Meet us at Black Hat 2026

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
New: AI-native capabilities built for the speed and risk of AI-driven app development. New: AI-native capabilities built for the speed and risk of AI-driven app development. Learn More.
magnifying glass icon

Industry News

New NPM Supply Chain-Attack Hits 187 Packages — Here’s Why Mobile Apps Are Still at Risk

By Jeff Kneis / September 16, 2025 / Comments Off on New NPM Supply Chain-Attack Hits 187 Packages — Here’s Why Mobile Apps Are Still at Risk

Executive Summary Last week, we reported on a near-miss incident involving npm software supply-chain attacks impacting mobile applications. Unfortunately, a new wave of NPM supply chain compromises has been discovered affecting 187 packages including critical frameworks used in mobile app development.  The good news? Our ongoing analysis of public mobile apps from the Google Play […]

Major NPM Supply-Chain Attack: Potential Impact on Mobile Applications

By Jeff Kneis / September 8, 2025 / Comments Off on Major NPM Supply-Chain Attack: Potential Impact on Mobile Applications

Today, security researchers revealed details of a massive supply-chain attack affecting some of the most popular NPM packages in the JavaScript ecosystem. The attack, which compromised packages including chalk, debug, ansi-styles and others with a combined 2+ billion weekly downloads, represents one of the most significant supply-chain incidents in recent memory. This is a big […]

What Is Mobile App Risk Management and Why Your Enterprise Needs It

By Amy Schurr / August 27, 2025 / Comments Off on What Is Mobile App Risk Management and Why Your Enterprise Needs It

How CISOs, AppSec leaders and DevSecOps teams can secure mobile apps, safeguard privacy, reduce risk and prove compliance. Executive Summary Most enterprises already have risk management programs for cloud, network and web applications. However, many lack a comparable framework for mobile apps even though apps often are the primary way customers, partners and employees interact […]

NowSecure Achieves SOC 2 Type 2 Compliance for Fifth Year in a Row — With Zero Deficiencies

By Amy Schurr / August 13, 2025 / Comments Off on NowSecure Achieves SOC 2 Type 2 Compliance for Fifth Year in a Row — With Zero Deficiencies

NowSecure has once again demonstrated its leadership in mobile app security by achieving SOC 2 Type 2 compliance for the fifth consecutive year. This accomplishment reinforces NowSecure’s standing as the only enterprise-grade mobile application security testing (MAST) platform to consistently deliver clean SOC 2 Type 2 compliance year after year.  The independent SOC 2 audit […]

What You Missed at NowSecure Connect 2025: Mobile Security, Privacy & Compliance Trends

By Amy Schurr / June 18, 2025 / Comments Off on What You Missed at NowSecure Connect 2025: Mobile Security, Privacy & Compliance Trends

Mobile app risk is not just a technical issue, it poses a serious business threat. That’s the central message speakers amplify in NowSecure Connect 2025: Avoid the APPocalypse, a virtual event at which industry leaders, security professionals and app development leaders gathered to confront the rising tide of mobile risk. In his opening keynote, NowSecure […]

NowSecure Drives OWASP Mobile Standards to Strengthen AppSec

By Amy Schurr / April 16, 2025 / Comments Off on NowSecure Drives OWASP Mobile Standards to Strengthen AppSec

NowSecure recently celebrated three years of contributing to the OWASP Mobile App Security Project which produces globally recognized standards for secure mobile app development and mobile app security testing. The company’s industry leadership as an OWASP MAS Advocate has advanced mobile security and provided mobile application risk management solutions that align with OWASP standards to […]

PTaaS for Mobile Apps: The Scalable Alternative to Traditional Penetration Testing

By Tim Neighbors / April 9, 2025 / Comments Off on PTaaS for Mobile Apps: The Scalable Alternative to Traditional Penetration Testing

Traditional penetration testing wasn’t built for today’s mobile release cycles. Annual, semi-annual or even quarterly pen tests don’t cut it anymore. If your mobile app updates weekly, that’s a dozen untested versions before your next scheduled assessment. That’s a dozen chances for a data leak or privacy flaw to slip through. Mobile Penetration Testing as […]

App Store Security Myths: Why Enterprises Can’t Solely Rely on Apple and Google for Security Reviews

By Amy Schurr / March 26, 2025 / Comments Off on App Store Security Myths: Why Enterprises Can’t Solely Rely on Apple and Google for Security Reviews

When enterprise mobility managers, end-user computing (EUC) managers and IT security teams evaluate third-party mobile app risk for business use, a common misconception arises: If an app is available in the Apple App Store or Google Play Store, it must be secure and free of privacy risks. The reality is that Apple and Google app […]

How Mobile App Location Tracking Puts Executives and Enterprises at Risk

By Amy Schurr / February 12, 2025 / Comments Off on How Mobile App Location Tracking Puts Executives and Enterprises at Risk

The Real-Time Location Tracking Threat Mobile apps quietly collect vast volumes of location data unbeknownst to users. While location tracking enhances functionality of many mobile apps, this data can be exploited and exposes individuals and enterprises to serious risk. From stalking to real-time tracking and surveillance, data misuse can lead to physical harm and even […]

Top Mobile App Security and Privacy Breaches of 2024

By Amy Schurr / January 8, 2025 / Comments Off on Top Mobile App Security and Privacy Breaches of 2024

The growing reliance on mobile apps has spawned a wave of security and privacy challenges in 2024 with major breaches making headlines and regulatory agencies pursuing compliance enforcement.  From exposed user data to prolonged service outages, these incidents highlight the critical need for strong mobile application security. Mobile security experts identify several threats you can […]