Meet us at Black Hat 2026

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
Get a closer look at mobile AI risk: Get a closer look at mobile AI risk: Meet Us at Black Hat Booth #5545
magnifying glass icon

Research & Threat Intel

Retailers Must Manage Mobile AppSec Risk to Grow

By Amy Schurr / May 31, 2023 / Comments Off on Retailers Must Manage Mobile AppSec Risk to Grow

Security and privacy vulnerabilities can compromise popular consumer brands.

How to Exploit Android WebViews with Frida

By Tim Neighbors / May 24, 2023 / Comments Off on How to Exploit Android WebViews with Frida

Many mobile applications rely heavily on web technologies and resources for their functionality. For example, WebViews  offer a simple and convenient way to load and display web content directly within a mobile app. However, WebViews can increase the mobile attack surface while introducing significant risk depending on their configuration. Cyberattackers can exploit Android WebViews to […]

Reverse Engineering Techniques for Mobile App Pen Testing

By Tim Neighbors / April 19, 2023 / Comments Off on Reverse Engineering Techniques for Mobile App Pen Testing

Reverse engineering a mobile application means taking apart an Android or iOS binary to learn about its makeup. This insight makes it easier to manipulate an app in ways its developer didn’t originally intend. As a mobile pen tester, security analyst or researcher, knowing how to reverse engineer mobile apps improves the quality and depth […]

High-Tech Mobile Apps Expose Data

By NowSecure Marketing / March 29, 2023 / Comments Off on High-Tech Mobile Apps Expose Data

Security and privacy vulnerabilities in popular business software could spill corporate secrets.

Reverse Engineering Android Apps to Bypass Root Detection Capabilities

By Tim Neighbors / March 1, 2023 / Comments Off on Reverse Engineering Android Apps to Bypass Root Detection Capabilities

Smartphone manufacturers ship Android devices with a strict set of permissions and access control systems to protect users from security risks and prevent them from acSmartphone manufacturers ship Android devices with a strict set of permissions and access control systems to protect users and reduce risk.But for users and researchers alike, these controls can limit […]

mHealth Apps Diagnosed with Poor Security

By Amy Schurr / January 25, 2023 / Comments Off on mHealth Apps Diagnosed with Poor Security

Mobile Banking & Finance Apps Fall Short on Security

By Amy Schurr / November 30, 2022 / Comments Off on Mobile Banking & Finance Apps Fall Short on Security

Is Your Mobile App Exposed to OpenSSL Vulnerabilities?

By Andrew Hoog / November 3, 2022 / Comments Off on Is Your Mobile App Exposed to OpenSSL Vulnerabilities?

On Oct. 25, 2022, OpenSSL began pre-notifying organizations of two critical vulnerabilities in OpenSSL 3.0.x. On the positive side, OpenSSL 3.0 had not been widely deployed yet, and even better on Nov 1, 2022, the two vulnerabilities were downgraded from critical to high. However, on the heels of other recent highly impactful vulnerabilities like Log4j […]

The Results Are In: Vulnerability Management Comes of Age

By Tim Neighbors / October 26, 2022 / Comments Off on The Results Are In: Vulnerability Management Comes of Age

NowSecure recently partnered with Coalfire to contribute mobile risk data to the cybersecurity advisory company’s 4th Annual Penetration Risk Report. The report findings reveal the importance of continuous testing in vulnerability management combined with human-based testing to reduce risk. The most successful vulnerability and risk management programs are no longer focused on point-in-time schedules but […]

A Zero-Click RCE Exploit for the Peloton Bike (And Also Every Other Unpatched Android Device)

By Shannon / February 9, 2022 / Comments Off on A Zero-Click RCE Exploit for the Peloton Bike (And Also Every Other Unpatched Android Device)

TL;DR: The Peloton Bike ran an unpatched version of Android 7 which led to it being vulnerable to a number of known issues, most significantly CVE-2021-0326, which could allow an attacker within WiFi range to execute arbitrary code on the device. There is no requirement for the user to interact with any attacker controlled data, […]