Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Live Webinar: Go inside the biggest OWASP MAS update yet with the person who led it. Register Now →
magnifying glass icon

Research & Threat Intel

Key Security Considerations for AI Coding Assistants in Mobile DevSecOps

By Amy Schurr / August 23, 2023 / Comments Off on Key Security Considerations for AI Coding Assistants in Mobile DevSecOps

The rise of generative Artificial Intelligence (AI)-based tools has the potential to revolutionize software development. Many organizations have already embraced AI-powered coding assistants such as GitHub Copilot and ChatGPT to improve the developer experience and speed time to market. A recent McKinsey study found devs can complete coding tasks up to twice as fast with […]

Post-Quantum Cryptography (PQC) & Mobile App Security

By Tim Neighbors / June 12, 2023 / Comments Off on Post-Quantum Cryptography (PQC) & Mobile App Security

“Photo by FLO:D on Unpslash https://unsplash.com/photos/yQYQJaiypZE“ Technology advancements are constantly reshaping the way we communicate and conduct business. As the CTO of NowSecure, a mobile application security testing SaaS provider, I want to discuss a topic I believe is of timely relevance: post-quantum security and in particular within the mobile application context. The cryptographic landscape is […]

Retailers Must Manage Mobile AppSec Risk to Grow

By Amy Schurr / May 31, 2023 / Comments Off on Retailers Must Manage Mobile AppSec Risk to Grow

Security and privacy vulnerabilities can compromise popular consumer brands.

How to Exploit Android WebViews with Frida

By Tim Neighbors / May 24, 2023 / Comments Off on How to Exploit Android WebViews with Frida

Many mobile applications rely heavily on web technologies and resources for their functionality. For example, WebViews  offer a simple and convenient way to load and display web content directly within a mobile app. However, WebViews can increase the mobile attack surface while introducing significant risk depending on their configuration. Cyberattackers can exploit Android WebViews to […]

Reverse Engineering Techniques for Mobile App Pen Testing

By Tim Neighbors / April 19, 2023 / Comments Off on Reverse Engineering Techniques for Mobile App Pen Testing

Reverse engineering a mobile application means taking apart an Android or iOS binary to learn about its makeup. This insight makes it easier to manipulate an app in ways its developer didn’t originally intend. As a mobile pen tester, security analyst or researcher, knowing how to reverse engineer mobile apps improves the quality and depth […]

High-Tech Mobile Apps Expose Data

By NowSecure Marketing / March 29, 2023 / Comments Off on High-Tech Mobile Apps Expose Data

Security and privacy vulnerabilities in popular business software could spill corporate secrets.

Reverse Engineering Android Apps to Bypass Root Detection Capabilities

By Tim Neighbors / March 1, 2023 / Comments Off on Reverse Engineering Android Apps to Bypass Root Detection Capabilities

Smartphone manufacturers ship Android devices with a strict set of permissions and access control systems to protect users from security risks and prevent them from acSmartphone manufacturers ship Android devices with a strict set of permissions and access control systems to protect users and reduce risk.But for users and researchers alike, these controls can limit […]

mHealth Apps Diagnosed with Poor Security

By Amy Schurr / January 25, 2023 / Comments Off on mHealth Apps Diagnosed with Poor Security

Mobile Banking & Finance Apps Fall Short on Security

By Amy Schurr / November 30, 2022 / Comments Off on Mobile Banking & Finance Apps Fall Short on Security

Is Your Mobile App Exposed to OpenSSL Vulnerabilities?

By Andrew Hoog / November 3, 2022 / Comments Off on Is Your Mobile App Exposed to OpenSSL Vulnerabilities?

On Oct. 25, 2022, OpenSSL began pre-notifying organizations of two critical vulnerabilities in OpenSSL 3.0.x. On the positive side, OpenSSL 3.0 had not been widely deployed yet, and even better on Nov 1, 2022, the two vulnerabilities were downgraded from critical to high. However, on the heels of other recent highly impactful vulnerabilities like Log4j […]