Research & Threat Intel
What the Transsion Telemetry Research Means for Mobile Security Transsion is the world’s fourth-largest smartphone manufacturer. Its brands — TECNO, Infinix, and itel — dominate markets across Africa, South Asia, Southeast Asia, and Latin America. Every one of these devices ships with a first-party Android telemetry framework: Athena for event collection and oneID for cross-app […]
Most vulnerability management programs are built on a simple assumption: vulnerabilities are discovered, assigned a CVE, analyzed, prioritized and remediated. A new federal audit suggests that model is under increasing strain. The National Vulnerability Database (NVD) backlog isn’t just a government process issue; it’s evidence that vulnerability volume, software supply-chain complexity and shrinking exploitation timelines […]
Key Finding: 1 in 4 AI-generated code samples contain at least one confirmed OWASP vulnerability — and mobile apps face elevated risk due to their distributed, client-side execution model, direct exposure to untrusted devices and attack surfaces traditional AppSec tools are not designed to evaluate. Developers are increasingly turning to AI coding assistants to speed […]
When regulators issue billion-dollar fines, enterprises can no longer ignore the mobile app privacy blind spot. Organizations face significant compliance exposure because mobile apps that power the business often rely on hidden third-party SDKs and data flows that security teams aren’t monitoring. Most organizations have invested heavily in securing web applications and cloud infrastructure. Mobile […]
Part 2 of the series following “AI Vibe Coding for Mobile Apps: Easy or Secure?” From “Easy” to “Secure”: What Happens After the First Build In Part 1, we explored how quickly AI can generate a functional mobile app. With great ideas and the right prompts, you can go from vision to working application in […]
Today Vercel confirmed a security incident but the real risk may not be where most teams are looking. Attackers reportedly pivoted through a compromised OAuth grant at Context AI, took over a Vercel employee’s Google account, and accessed customer API keys, source code and database contents. Vercel has advised customers to rotate anything marked “non-sensitive.” […]
A Q&A with NowSecure Cofounder Andrew Hoog TL;DR: What this shift means for your AppSec program AI is compressing the time between vulnerability discovery and exploitation thanks to frontier models. Anthropic’s Claude Mythos, designed to reason about code, identify vulnerabilities and simulate attack paths, recently demonstrated it could autonomously discover and exploit vulnerabilities and execute […]
AI-generated (“vibe coded”) mobile apps can be built in hours but often lack basic security controls like encryption, secure storage and compliance requirements. This blog series outlines the process I went through building my own app capturing key observations and lessons useful for those of us using AI for personal and business use. I am […]
The March 2026 axios npm supply-chain attack compromised developer machines, exposed CI/CD pipeline secrets and — in apps using OTA update mechanisms like CodePush — gave attackers a path to production without touching App Store review. A software supply-chain attack targets the dependencies, build systems and distribution pipelines used to create applications — rather than […]
Executive Summary Recent reporting on the White House mobile app has overstated several security and privacy concerns by focusing on what the app could do rather than what it actually does in practice. NowSecure analyzed the app using static and dynamic mobile application security testing. We found no evidence of unauthorized location tracking described in […]