Meet us at Black Hat 2026

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
Get a closer look at mobile AI risk: Get a closer look at mobile AI risk: Meet Us at Black Hat Booth #5545
magnifying glass icon

Research & Threat Intel

Unlocking Mobile App Vulnerabilities in Hotel Room Keys

By Amy Schurr / October 23, 2019 / Comments Off on Unlocking Mobile App Vulnerabilities in Hotel Room Keys

To improve the guest experience and keep pace with competition, hotels worldwide are deploying digital key technology that allows guests to skip the front desk and use their mobile apps to remotely check in and go directly into their rooms without needing key cards. However, hotel mobile apps have vulnerabilities that can be exploited, as researchers demonstrated at the Black Hat USA 2019 conference.

R2con Conference Recap: OSS & Mobile AppSec Learning

By Amy Schurr / September 19, 2019 / Comments Off on R2con Conference Recap: OSS & Mobile AppSec Learning

In early September, radare2 users and developers from around the globe gathered in Barcelona for r2con, an annual conference celebrating the r2 multi-platform, open-source, reverse engineering framework supported by NowSecure. Around 200 attendees enjoyed four days of hacking, teaching, discussing, coding, socializing and having fun.

Debunking the Top 3 Myths About Mobile Application Security Testing

By Amy Schurr / July 24, 2019 / Comments Off on Debunking the Top 3 Myths About Mobile Application Security Testing

We frequently hear the same myths about mobile application security testing ranging from the notion that mobile apps are safe because Apple and Google test them to the notion that testing mobile apps is the same as testing web apps. These beliefs put organizations at risk of using and publishing mobile apps that are inherently insecure.

Discover what the top three misperceptions are and how to counter them.

Think Twice Before Adopting Security By Obscurity in Kotlin Android Apps

By Amy Schurr / July 11, 2019 / Comments Off on Think Twice Before Adopting Security By Obscurity in Kotlin Android Apps

Let’s examine how Android apps programmed using Kotlin could render Security By Obscurity ineffective. Kotlin is a statically-typed, general purpose language which was designed to interoperate fully with Java and the Java Virtual Machine. Android initially supported Kotlin in 2017 and it recently emerged as the preferred language Google recommends for Android app development. Kotlin Android apps offer a great example of why static analysis of binaries is better than static analysis of source code.

Black Friday & Cyber Monday Retail Apps Threaten Shoppers’ Privacy

By Amy Schurr / November 14, 2018 / Comments Off on Black Friday & Cyber Monday Retail Apps Threaten Shoppers’ Privacy

Last year, 66 million U.S. residents shopped online on Black Friday, topped only by 81 million on Cyber Monday. As an onslaught of consumers gear up to use retail and deal finding mobile apps to take advantage of post-Thanksgiving sales, companies should realized that many of those apps have security flaws that could compromise customer data.

The Nightmare Beyond Your Injured Draft Pick: 38% of Top Fantasy Sports Mobile Apps Have Security or Privacy Flaws

By Amy Schurr / September 4, 2018 / Comments Off on The Nightmare Beyond Your Injured Draft Pick: 38% of Top Fantasy Sports Mobile Apps Have Security or Privacy Flaws

The new NFL season kicks off on Sept. 7, 2018 and the NHL and NBA seasons resume a few weeks later. As their favorite players take the field, ice and court, millions of fans will wield their mobile devices to check game scores and compete in fantasy sports leagues. But just like some of the […]

NowSecure Benchmark: 25% of 88 top U.S. FedGov Public Mobile Apps Have Security or Privacy Flaws

By NowSecure Marketing / August 29, 2018 / Comments Off on NowSecure Benchmark: 25% of 88 top U.S. FedGov Public Mobile Apps Have Security or Privacy Flaws

On the eve of the ATARC Federal Mobile Technology Summit on August 30, 2018, NowSecure analyzed 88 publicly available mobile apps from across multiple U.S. federal government agencies. Overall, we found that 25% of 88 mobile apps have high and/or critical CVSS-scored vulnerabilities and over 20% do not comply with National Information Assurance Partnership (NIAP) requirements. Read the blog to see more data.

Benchmark Analysis Reveals Risky Mobile Apps in Apple® App Store® and Google Play™ store

By NowSecure Marketing / July 25, 2018 / Comments Off on Benchmark Analysis Reveals Risky Mobile Apps in Apple® App Store® and Google Play™ store

A staggering 85% of the 45,000 mobile apps reviewed for this benchmark analysis violated at least 1 or more of the OWASP MASVS. This benchmark report identifies significant risks of data leakage in mobile apps with insecure data storage, insecure network communications and insecure coding practices that all organizations must address in their risk models and app security programs.

Android Dirty COW patch and exploiting vulnerable devices without root

By NowSecure Marketing / December 8, 2017 / Comments Off on Android Dirty COW patch and exploiting vulnerable devices without root

Android Dirty COW patch released On Monday, Google announced putting the Dirty COW vulnerability (CVE-2016-5195) out to pasture with the 2016-12-05 patch level in the December 2016 Android Security Update. That’s welcome news for owners of Google Nexus and Pixel devices. Of course even with the patch from Google, the long standing problem of Android […]

iOS Instrumentation without Jailbreak

By NowSecure Marketing / November 23, 2017 / Comments Off on iOS Instrumentation without Jailbreak

With the release of Frida 6.0, it is now possible to instrument iOS apps on non-jailbroken devices.