As mobile devices continually operate outside traditional security measures, they pose a significant challenge for IT teams who often lack comprehensive insight into app components and their vulnerabilities. Lookout, a leader in cybersecurity, addresses this issue through its new Mobile Security Exposure Center (MSEC), providing deeper visibility into potential risks within enterprise mobile devices.
The Hidden Risks in Mobile Applications
Mobile applications are often more than they appear, with underlying components like WolfSSL, a widely-used SSL/TLS library, which is present on over a billion devices. Jim Dolce, CEO of Lookout, highlights the risks associated with such libraries, especially when vulnerabilities are identified, such as one found by the Mythos Glasswing project. This vulnerability could allow malicious actors to impersonate banks and steal sensitive information.
Despite awareness of these vulnerabilities, security teams frequently remain in the dark regarding the apps employees use. This gap in knowledge can lead to overlooked risks that threaten organizational security.
Comprehensive Visibility with Lookout MSEC
Lookout’s MSEC aims to bridge this gap by thoroughly analyzing each device in an enterprise’s mobile fleet. It identifies all installed applications and creates a proprietary software bill of materials (SBOM). This detailed inventory allows MSEC to correlate app components with known vulnerability databases such as the KEV list.
By identifying applications using vulnerable components like WolfSSL, MSEC empowers security teams to take proactive remediation actions. This approach transforms application management from reactive to proactive, enhancing overall security posture.
Innovative Use of AI Models
While MSEC excels in identifying known vulnerabilities, Lookout is also leveraging frontier AI models to uncover unknown vulnerabilities. According to Dolce, these AI models are employed defensively to stay ahead of potential cyber threats. By exploring beyond existing databases, Lookout aims to catalog previously undiscovered vulnerabilities, further fortifying mobile app security.
The process begins with creating an accurate SBOM for each app, correlating components with known vulnerabilities, and ultimately using AI models to discover new ones. This comprehensive strategy aims to outpace adversaries and secure enterprise mobile environments.
As organizations continue to face expanding mobile attack surfaces, Lookout’s MSEC offers a vital solution for navigating the complexities of modern mobile security. By integrating cutting-edge technology and thorough risk assessment, Lookout ensures that enterprises can better manage and mitigate app vulnerabilities.
