Industry News
The Singapore Cyber Security Agency (CSA) paved the way in establishing national mobile app safety guidelines with the January 2024 introduction of the Safe App Standard. Designed in consultation with industry experts, the Safe App Standard sets a baseline of recommended security controls to ensure developers follow best practices for secure application development. The standard […]
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) and Office of Management and Budget (OMB) released a secure software development attestation form on March 11, 2024, in a long awaited followup to Executive Order (EO) 14028. EO 14028, “Improving the Nation’s Cybersecurity,” outlines the federal cybersecurity strategy to reduce software supply-chain risks. The OMB M-22-18 […]
Mobile penetration testing helps businesses defend against cyberattacks, safeguard data privacy and preserve brand reputation. Best practices call for continuous automated mobile application security testing throughout the software developement lifecycle to gain speed and efficiency. However, organizations should augment automation with manual mobile penetration testing for certain high-risk mobile apps to achieve the greatest coverage. […]
Organizations can expect mobile application security and mobile app privacy risks to intensify across Europe when the Digital Markets Act regulation takes effect in March. Users within Europe will be able to download mobile apps from outside the trusted mobile ecosystems of the Apple App Store and Google Play Store. While new third-party app stores […]
The Federal Trade Commission (FTC) has been aggressively cracking down on mobile app privacy violations to safeguard consumers’ personal information. Following the landmark California Consumer Privacy Act (CCPA), several states including Florida, Montana, Oregon, Texas and Washington enacted data privacy laws that take effect in 2024 and many others have pending privacy legislation. With privacy […]
While the world runs on mobile apps, the importance of a robust mobile app security testing (MAST) stack cannot be overstated. As attackers have turned their eye to mobile apps such as Chick-fil-A, RingGo, Shein and UnitedHealthcare, dev and security teams must deploy a modern, multi-layered approach to safeguard their mobile applications. Modern Mobile App […]
In today’s digital landscape, safeguarding mobile apps has become paramount. Mobile app breaches pose significant threats to data security and privacy. In addition, they erode user trust in apps and their respective developers, which in turn impacts the installed base and revenue. Mobile application security testing can help organizations identify insecure coding practices, configuration errors […]
There is a misconception that data security for mobile apps is a feature when, in reality, it has become a necessity. In IDC’s 2023 DevSecOps Adoption, Techniques, and Tools Survey, 24% of respondents indicated they experienced a sensitive data exposure breach in 2023. If developers don’t properly secure mobile applications, personally identifiable information (PII), health […]
One NowSecure Connect mobile app security testing and mobile DevSecOps virtual conference tradition is our Hack to the Future panel, where we discuss the issues and challenges at the top of hackers’ minds. Our third annual panel reunited experts Jasmine Jackson, founder of the Accelerated Training Program (T-ATP); Tennisha Martin, executive director of BlackGirlsHack; and […]
Developers of iOS apps and SDKs should mark their calendars for upcoming changes to Apple privacy requirements and block out time to familiarize yourselves with them to avoid App Store rejections. Apple announced at the Worldwide Developers Conference (WWDC) 2023 in June new initiatives to increase transparency about mobile app privacy. All mobile app developers […]