacy issues.
Although we recommend periodic in-depth pen tests for high-risk mobile apps that run organization-critical processes or access sensitive information, this practice doesn’t scale well for DevOps teams. Mobile app pen testing requires intense human labor that simply can’t keep pace with the volume, velocity and frequency of DevOps releases. Many organizations can benefit from incorporating automated mobile appsec testing in the mobile DevSecOps toolchain to speed the delivery of secure mobile apps.
A keen focus on technology has helped fast casual company Sweetgreen expand across the nation. The company has plans to create a ‘food platform’ or integrated food system from supply chain all the way to delivery. Sweetgreen is but one example of mobile digital transformation that dramatically changes the way that companies interact with their customers, employees and partners. And attackers have taken notice of mobile.
Recent enhancements to the Frida open-source dynamic instrumentation toolkit greatly ease the process of conducting jailed testing. You no longer have to manually package the Frida Gadget in your target app. As long as the app is debuggable, Frida does that for you. This post will walk you through the process of using Frida on a jailed device.
What will 2020 hold for mobile application security? NowSecure predicts we’ll see an intensified focus on privacy, mobile DevSecOps gaining traction and ample activity around wearables and Internet of Things (IoT). Here are some of the mobile appsec trends and challenges that our experts anticipate we’ll see in 2020.
IDC estimates that by the end of 2019, organizations worldwide will have spent more than $1 trillion on digital transformation initiatives. But organizations struggle to develop apps fast enough to satisfy organization demand and security often falls by the wayside. Learn how mobile DevSecOps can support digital transformation by enabling companies to swiftly develop apps without compromising security.
While corporations widely recognize the convenience and productivity enhancements that mobile applications deliver to their customers and employees, too few realize that mobile apps also can present significant security and privacy risks. It’s not difficult to find examples of mobile app data breaches that resulted in severe consequences, both in terms of money and corporate reputation. Given that smartphone apps account for 63% of total digital minutes, according to the Comscore “2019 Global State of Mobile” report, it stands to reason that attackers are going where the traffic is.
NowSecure enables organizations to leverage Microsoft tools such as Azure DevOps, Visual Studio, Visual Studio App Center and GitHub to ship software faster. Over the years, NowSecure has helped organizations automate security and privacy testing of mobile apps in their DevOps continuous delivery toolchains. We’re pleased to announce the availability of a new pre-built connector for Azure DevOps and Azure Pipeline CI/CD tools — the NowSecure Extension for Microsoft Azure DevOps. Devs can find the Azure DevOps extension in the Microsoft Visual Studio Marketplace. Formerly known as Visual Studio Team Services, Microsoft Azure DevOps provides developers with a suite of integrated tools.