What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out
Lookout MSEC creates SBOMs for enterprise mobile apps to find vulnerable components and risks.
Summary
Lookout has launched the Mobile Security Exposure Center (MSEC) to address the security blind spot of mobile devices operating outside traditional security perimeters. MSEC generates Software Bills of Materials (SBOMs) for enterprise mobile applications, identifying all components and dependencies. It then correlates these components with vulnerability databases like CISA's KEV list to uncover known risks, enabling proactive remediation.
Full text
Mobile devices present a serious security problem: they operate outside the security perimeter and beyond the visibility of the security team. While security may know what applications live on those devices, they rarely understand the components and dependencies that comprise those applications; nor what vulnerabilities are buried within those components. Jim Dolce, CEO at Lookout, gave an example: WolfSSL. It’s a small, fast, and portable SSL/TLS library written in ANSI C, designed mainly for devices with limited memory – and it exists on more than a billion devices. “If you have a banking app on a mobile device for online banking, that app is likely using WolfSSL. It has a very serious vulnerability. If exploited by a bad actor, it can mimic your bank, and when you put in your credentials, it will steal your banking credentials.” The Mythos Glasswing project found and publicized this WolfSSL vulnerability. So, the bad guys know the banking app may be vulnerable, but does the security team know that employees are using it? “Knowing an application’s name and version reveals only a fraction of its risk profile,” explains Lookout. “Security teams need visibility into the software components, dependencies, and vulnerabilities embedded beneath the surface.” This is what the firm’s new Mobile Security Exposure Center (MSEC) provides: full visibility into (rather simply ‘about’) an organization’s potentially vast mobile fleet. In a nutshell, MSEC examines every device in the fleet, so it knows what apps are present. It then creates its own proprietary software bill of materials (SBOM) from the binary for the different apps. From this SBOM it learns every component within the app and correlates those components with the vulnerability databases (such as the KEV list) that exist. The results are fed into the organization’s CTEM to assist the security team to take any necessary remediation steps.Advertisement. Scroll to continue reading. “The system will identify which apps use WolfSSL, the version of that app, the user and the device that is using that app, and all of that information then can be used to remediate the exposure. So MSEC basically identifies the exposure and provides that information,” continued Dolce. This applies to all the software components of all the apps on all the mobile devices. MSEC also complements Lookout’s existing AI Visibility & Governance product. “While AI Visibility & Governance helps organizations understand AI adoption and usage across the enterprise,” says Lookout, “MSEC reveals the software composition and exposure profile of those applications. Together, they provide a more complete view of application risk, security, and governance.” The result, it continues, is “A shift from reactive application management to proactive exposure management.” However, there is a slight issue here. MSEC correlates the app components it unearths in its SBOM creation with the vulnerability databases that exist. We’ve mentioned one – the KEV list, or the Known Exploited Vulnerabilities Catalog produced by CISA. The clue to the issue is in the name, known vulnerabilities. No vulnerability database can include unknown vulnerabilities. So, while MSEC can help remediate known vulnerabilities, there is always the possibility that a new frontier AI model will unearth new vulnerabilities. Lookout is obviously aware of this, and has it covered. “Bad actors can use frontier AI models, Mythos as an example, in order to find vulnerabilities and exploit them,” agreed Dolce. “That’s the offensive use of a frontier AI model. Well, Lookout can use that same model defensively. We can go beyond KEV and the other vulnerability databases by using the frontier models ourselves to find unknown vulnerabilities across the SBOM. That will be the next iteration of MSEC.” He continued, “We will take our SBOM and use the frontier AI models defensively to go and find unknown vulnerabilities for ourselves, and catalog those as well.” But it all starts with knowing the app inventory across the enterprise mobile fleet, creating the accurate SBOM for all the apps in the fleet, and then correlating the app components against known vulnerability databases, and then, he added, “The last step is find unknown vulnerabilities using the same frontier AI models defensively that the bad guys are using offensively.” Related: Mobile Attack Surface Expands as Enterprises Lose Control Related: FBI Warns of Data Security Risks From China-Made Mobile Apps Related: Mobile Security: Verizon Says Attacks Soar, AI-Powered Threats Raise Alarm Related: Chinese Hackers Turn Smartphones Into a ‘Mobile Security Crisis’ Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI InsiderVibe-Coded Apps Riddled With Exploitable Security FlawsCisco Launches Low-Cost AI Models for Source Code SecurityCISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AGAI Data Centers Are Being Built Faster Than They Can Be SecuredWindows Bind Link Attacks Can Hide Malware From EDR ToolsHacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to RedemptionUK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge Latest News Coca-Cola Confirms Data Breach After Fairlife Ransomware AttackBeelzebub Raises $3.4 Million for Hacker-Trapping PlatformHacked Public Wi-Fi Gateways Used to Harvest Corporate CredentialsAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on ExploitsDentaQuest Data Breach Potentially Impacts Over 23 Million PeopleMCBS Data Breach Affects 1.2 Million IndividualsRockwell Patches Code Execution Flaws in Arena Simulation SoftwareIn Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveBarry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of