Guardsquare

Guardsquare Guardsquare is the leader in mobile application security.

A new report from PYMNTS highlights that shoppers increasingly use mobile phones inside physical stores to make faster, ...
04/09/2026

A new report from PYMNTS highlights that shoppers increasingly use mobile phones inside physical stores to make faster, more confident choices instead of simply chasing discounts.

The numbers show 42% of shoppers now use a phone while shopping in-store (up from only 30% in January 2024). The phone has become a pocket-sized sales associate, helping people answer practical questions before they put an item in the cart. More than a quarter (26%) of consumers used their phones in-store for reading product reviews and for comparing prices–with both activities showing significant growth since 2024.

In combination with increasing “mobile-first” preference for making retail purchases, consumers depend on not just the convenience that mobile apps and wallets offer, but also an inherent sense of trust. As bad actors use new tools and techniques to target mobile transactions, developers need to ensure consumer trust is well-placed with best-of-breed mobile app security.

America’s phone-carrying shopper is becoming less of a bargain hunter and more of an in-aisle decision maker. That shift stands out in PYMNTS

Mobile telecom apps are a force multiplier for modern life, handling billing, account and device management, support cha...
02/09/2026

Mobile telecom apps are a force multiplier for modern life, handling billing, account and device management, support chats, and purchases.

But this creates a very concentrated risk profile, which attackers look to exploit. When attackers reverse engineer a telecom app, they can gain access to and abuse backend systems in ways that traditional network defenses were not designed to catch.

Mobile telecom application security works best when it is treated as architecture that is built, reinforced, validated, and monitored over time.

Read more about what comprehensive security means for mobile telecom apps:
https://hubs.la/Q04wfwWs0

Developing mobile apps using free and open source software (FOSS) components has become common practice. It is estimated...
01/09/2026

Developing mobile apps using free and open source software (FOSS) components has become common practice. It is estimated that between 70% and 90% of any given software codebase is made up of open source components.

However, including open source libraries in your mobile application greatly increases its attack surface. Weaknesses and vulnerabilities can make their way into your app and reach production without your knowledge, putting your customers, your IP, and your revenue at risk.

The solution? A dedicated mobile application security testing (MAST) tool. MAST uncovers weaknesses in the FOSS components you use, and identifies deprecated versions that might be at risk or that are no longer supported. Learn how to protect your mobile app today by reading our latest blog:

Discover why mobile application security testing (MAST) is crucial in an age when developers rely on open source software to develop their apps.

The distinction between a “banking app” and a “consumer app” is disappearing, and the next wave of breaches is taking ad...
26/08/2026

The distinction between a “banking app” and a “consumer app” is disappearing, and the next wave of breaches is taking advantage of that gap.

Embedded finance features integrate payment, credit, insurance, or investments directly into non-finance based mobile applications. These features introduce compliance needs to apps that were not designed to comply with strict financial regulations, and users trust these apps with their personal information.

For embedded finance apps to both meet compliance requirements and protect customers’ financial data, security must be multi-layered and integrated throughout the SDLC.

Read our report to learn more about how you can secure your embedded finance apps and meet compliance requirements: https://hubs.la/Q04vp20V0

OS-level mobile security is a critical baseline, but is it enough to stop advanced reverse engineering? 84% of mobile ap...
25/08/2026

OS-level mobile security is a critical baseline, but is it enough to stop advanced reverse engineering? 84% of mobile app developers say no. Industry consensus shows that relying solely on OS-level protections leaves critical vulnerabilities exposed.

Our latest blog breaks down how attackers reverse engineer mobile apps to steal credentials, proprietary logic, and manipulate authentication flows. More importantly, we cover how to stop them using a layered approach with code hardening, Runtime Application Self-Protection (RASP), and real-time threat monitoring.

Read the full breakdown here:

Discover why mobile apps are vulnerable to reverse engineering, what attackers target, and how code hardening and RASP protect against it.

Mobile security researchers recently uncovered a new family of NFC relay malware (dubbed “WindRelay”) which is being dep...
21/08/2026

Mobile security researchers recently uncovered a new family of NFC relay malware (dubbed “WindRelay”) which is being deployed with the well-known “SpyNote” trojan. This dynamic threat combo captures live card data via NFC and then transmits it to fraudsters in real time.

NFC (“near field communication”) technology has become widely trusted for both mobile contactless payments and identity verification. But several new attacks this year take advantage of this trust: while a mobile banking customer believes they are simply verifying their account, their card is actively being swiped thousands of miles away.

As mobile apps become indispensable to banking, retail, healthcare administration, and government (digital identity wallets replacing physical documents), developers must move beyond the assumption that platform security alone is sufficient. Effective mobile security requires continuous validation that the app, device, and runtime environment can be trusted before any sensitive transactions occur.

WindRelay pairs with SpyNote to relay live NFC card data from infected Android phones, enabling contactless payment fraud in real time.

Mobile streaming apps offer all types of content including live sports, TV shows, and movies anytime, anywhere.But these...
19/08/2026

Mobile streaming apps offer all types of content including live sports, TV shows, and movies anytime, anywhere.

But these apps often become targets for attacks.

Reverse engineering and tampering allows attackers to gain unauthorized access to content, sensitive financial and personal information, or execute DDoS attacks to bring the app’s services down.

With strong mobile application security, streaming apps can prevent reverse engineering and tampering, keeping their services up and running and protecting their customers’ data.

Read this customer story to see how Guardsquare helped a Latin American streaming service protect their mobile apps: https://hubs.la/Q04ts-7c0

As mobile app developers use the latest AI- and LLM-based tools to build faster, bad actors are using those same tools t...
18/08/2026

As mobile app developers use the latest AI- and LLM-based tools to build faster, bad actors are using those same tools to automate and scale their attacks. These include things like agentic credential scraping, LLM-automated phishing, and deepfake KYC fraud.

Perhaps the ultimate AI nightmare scenario for an organization is a reverse engineering attack scaled across their entire app portfolio—all because of outdated mobile protections.

Polymorphism is key to ensuring mobile applications have multi-layered protection that uniquely changes with each app build – resetting the clock on threat actors and preventing automated attacks at-scale:

Without polymorphic mobile app protections, AI-based tools can make a single reverse engineering attack scalable. Learn why polymorphism is essential.

Cryptocurrency fraud is on the rise, and mobile apps are at the forefront of it.Mobile crypto wallets control both the p...
12/08/2026

Cryptocurrency fraud is on the rise, and mobile apps are at the forefront of it.

Mobile crypto wallets control both the public blockchain address, which functions like a bank account number, and the private key, which controls the ability to move funds. If an attacker steals the private key, they gain full control over the cryptocurrency in that wallet.

Developers need to protect these keys from several different types of attacks including:
- Reverse engineering
- Memory scraping and malware
- Repackaging
- Credential harvesting
- API abuse

Effective mobile app security for crypto wallets uses multiple layers that protect apps before and after release.

Read more about securing mobile crypto wallets here: https://hubs.la/Q04sG--k0

Can you be "compliant" and still be exposed?According to Dr. Amoroso (CEO, TAG Infosphere and former SVP & Chief Securit...
11/08/2026

Can you be "compliant" and still be exposed?

According to Dr. Amoroso (CEO, TAG Infosphere and former SVP & Chief Security Officer at AT&T), the answer for most enterprises today is yes. This is because mobile app risk still isn't built into frameworks like NIST CSF 2.0 or ISO 27001.

In a guest post on Guardsquare’s blog, Ed makes the case for why mobile app security needs to be incorporated into key frameworks and what mobile app hardening looks like when it's treated as a real compliance control and not as an afterthought.

Read it here:

Discover how Guardsquare mobile app security helps compliance framework developers identify practical controls that can be incorporated into standards.

Adresse

Tervuursevest 362 Bus 1
Leuven
3000

Notifications

Soyez le premier à savoir et laissez-nous vous envoyer un courriel lorsque Guardsquare publie des nouvelles et des promotions. Votre adresse e-mail ne sera pas utilisée à d'autres fins, et vous pouvez vous désabonner à tout moment.

Contacter L'entreprise

Envoyer un message à Guardsquare:

Raccourcis

Partager