Approov Blog
Secure your iOS, Android, and HarmonyOS apps and APIs. Learn mobile app security best practices, API key protection, and incident response strategies.

An Analysis of Hardware-Backed Key Attestation for Mobile Security
George McGregor | | API security, API Security - Analysis, News and Insights, App Attestation, mobile app security
Companies such as Google and Apple promote hardware-backed key attestation as a security measure for protecting mobile apps and APIs. This approach ensures that cryptographic keys are stored and used within secure ...

HIPAA Security Rule Amendment: Key Public Comments and Next Steps
George McGregor | | API Security - Analysis, News and Insights, healthcare, mobile app security, Mobile Health
Major cybersecurity breaches continue to plague the US healthcare industry, and on December 27, 2024, the U.S. Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) to ...

UK NHS API Flaw Exposes Critical Mobile Security Risks
Ted Miracco | | API security, API Security - Analysis, News and Insights, healthcare, mobile app security, Mobile Health
A recent vulnerability discovered in an UK National Health Service HS API has once again highlighted the risks associated with insecure mobile application programming interfaces (APIs). The flaw reportedly allowed unauthorized access ...

New Mobile App Scanning Tool Created by Approov and CMU Africa
George McGregor | | API security, API Security - Analysis, News and Insights, Fintech, mobile app security, Mobile Finance
Approov and Carnegie Mellon University Africa's Upanzi Network have teamed up again to help fintech companies provide more secure services to their customers by creating a new web-based open source tool which ...

Incorporating Mobile App Security into HIPAA’s Healthcare Security Rule
George McGregor | | API security, API Security - Analysis, News and Insights, healthcare, mobile app security, Mobile Health
A proposed update to the HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information was issued in June 2024. Comments were requested and Approov has proposed some changes. This ...

DeepSeek App Security Flaws Exposed: How Approov Could Have Averted the Risk
Ted Miracco | | API Abuse, API Security - Analysis, News and Insights, App Attestation, MitM Attack, Mobile API Security
With a global AI race underway, mobile app security is not optional - it’s a necessity. A recent security audit of the DeepSeek iOS application revealed significant vulnerabilities that put user data ...

Why Over-the-Air Updates are Key for Mobile App Security in the AI Era
George McGregor | | API security, API Security - Analysis, News and Insights, mobile app security, over the air updates
The rapid pace of technological advancements, particularly in artificial intelligence (AI), has transformed both the opportunities and threats in the mobile app ecosystem. This blog describes why over-the-air (OTA) updates to ...

Enhancing Mobile App API Security: Closing Gaps with a Robust SDK
George McGregor | | API security, API Security - Analysis, News and Insights, Bots, mobile app security, SDK, WAAP, waf
The large app sec vendors are only now starting to recognize the mobile gap in their portfolio - that an SDK in mobile apps is needed to eliminate the growing mobile ...

Strategies to Stop Credential Stuffing Attacks on Mobile Apps
George McGregor | | account takeover, API Security - Analysis, News and Insights, credential stuffing, Data Security, mobile app development, mobile app security, zero trust
Identity-based and social engineering attacks are surging in 2024. Stolen credentials give hackers immediate access and control… and an instant path to stealing data and orchestrating ransomware attacks. Credential stuffing attacks ...