Your first mobile app security scan will almost certainly produce dozens of findings. Some will be Critical. Some will be Informational. Most will fall somewhere in between. The question that follows immediately is: which ones do we fix first? Severity ratings are a starting point, but they are not the full picture. A Critical finding...
Play Store Auto-Scanning: Why Security Testing Should Start the Moment You Publish
Here is the timeline that most organisations follow when they publish a mobile app update: the development team completes the build, QA runs their functional tests, the product manager approves the release, and the APK is submitted to the Google Play Store. Within hours, the new version is live and accessible to every user who...
SAMA CSF and Mobile Banking: What Saudi Financial Institutions Must Test
If your organisation holds a licence from the Saudi Arabia Monetary Authority, you are subject to the SAMA Cybersecurity Framework (CSF). And if your organisation publishes a mobile banking or payment application which, in 2026, means virtually every SAMA-licensed institution that application is within scope for quarterly compliance reporting. This post breaks down the specific...
7 Mobile App Vulnerabilities That Would Fail a NESA Audit
NESA auditors are no longer satisfied with a generic vulnerability scan and a checklist. When they assess your mobile applications, they are looking for specific evidence of security controls mapped to recognised standards and they know what the most common failures look like. This post describes seven vulnerability classes that we see consistently in mobile...
What Happens When You Scan a Mobile App for the First Time: A Walkthrough
Most people who have never used a mobile application security testing tool imagine something complicated. A command-line interface. Weeks of configuration. A team of security experts interpreting raw output. The reality is significantly simpler and significantly faster. This post walks you through exactly what happens when you scan a mobile application with HEXMobileSuite, from the...
The Hidden Cost of Ignoring Mobile App Security in the UAE
There is a number that most CISOs in the UAE know by heart: AED 5.9 billion. That is the estimated annual cost of cyberattacks to UAE organisations. What most CISOs do not know is how much of that cost is attributable to mobile applications because the honest answer is that nobody is tracking it yet....
Third-Party SDKs: The Supply Chain Risk Hiding Inside Your Mobile App
Third-Party SDKs: The Supply Chain Risk Hiding Inside Your Mobile App When the OWASP Foundation published the updated Mobile Top 10 for 2024, the most significant change was the elevation of supply chain risk to the number two position. Not authentication. Not data storage. Supply chain specifically, the security of third-party SDKs and libraries embedded...
SAMA vs NESA: A Dual-Compliance Playbook for GCC Financial Institutions
Key takeaways GCC banks now answer to SAMA, NCA, TDRA, SIA, CBUAE and the UAE Cybersecurity Council — six authorities, overlapping but incompatible control catalogues. Mobile is where the gaps surface fastest. SAMA Cyber Security Framework v1.0 (May 2017) is the working standard for Saudi banks, insurance companies and finance companies, with a 6-level maturity model. The...
Mobile App Security in CI/CD: A Practical Integration Guide for Android and iOS Teams
Key takeaways Mobile shift-left is structurally different from web shift-left: ephemeral builds, signing identities, store review cycles, two codebases (Android + iOS), three test layers (static + dynamic + device). Four pipeline patterns work in 2026: GitHub Actions, GitLab CI, Bitbucket Pipelines + Fastlane, Azure DevOps. This article covers integration patterns for each. Don’t hard-block on day one. The...
India Fintech’s Mobile Security Problem: What RBI, CERT-In, and DPDP Actually Require
Key takeaways Indian fintech mobile teams sit under a three-layer regulatory stack: prudential (RBI Master Direction on IT Governance, effective 1 April 2024), technical (CERT-In Directions, April 2022, 6-hour reporting), and privacy (DPDP Rules 2025, substantive provisions live 13 May 2027). The RBI Master Direction (RBI/2023-24/107) requires VAPT every 6 months on critical systems and annually on...





