What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out
The new Mobile Security Exposure Center creates SBOMs for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks. The post What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out appeared first on SecurityWeek.
Mobile devices present a serious security problem: they operate outside the security perimeter and beyond the visibility of the security team. While security may know what applications live on those devices, they rarely understand the components and dependencies that comprise those applications; nor what vulnerabilities are buried within those components.
Jim Dolce, CEO at Lookout, gave an example: WolfSSL. It’s a small, fast, and portable SSL/TLS library written in ANSI C, designed mainly for devices with limited memory – and it exists on more than a billion devices. “If you have a banking app on a mobile device for online banking, that app is likely using WolfSSL. It has a very serious vulnerability. If exploited by a bad actor, it can mimic your bank, and when you put in your credentials, it will steal your banking credentials.”
The Mythos Glasswing project found and publicized this WolfSSL vulnerability. So, the bad guys know the banking app may be vulnerable, but does the security team know that employees are using it?
Source: https://www.securityweek.com/whats-hiding-in-your-mobile-apps-lookout-msec-aims-to-find-out/
Related breach coverage
- Vibe-Coded Apps Riddled With Exploitable Security Flaws2026-07-22
Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek.
- AI Data Centers Are Being Built Faster Than They Can Be Secured2026-07-16
AI infrastructure introduces new security risks that traditional data center designs were never built to handle. The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek.
- US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security2026-07-29
The agency said imports of advanced robots pose cybersecurity and other national security risks. The post US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security appeared first on SecurityWeek.
- Act Security Emerges from Stealth to Fight the Patch Problem2026-07-28
Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first on SecurityWeek.
