Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Register Now →
magnifying glass icon

Research & Threat Intel

Business Logic Testing: Protect Mobile Apps from Exploits and Fraud

By Jeff Kneis / October 22, 2025 / Comments Off on Business Logic Testing: Protect Mobile Apps from Exploits and Fraud

Business logic testing examines the rules and workflows that dictate who can do what, when and how within a mobile app. These tests go beyond technical vulnerabilities to uncover weaknesses in how the app enforces permissions, processes transactions and validates inputs.  When business logic vulnerabilities slip through, attackers can exploit these flaws to bypass payments, […]

Learn About Hidden Mobile Security and Privacy Risk Sources with the NowSecure Mobile Application Risk Checker (MARC)

By Jeff Kneis / October 9, 2025 / Comments Off on Learn About Hidden Mobile Security and Privacy Risk Sources with the NowSecure Mobile Application Risk Checker (MARC)

Last month, NowSecure launched NowSecure Privacy, the first automated solution for finding and fixing the systemic blind spots that degrade mobile application privacy. And today, we released NowSecure Mobile Application Risk Checker (MARC), the first and only free public risk checker for mobile applications.  The free, educational MARC tool builds mobile security awareness by helping […]

New NPM Supply Chain-Attack Hits 187 Packages — Here’s Why Mobile Apps Are Still at Risk

By Jeff Kneis / September 16, 2025 / Comments Off on New NPM Supply Chain-Attack Hits 187 Packages — Here’s Why Mobile Apps Are Still at Risk

Executive Summary Last week, we reported on a near-miss incident involving npm software supply-chain attacks impacting mobile applications. Unfortunately, a new wave of NPM supply chain compromises has been discovered affecting 187 packages including critical frameworks used in mobile app development.  The good news? Our ongoing analysis of public mobile apps from the Google Play […]

Major NPM Supply-Chain Attack: Potential Impact on Mobile Applications

By Jeff Kneis / September 8, 2025 / Comments Off on Major NPM Supply-Chain Attack: Potential Impact on Mobile Applications

Today, security researchers revealed details of a massive supply-chain attack affecting some of the most popular NPM packages in the JavaScript ecosystem. The attack, which compromised packages including chalk, debug, ansi-styles and others with a combined 2+ billion weekly downloads, represents one of the most significant supply-chain incidents in recent memory. This is a big […]

Why I Don’t Trust My Kids’ Apps – The Hidden Mobile Privacy Risks Parents Should Know

By Jeff Kneis / July 30, 2025 / Comments Off on Why I Don’t Trust My Kids’ Apps – The Hidden Mobile Privacy Risks Parents Should Know

We’re in an era where parents like me have grown up with smartphones. My parents, as much as I loved them, were what we would refer to as ‘technologically challenged’.  I often had to help them navigate the digital world, teaching them how to spot phishing emails or PayPal scams.  Now, as a parent myself, […]

Remote Code Execution Discovered in XTool AnyScan App: Risks to Phones and Vehicles

By Jeff Kneis / July 16, 2025 / Comments Off on Remote Code Execution Discovered in XTool AnyScan App: Risks to Phones and Vehicles

Introduction Update (2025): The security issues identified in the XTool AnyScan mobile application have now been assigned official CVEs: CVE-2025-63432, CVE-2025-63433, CVE-2025-63434, and CVE-2025-63435. These CVEs formalize and validate the vulnerabilities discovered by the NowSecure research team, underscoring the seriousness of the remote code execution (RCE) risks posed to mobile devices and connected vehicles. NowSecure […]

NowSecure Responds to ‘NICKNAME’ iMessage Exploit

By Andrew Hoog / June 5, 2025 / Comments Off on NowSecure Responds to ‘NICKNAME’ iMessage Exploit

iVerify recently published a detailed technical analysis uncovering a new iMessage vulnerability — dubbed “NICKNAME” — that could be used in a zero-click attack to compromise iOS devices. The exploit abuses the way iOS handles iMessage contact profile updates (nicknames) to trigger memory corruption and potentially deliver spyware without any user interaction. What We Know […]

AI Risks in Mobile Apps: How to Protect Your Data and Stay Compliant

By Amy Schurr / February 26, 2025 / Comments Off on AI Risks in Mobile Apps: How to Protect Your Data and Stay Compliant

App Store and Google Play visitors find it hard to escape Artificial Intelligence (AI). From photo enhancement apps to voice assistants to health diagnostics, AI commands an undeniable presence in mobile apps. In fact, 10 out of 12 top graphic design apps use AI — it’s everywhere. As AI permeates mobile apps, it introduces a […]

NowSecure Uncovers Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App

By Andrew Hoog / February 6, 2025 / Comments Off on NowSecure Uncovers Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App

A NowSecure mobile application security and privacy assessment has uncovered multiple security and privacy issues in the DeepSeek iOS mobile app that lead us to urge enterprises to prohibit/forbid its usage in their organizations. As the top iOS app since Jan 25, 2025, the DeepSeek iOS app has already been downloaded and used on millions […]

Decompiling Apps With AI Language Models

By Tim Neighbors / January 29, 2025 / Comments Off on Decompiling Apps With AI Language Models

At NowSecure, we continually explore innovative ways to analyze mobile apps without requiring access to their source code. As mobile app development changes quickly with new languages, frameworks and technologies, reverse engineering tools often struggle to keep pace.  Artificial intelligence (AI) language models are emerging as valuable tools for mobile security analysts and developers, offering […]