Meet us at Black Hat 2026

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
New: AI-native capabilities built for the speed and risk of AI-driven app development. New: AI-native capabilities built for the speed and risk of AI-driven app development. Learn More.
magnifying glass icon

Mobile Security Solutions

iOS 27 Security: What WWDC 2026’s AI Features Mean for Mobile App Risk

By Jeff Kneis / June 11, 2026 / Comments Off on iOS 27 Security: What WWDC 2026’s AI Features Mean for Mobile App Risk

Apple’s most AI-intensive developer conference ever just redefined the attack surface for every iOS app — and the security implications are immediate. What happened at WWDC 2026? Apple announced a sweeping transformation of its developer platform at the Worldwide Developers Conference (WWDC) 2026 technology showcase. On-device large language models, agentic workflows that take real-world actions, […]

What OWASP Vulnerabilities in AI-Generated Code Mean for Mobile App Security

By Jeff Kneis / May 19, 2026 / Comments Off on What OWASP Vulnerabilities in AI-Generated Code Mean for Mobile App Security

Key Finding: 1 in 4 AI-generated code samples contain at least one confirmed OWASP vulnerability — and mobile apps face elevated risk due to their distributed, client-side execution model, direct exposure to untrusted devices and attack surfaces traditional AppSec tools are not designed to evaluate. Developers are increasingly turning to AI coding assistants to speed […]

Mobile App Privacy Risks Explained: SDKs, Data Collection & Hidden Exposure

By Jeff Kneis / May 13, 2026 / Comments Off on Mobile App Privacy Risks Explained: SDKs, Data Collection & Hidden Exposure

When regulators issue billion-dollar fines, enterprises can no longer ignore the mobile app privacy blind spot. Organizations face significant compliance exposure because mobile apps that power the business often rely on hidden third-party SDKs and data flows that security teams aren’t monitoring. Most organizations have invested heavily in securing web applications and cloud infrastructure. Mobile […]

Governing AI-Generated Mobile Apps: A CISO Blueprint for Security at Scale

By Jeff Kneis / May 6, 2026 / Comments Off on Governing AI-Generated Mobile Apps: A CISO Blueprint for Security at Scale

Why Line of Business and the CISO can finally be on the same team. AI is rapidly transforming how mobile applications are built. One emerging approach, often referred to as vibe coding — AI-assisted generation of mobile applications using natural language prompts — is enabling teams to create apps faster than ever before. But speed […]

The Third-Party Mobile App Risk Hidden Inside Your Approved Apps

By Amy Schurr / April 28, 2026 / Comments Off on The Third-Party Mobile App Risk Hidden Inside Your Approved Apps

When Frederick County, Maryland, reviewed a mobile app used by its fire and rescue team, it passed every traditional check. The app connected to an ultrasound device, looked legitimate and had been approved. Binary-level analysis told a different story: the app was exposing protected health information, violating HIPAA in ways that no privacy label, MDM […]

Vibe Coding Risk: Securing AI-Generated Mobile Apps

By Jeff Kneis / April 23, 2026 / Comments Off on Vibe Coding Risk: Securing AI-Generated Mobile Apps

Part 2 of the series following “AI Vibe Coding for Mobile Apps: Easy or Secure?” From “Easy” to “Secure”: What Happens After the First Build In Part 1, we explored how quickly AI can generate a functional mobile app.  With great ideas and the right prompts, you can go from vision to working application in […]

Emulator vs Real Device Testing in Mobile App Security: Closing Critical Coverage Gaps

By Jeff Kneis / April 15, 2026 / Comments Off on Emulator vs Real Device Testing in Mobile App Security: Closing Critical Coverage Gaps

The Mobile Security Illusion: Why Emulators Don’t Reflect Real-World Risk Mobile app security testing is no longer just about scanning code or satisfying compliance checklists; it is about identifying vulnerabilities that attackers can exploit once the app is running on a real user’s device. Yet many security programs still evaluate mobile applications in environments that […]

Mobile Shadow AI Risk: AI Governance for Third-Party Mobile Apps

By Amy Schurr / March 25, 2026 / Comments Off on Mobile Shadow AI Risk: AI Governance for Third-Party Mobile Apps

How enterprise mobility teams can detect hidden AI features and reduce mobile app risk. Enterprise mobility and security teams face a growing challenge: AI capabilities quietly appear inside the mobile apps employees use every day, creating mobile shadow AI risk. TL;DR Enterprise mobility teams approve hundreds — sometimes thousands — of third‑party mobile apps for […]

Agentic AI Security Tools Are Only as Smart as Their Data — and They Are Missing Mobile Signals

By Amy Schurr / March 18, 2026 / Comments Off on Agentic AI Security Tools Are Only as Smart as Their Data — and They Are Missing Mobile Signals

AI security platforms rely on telemetry to detect threats and correlate risk, but still lack visibility into mobile application behavior — one of the fastest-growing sources of security signals. In brief: TL;DR AI security platforms analyze networks, endpoints and cloud activity. Yet many cannot see mobile app behavior that bypasses these solutions.  That limitation matters […]

Closing the Mobile Security Gap: What Mobile App Risk Intelligence Means for Mobile EDR

By Amy Schurr / March 10, 2026 / Comments Off on Closing the Mobile Security Gap: What Mobile App Risk Intelligence Means for Mobile EDR

What is Mobile App Risk Intelligence? Mobile App Risk Intelligence analyzes mobile applications to identify security, privacy and behavioral risks that could expose enterprise data. It evaluates issues such as insecure data storage, dangerous permissions, third-party SDK vulnerabilities and risky network communications. For enterprise security teams, this matters because mobile apps can: As mobile devices […]