Meet us at Black Hat 2026

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
Get a closer look at mobile AI risk: Get a closer look at mobile AI risk: Meet Us at Black Hat Booth #5545
magnifying glass icon

Research & Threat Intel

New NPM Supply Chain-Attack Hits 187 Packages — Here’s Why Mobile Apps Are Still at Risk

By Jeff Kneis / September 16, 2025 / Comments Off on New NPM Supply Chain-Attack Hits 187 Packages — Here’s Why Mobile Apps Are Still at Risk

Executive Summary Last week, we reported on a near-miss incident involving npm software supply-chain attacks impacting mobile applications. Unfortunately, a new wave of NPM supply chain compromises has been discovered affecting 187 packages including critical frameworks used in mobile app development.  The good news? Our ongoing analysis of public mobile apps from the Google Play […]

Major NPM Supply-Chain Attack: Potential Impact on Mobile Applications

By Jeff Kneis / September 8, 2025 / Comments Off on Major NPM Supply-Chain Attack: Potential Impact on Mobile Applications

Today, security researchers revealed details of a massive supply-chain attack affecting some of the most popular NPM packages in the JavaScript ecosystem. The attack, which compromised packages including chalk, debug, ansi-styles and others with a combined 2+ billion weekly downloads, represents one of the most significant supply-chain incidents in recent memory. This is a big […]

Why I Don’t Trust My Kids’ Apps – The Hidden Mobile Privacy Risks Parents Should Know

By Jeff Kneis / July 30, 2025 / Comments Off on Why I Don’t Trust My Kids’ Apps – The Hidden Mobile Privacy Risks Parents Should Know

We’re in an era where parents like me have grown up with smartphones. My parents, as much as I loved them, were what we would refer to as ‘technologically challenged’.  I often had to help them navigate the digital world, teaching them how to spot phishing emails or PayPal scams.  Now, as a parent myself, […]

Remote Code Execution Discovered in XTool AnyScan App: Risks to Phones and Vehicles

By Jeff Kneis / July 16, 2025 / Comments Off on Remote Code Execution Discovered in XTool AnyScan App: Risks to Phones and Vehicles

Introduction Update (2025): The security issues identified in the XTool AnyScan mobile application have now been assigned official CVEs: CVE-2025-63432, CVE-2025-63433, CVE-2025-63434, and CVE-2025-63435. These CVEs formalize and validate the vulnerabilities discovered by the NowSecure research team, underscoring the seriousness of the remote code execution (RCE) risks posed to mobile devices and connected vehicles. NowSecure […]

NowSecure Responds to ‘NICKNAME’ iMessage Exploit

By Andrew Hoog / June 5, 2025 / Comments Off on NowSecure Responds to ‘NICKNAME’ iMessage Exploit

iVerify recently published a detailed technical analysis uncovering a new iMessage vulnerability — dubbed “NICKNAME” — that could be used in a zero-click attack to compromise iOS devices. The exploit abuses the way iOS handles iMessage contact profile updates (nicknames) to trigger memory corruption and potentially deliver spyware without any user interaction. What We Know […]

AI Risks in Mobile Apps: How to Protect Your Data and Stay Compliant

By Amy Schurr / February 26, 2025 / Comments Off on AI Risks in Mobile Apps: How to Protect Your Data and Stay Compliant

App Store and Google Play visitors find it hard to escape Artificial Intelligence (AI). From photo enhancement apps to voice assistants to health diagnostics, AI commands an undeniable presence in mobile apps. In fact, 10 out of 12 top graphic design apps use AI — it’s everywhere. As AI permeates mobile apps, it introduces a […]

NowSecure Uncovers Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App

By Andrew Hoog / February 6, 2025 / Comments Off on NowSecure Uncovers Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App

A NowSecure mobile application security and privacy assessment has uncovered multiple security and privacy issues in the DeepSeek iOS mobile app that lead us to urge enterprises to prohibit/forbid its usage in their organizations. As the top iOS app since Jan 25, 2025, the DeepSeek iOS app has already been downloaded and used on millions […]

Decompiling Apps With AI Language Models

By Tim Neighbors / January 29, 2025 / Comments Off on Decompiling Apps With AI Language Models

At NowSecure, we continually explore innovative ways to analyze mobile apps without requiring access to their source code. As mobile app development changes quickly with new languages, frameworks and technologies, reverse engineering tools often struggle to keep pace.  Artificial intelligence (AI) language models are emerging as valuable tools for mobile security analysts and developers, offering […]

The Looming Threat: How Mobile Security Risks Jeopardize Reputation and Trust

By Amy Schurr / December 4, 2024 / Comments Off on The Looming Threat: How Mobile Security Risks Jeopardize Reputation and Trust

Mobile apps may run the business, but they also face threats that can destroy it. Mobile application security and privacy breaches can disrupt operations, cause  theft and fraud, endanger the personal safety of employees and result in regulatory non-compliance. The good news is CISOs can neutralize many of these threats by implementing a strong mobile […]

Top Mobile App Vulnerabilities: How to Protect Your Business from Hidden Security Risks

By Amy Schurr / November 20, 2024 / Comments Off on Top Mobile App Vulnerabilities: How to Protect Your Business from Hidden Security Risks

What risks lurk in your mobile app ecosystem? Mobile apps play a vital role in customer engagement and business operations, but they also bring unique security and privacy risks. Unlike traditional desktop applications, mobile apps run on diverse devices and operating systems, increasing their exposure to vulnerabilities.  Mobile app risks can range from insecure data […]