Key takeaways Modern mobile banking compromises are chained, not single-exploit events: lure → dropper → accessibility-service abuse → overlay attack → credential theft → device takeover → fraudulent transaction. The Android banking trojan ecosystem in 2024–2026 is dominated by Anatsa, Crocodilus, TrickMo, Hook, Octo, Godfather and their forks. ThreatFabric documented Crocodilus expanding from Spain/Turkey to 8 countries including India, Brazil,...
Why Most Mobile Pentests Miss 60% of Real Vulnerabilities (And How Continuous Testing Closes the Gap)
Key takeaways The average mobile app receives a release roughly every 2–5 weeks. Annual or semi-annual pentests sample at best 4–8% of the actual production attack surface across a year. Modern mobile threats — SDK supply-chain compromises, post-release Play Store substitutions, runtime API changes — emerge between pentest engagements, not during them. The 60% figure...
OWASP MASVS 2.1 vs OWASP Mobile Top 10 2024: What Changed and Why It Matters
Key takeaways MASVS v2.1.0 was released on 18 January 2024, adding the new MASVS-PRIVACY control group (4 controls) and CycloneDX SBOM support. OWASP Mobile Top 10 2024 is the first major revision since 2016. Four categories are brand-new; the priority order has shifted dramatically. Improper Credential Usage (M1) is now the top risk; Inadequate Supply Chain Security (M2) is the second. Verification...
The MSSP Playbook: How Managed Security Providers Build a Profitable Mobile App Security Practice
Key takeaways The global Managed Security Services market hits USD 43.03 billion in 2026 and grows at 12.33% CAGR to USD 76.96 billion by 2031, with Asia-Pacific the fastest-growing region at 12.95% CAGR. Mobile application security testing (MAST) is the next high-margin recurring service line for MSSPs serving GCC and India clients driven by NESA, SAMA, RBI and DPDP...
NESA Mobile App Security Compliance: The 2026 Evidence Guide for UAE Organisations
Key takeaways NESA still exists as the framework, but the authority has been renamed the UAE Signals Intelligence Agency (SIA), with day-to-day oversight by TDRA. The standard you are audited against is the UAE Information Assurance Regulation v1.1 and its underlying Information Assurance Standards (188 controls across 4 priority tiers). Mobile applications are now treated as part of the...
₹250 Crore Risk: A Complete DPDP Act Compliance Checklist for Mobile Apps in India
Key takeaways The DPDP Rules 2025 were notified on 13 November 2025 by MeitY. The Data Protection Board of India is now constituted. The substantive obligations come into force on 13 May 2027 — every Indian mobile app and every foreign app serving Indian users has 18 months to comply. The maximum penalty is ₹250 crore per violation for failure to...








