Research & Threat Intel
How enterprise mobility teams can detect hidden AI features and reduce mobile app risk. Enterprise mobility and security teams face a growing challenge: AI capabilities quietly appear inside the mobile apps employees use every day, creating mobile shadow AI risk. TL;DR Enterprise mobility teams approve hundreds — sometimes thousands — of third‑party mobile apps for […]
The PhantomRaven campaign shows how attackers can hide malware outside the npm registry using RDD, allowing malicious code to execute during installation while bypassing many traditional security scanners. This blog addresses why it is a particularly critical risk for mobile applications and how using AI during the development process increases this risk. TL;DR — PhantomRaven […]
It doesn’t take a particle physicist to figure out that authenticated mobile app security testing will give you better results. But I never really had data to back it up. Recently, NowSecure CTO David Weinstein analyzed about 105,000 mobile app assessments — roughly 5,000 authenticated and 100,000 unauthenticated, across both Android and iOS — and […]
Mobile apps often surface security risks earlier than other enterprise systems. Because mobile app code ships publicly through app stores, attackers can download, reverse engineer and analyze it, gaining a head start in finding data leaks and security vulnerabilities. For mobile AppSec and DevSecOps leaders, this reality makes mobile app security a critical focus for […]
AI Security in Mobile Apps: The Hidden Threat Multiplying Faster Than You Think Mobile applications have become the primary gateway to enterprise data, customer information and business operations. But there’s a rapidly evolving threat that most organizations are completely blind to: artificial intelligence (AI) embedded throughout their mobile app ecosystem. Recent analysis reveals a startling […]
Have you ever wondered how mobile apps always seem to recognize you, even when you’ve never created an account or provided your email? That experience isn’t magic; it’s often the result of mobile app fingerprinting and other invisible tracking techniques. For mobile app developers, AppSec leaders and enterprise mobility managers, this capability poses more than […]
Mobile apps collect more data than most users expect. Developers race to personalize experiences, train AI models and optimize revenue. That pressure pushes many apps to grab as much behavioral data as possible. During a recent NowSecure investigation, we analyzed the AI-powered Phia iOS shopping app and discovered how quickly helpful features can turn into […]
The rapid integration of artificial intelligence (AI) and generative AI (GenAI) into mobile applications has transformed how users interact with their devices. From personal assistants to image recognition, AI and large language model (LLM) capabilities now sit in the palms of our hands. However, this convenience comes with serious security, privacy and safety implications that […]
Business logic testing examines the rules and workflows that dictate who can do what, when and how within a mobile app. These tests go beyond technical vulnerabilities to uncover weaknesses in how the app enforces permissions, processes transactions and validates inputs. When business logic vulnerabilities slip through, attackers can exploit these flaws to bypass payments, […]
Last month, NowSecure launched NowSecure Privacy, the first automated solution for finding and fixing the systemic blind spots that degrade mobile application privacy. And today, we released NowSecure Mobile Application Risk Checker (MARC), the first and only free public risk checker for mobile applications. The free, educational MARC tool builds mobile security awareness by helping […]