Archive for Approov

Approov names Valley vet Rex Jackson Chairman of Scottish mobile app security leader

Posted in Commentary with tags on July 23, 2026 by itnerd

Approov today announced the appointment of Rex S. Jackson as independent Chairman of its Board of Directors. Mr. Jackson succeeds Dr. Lucio Lanza, who has been recognized for his years of leadership and who will continue to serve on the Board as a non-executive director.

Mr. Jackson brings more than three decades of executive and board leadership in Silicon Valley technology companies. He has served as Chief Financial Officer and General Counsel across multiple public and private technology companies, most recently as CFO helping lead ChargePoint through its merger and public listing. He currently serves on the board of Terra Innovatum (Nasdaq: NKLR), where he chairs the audit committee and serves on the compensation committees. Mr. Jackson holds a J.D. from Stanford Law School and a B.A. from Duke University.

The company also paid tribute to Dr. Lanza’s tenure. A legendary figure in semiconductor and electronic design automation investing, Dr. Lanza backed Approov’s vision early and has chaired its Board through years of sustained growth, championing the company’s pioneering work in cloud-based cryptographic mobile app attestation.

The appointment was approved unanimously by Approov’s Board and shareholders, including investors Maven Capital Partners, Lanza Tech Ventures and Scottish Enterprise.

Approov Expands Global Infrastructure to Counter the New Wave of Agentic AI Attacks on Mobile APIs

Posted in Commentary with tags on July 15, 2026 by itnerd

Attackers are no longer writing bots by hand. Agentic AI systems can now probe mobile APIs, mimic legitimate app behavior, and adapt to defenses in real time – at a scale no human-operated botnet could match. Today Approov, the leader in mobile app and API security, announced Approov 2026 3.6, a major global attestation platform upgrade built to meet that threat head-on, combining expanded global infrastructure with the deep, real-time visibility enterprise security teams need to detect and shut down AI-driven attacks as they happen.

The release arrives as Approov processes record attestation volumes for organizations whose mobile apps handle their customers’ most sensitive data – banks, healthcare providers, retailers, and automakers – billions of verifications confirming that every API request comes from a genuine, untampered app on a safe device. Agentic AI attacks rarely run inside the real mobile app; instead, they impersonate it, replaying its API traffic from scripts, emulators and server farms while masquerading as genuine mobile devices. Attestation cuts through that disguise by requiring each request to prove it originates from the authentic app on a real device – proof that a spoofed client running in a data center cannot supply.

New Global Infrastructure for Ultra-Low Latency

Approov has deployed new regional attestation infrastructure in Mexico, with a Milan region following shortly, expanding a global network that already spans North America, South America, Europe, and Asia-Pacific. The new regions cut response times for users across Central America, the southern United States, Southern Europe, the Middle East, and parts of Africa. The Approov attestation network runs across multiple independent cloud providers with automatic failover, using intelligent traffic routing to minimize latency worldwide. As attestation volumes surge, the expanded edge network keeps security checks invisible to legitimate users – protection without friction.

Real-Time Threat Intelligence, Straight into the SOC

Approov turns every protected API into a sensor for AI-driven attack activity, unlocking advanced logging and security use cases:

  • Direct SIEM integration. Backend systems can now decode Approov’s device and app threat signals locally – no extra round trip to Approov servers – and pass detection results directly into Splunk, Sentinel or any SIEM correlated with other request data.
  • Forgery detection. Message Signatures on each network request ensure the origin of the request data verified with a cryptographic key from the device.  Additional key and secret visibility allow verification of attestation ‘pass’ JWT tokens,validly signed ‘fail’ JWT tokens, and invalid or attacker-signed forged tokens – a critical signal when AI agents attempt to counterfeit credentials at scale.
  • Hands-off secret rotation. Setup automated retrieval and deployment of the secrets and keys that backend systems require to secure your mobile APIs, enabling fully automated secret rotation with no manual intervention and no maintenance window.

Deploy New Defenses Without Risking Real Users

Responding to a new attack pattern has always carried a hidden cost: a security policy that blocks attackers can also lock out legitimate customers. Approov 2026 replaces all-or-nothing policy updates with gradual rollouts. Security teams can deploy a new defense to a small slice of traffic, watch its real-world impact live, and expand with confidence – making it safe to respond aggressively to fast-moving AI threats.

Early Warning Before Incidents Escalate

An updated monitoring and alerting suite give both customers and Approov’s own engineers advance notice of trouble:

  • Customer-configurable alerts flag unusual spikes in failed verifications – whether caused by an emerging attack or a third-party network anomaly – so teams can act before failover systems are needed.
  • Global anomaly detection watches pass/fail patterns across Approov’s entire customer base. If multiple accounts show simultaneous failures, Approov’s on-call engineers are paged automatically, turning isolated signals into ecosystem-wide early warning.

Looking Ahead: HarmonyOS Readiness

The release also activates backend support for Huawei’s HarmonyOS platform, now in internal validation, positioning Approov to deliver enterprise-grade protection ahead of the platform’s full market expansion.

Availability

The Approov 2026 backend upgrade is rolling out automatically to all enterprise customers. Documentation for the new SIEM integration, gradual rollout, and automated secret rotation capabilities is available in the updated Approov CLI documentation. For more information, visit approov.com.

AI Scraping puts World Cup, Olympics sports bettors & online sportsbooks at risk

Posted in Commentary with tags on May 14, 2026 by itnerd

Approov’s network monitoring and analysis has found that the World Cup will be the first major proving ground for AI-driven betting fraud, combining record-breaking volumes with high-speed AI tools.

Findings have just been published in “AI Scraping for Manipulation Makes Sports Betting Unfair – The World Cup is the Immediate Test, The LA28 Olympics are a Next Level.”

Indicators of upcoming activity were observed on the Approov Global Attestation Network.  For sportsbooks, this creates two problems that don’t get better with time:

  • Market distortion: Automated actors can move faster than human bettors, particularly in live‑in‑play and micro‑markets (such as first-scorer, goal/point totals, or player-specific props), which are expected to dominate World Cup betting.
  • Perception of unfairness: If regular users believe that bots and AI systems are always one step ahead, the sense of a “level playing field” collapses.

The analysis discusses a new generation of organized, AI-driven bad actors looking to fleece both bettors and betting platforms, with well‑resourced scrapers, arbitrageurs, and betting syndicates treating the World Cup as a high‑margin, high‑velocity data opportunity. It’s also a test lab for exploitation of other high-speed markets, real-time pricing-sensitive transactions, behavioral manipulation, API exploitation and consumer trust engineering.

Why does it all matter? Because when users believe that humans can’t compete, systems collapse.

More details here: https://approov.io/blog/threat-analysis-ai-scraping-for-manipulation-makes-sports-betting-unfair

Once Agentic Smartphones Act Without User Permission, What Could Go Wrong? 

Posted in Commentary with tags on April 21, 2026 by itnerd

When a smartphone’s AI agent can execute actions across apps, read messages, interpret meaning, pull data from various apps and act autonomously outside of the user’s knowledge or intent, outcomes can potentially go sideways very quickly.

For the last 15 years, smartphones have responded to their users’ commands. Now, Android 17 threatens this user interaction model and its inherent safety guardrails.

Agentic mobile’s risks are explained in “Android 17: Your Phone’s AI is Evolving to be More Autonomous,” new analysis by Approov Senior Manager Joyce Kuo.  The full analysis is embedded at bottom.

Here’s the upshot:

Android 17 represents a major step towards moving toward the agentic mobile model, in which a device can coordinate tasks across apps as a personal agent. The upside is convenience. The downside is a new class of risk where nothing is technically compromised, but the result is unpredictable and potentially quite wrong. Data may be exposed, actions may be triggered, and workflows may be executed based on manipulated or misunderstood context.

Kuo looks at this expansion of the mobile attack surface beyond traditional app boundaries and user interaction norms, and why existing protections like sandboxing and permissions won’t address this new layer of risk.

Android 17 represents more than just a UX update; it’s a fundamental security and architecture shift – for brands on mobile, for their developers, and for users.

The core issues are straightforward: when systems start acting on your behalf, potentially without the user’s knowledge, how do you as a smartphone-using consumer prevent them from doing exactly what they may otherwise be allowed to do at the wrong time and for the wrong reasons? And how to brands and other app publishers (and their developers) contain these risks?

Approov Opens New Headquarters in Edinburgh’s New Town Following Year of Rapid Growth, Investment

Posted in Commentary with tags on December 4, 2025 by itnerd

Approov today announced the official opening of its new headquarters in Edinburgh’s New Town. The move marks a significant milestone for the company following a defining year characterised by major investment, strategic partnerships, and a rapidly expanding global customer base.

The relocation to one of Edinburgh’s most iconic areas is a direct response to the company’s accelerated growth trajectory in 2025. Propelled by a recent investment round led by Maven Capital Partners, the new facility provides the necessary infrastructure to scale Approov’s technology and accommodate a growing workforce across engineering, product, sales, and customer success.

Heading into 2026, Approov plans to utilise the new space to accelerate innovation in mobile app and API security, expand its global partner ecosystem, and enhance threat-intelligence capabilities.

Approov Turbocharges Global Security: Cloudflare Argo Smart Routing Halves Latency for Next-Gen Mobile Attestation

Posted in Commentary with tags on October 14, 2025 by itnerd

Approov today announced significant strategic expansion of its global network infrastructure, positioning its unique cloud-based mobile app and device attestation platform as the essential defense against rapidly evolving AI-based API threats. This expansion includes the deployment of Cloudflare’s Argo Smart Routing technology across its multi-cloud network, which is supported by Amazon Web Services (AWS) and Google Cloud Platform (GCP).

Approov’s architecture represents a major shift in mobile security, moving away from conventional, on-device approaches like Runtime Application Self-Protection (RASP) and code obfuscation that are increasingly vulnerable to sophisticated hacking tools and AI-driven reverse engineering.

The Next Generation of Mobile Security: Cloud-Based Attestation

The core of Approov’s next-generation platform is its approach to security-by-design: moving all sensitive secrets, such as API keys, out of the mobile application and into a secure, cloud-based enclave. Security is then managed through a rigorous, real-time app and device attestation process performed entirely in the cloud.

Approov’s cloud platform verifies that all API requests originate from a genuine, untampered mobile app running on a secure device. This model drastically reduces API attacks from bots, scripts, and cloned apps by over 95%, creating a safer digital ecosystem for major organizations in finance, retail, healthcare, and connected cars.

High Performance for a Mission-Critical Platform

To ensure this mission-critical security is delivered without compromising the user experience, Approov recognizes the absolute need for a high-performance, robust, and resilient network infrastructure. The platform must deliver attestation tokens over an encrypted channel with the lowest possible latency, regardless of a mobile app’s operating location.

To meet this demand, Approov has made two key infrastructure enhancements:

1.    Cloudflare Argo Smart Routing Integration: Approov has integrated Cloudflare’s Argo Smart Routing™ across its network. This technology continuously optimizes the routing of attestation traffic by dynamically selecting the fastest and most reliable network paths. By enabling Argo Smart Routing, Approov reduces Internet latency on average by more than 30% and connection errors by 27%, significantly enhancing performance for end-users globally. The integration also includes Cloudflare’s enterprise-level Layer 4/7 Distributed Denial of Service (DDoS) protection.

2.    Expanded Global Attestation Fabric: Approov continues to grow its multi-region, multi-cloud fabric with new points of presence in U.S. East, Hong Kong, and Taipei, Taiwan, complementing existing locations in Dublin, U.S. West (San Jose), Sao Paulo, and Singapore. The multi-cloud deployment on AWS and Google Cloud is designed with automatic cross-cloud failover for maximum resiliency under the most extreme threats.

These strategic investments ensure that Approov will continue to deliver the fastest, most efficient, and most secure mobile app protection, allowing enterprises to fully trust the source of every mobile API request.

Approov Shortlisted for Cyber Innovation Recognition at the 2025 Scottish Cyber Awards

Posted in Commentary with tags on March 18, 2025 by itnerd

Approov has announced that it’s been shortlisted as a finalist for the Cyber Innovation Award at the 2025 Scottish Cyber Awards, sponsored by SC3. This prestigious recognition highlights Approov’s groundbreaking work in mobile security, alongside esteemed finalists Lloyds Banking Group, Morgan Stanley, TrueDeploy, and PACE Anti-Piracy Europe Ltd.

The Scottish Cyber Awards celebrate outstanding contributions to cybersecurity, showcasing organizations that drive innovation and resilience in digital security. Approov’s selection as a finalist underscores its pioneering app attestation technology, which safeguards mobile applications and their backend APIs from emerging cyber threats.

A Revolutionary Approach to Mobile Security

Approov’s innovation directly addresses the growing risks of API abuse, mobile app tampering, and data breaches. With its patented client software attestation technology (U.S. Patent 11,163,858 B2), Approov ensures that only legitimate, untampered mobile applications can interact with critical backend systems. This cloud-based attestation solution provides seamless security across Android, iOS, and HarmonyOS applications, making it a trusted choice for industries such as fintech, healthcare, automotive, and e-commerce.

Standing Out in the Cybersecurity Landscape

Approov’s nomination stems from its proven impact in reducing fraud, preventing unauthorized API access, and helping businesses comply with evolving data security regulations like the EU Digital Markets Act (DMA) and UK Digital Markets, Competition and Consumers Act (DMCC). By tackling API security vulnerabilities that traditional platform-native solutions fail to address, Approov offers organizations a future-proof defense against sophisticated cyber threats.

The winners of the 2025 Scottish Cyber Awards will be revealed at a gala ceremony in Edinburgh on March 27, 2025. Approov congratulates all fellow finalists and looks forward to celebrating cybersecurity excellence in Scotland.

For more information about the Awards, visit 2025 Scottish Cyber Awards.

Today Is World Password Day

Posted in Commentary with tags , , on May 2, 2024 by itnerd

World Password Day is today. It started as a sort of Valentine’s Day (i.e., a completely made-up day) to remind everyone to pay extra close attention to log-ins so as not to fall prey to bad actors. Nowadays, the day just seems like more of a reminder of how hackable we all are.

Below are the thoughts of some industry experts on World Password Day:

Ted Miracco, CEO, Approov

https://www.linkedin.com/in/tedmiracco

“Despite the availability of more secure methods, too many systems still rely solely on passwords for protection. This makes them vulnerable to textbook attacks such as phishing, keylogging, and credential stuffing. Combining mobile attestation with token-based API access presents a more robust and user-friendly alternative to traditional password-based authentication, particularly in mobile environments. By shifting the security focus from something the user knows (password) to something the user has (a secure device) and something the user can access (a token), the security model becomes inherently multi-factor, without the added friction typically associated with 2FA methods. This approach effectively addresses both security and usability, which are critical for mobile device interactions and the protection of sensitive data in mobile applications.”

Craig Harber, Security Evangelist: Open Systems

https://www.linkedin.com/in/craig-harber-531883188/

“Strong passwords are essential but cannot be a standalone defense mechanism to deter threat actors. The optimal length for a password depends on various factors, but security experts generally agree that a longer password is more secure. However, if the passwords are too long and too complex, users will write them down, defeating the purpose. Strong passwords must be paired with Multi-Factor Authentication (MFA) to provide a significant hurdle to stop threat actors. 

“So, as we celebrate another World Password Day, it’s important to remember that without a unique, random, and complex password acting as the first line of defense, the additional protection of MFA is weakened.”

Albert Martinek, cyber threat intelligence analyst, Horizon3.ai
https://www.linkedin.com/in/albert-martinek-6267aa227/

“As the trend remains from last year, cyber threat actors don’t typically use sophisticated hacking tools and techniques like zero-day exploits to gain access to a network; they simply log in with legitimate user credentials. Once they gain initial access, threat actors then appear as legitimate users and can move laterally within a network to gain further access and establish persistence, steal sensitive data, bring down systems, and/or hold the organization hostage through ransomware.

“To help harden organizational systems and networks, as well as your personal accounts, implementing strong password policies are key. This includes sophistication and length requirements as described in the latest recommendations from NIST Special Publication 800-63B to include: 12 characters or more; no passwords matching the list of known breached passwords, no passwords derived from dictionary terms, contextual terms (company name, products name, etc.), or user information (first name, username, DOB, etc.); and uniqueness.” 

Approov & PreEmptive Partner For Comprehensive, Effective Mobile Security Regardless of App Store

Posted in Commentary with tags on March 28, 2024 by itnerd

Approov, a leader in mobile application and API security, and PreEmptive, a pioneering force in application security, today joined forces to provide comprehensive mobile application protection as the EU Digital Markets Act takes effect. The joint solution addresses the main challenges for mobile app security: protecting intellectual property and app shielding, as well as runtime threats to apps and the need for app attestation.

The EU DMA forces Google and Apple to allow side-loaded apps via alternative app stores which reduces the effectiveness of the security mechanisms provided by these vendors. For example, the theft of app intellectual property, creation of illegal copies of apps, and manipulation of apps at runtime are all harder for Google and Apple to prevent.

PreEmptive and Approov have partnered to effectively protect app intellectual property and prevent runtime tampering through a straightforward, cross-platform solution to these challenges that are compatible with both iOS and Android. This effective and easy-to-deploy security solution for mobile apps seamlessly integrates with the CI/CD pipeline and SAST/DAST solutions, and is not dependent on Apple or Google. It includes:

  • Comprehensive shielding of Android and iOS mobile app code from reverse engineering and intellectual property theft.
  • Runtime app attestation to prevent cloned and copied apps.
  • Anti-tampering checks to detect client OS manipulation and the presence of emulators and hostile frameworks at runtime.
  • API and communications channel protection by using dynamic certificate pinning.
  • Dynamic API Key and certificate management to prevent API abuse.

There are fundamental security challenges with mobile apps: they can be reverse engineered, analyzed, cloned, modified, or copied, and the environments they run in can be hacked, rooted, instrumented, and manipulated to interfere with the operation of an app. Apple and Google provide only basic app protection and attestation, but these are limited and are dependent on features of the Apple App Store and on Google Play. Stronger security measures are needed.

Approov and PreEmptive address these challenges with a joint solution that works across all platforms and application types — independent of the app store employed to distribute apps. This means users can future-proof your application security while continuously monitoring for and preventing app and API abuse.

Under terms of the partnership:

  • Approov can resell Dotfuscator and JSDefender, and the PreEmptive mobile shielding products: PreEmptive DashO for Android, and Defender for iOS.
  • Approov provides an extended 90-day trial period of Approov RASP and runtime analytics to PreEmptive customers.

April 24 Joint Web Seminar Explains It All

Approov will host a joint web seminar on the impact of the EU Digital Markets Act with PreEmptive on April 24, 2024, at 11am US Eastern Time (ET). The one-hour session will delve into mobile app vulnerabilities and demonstrate how PreEmptive and Approov effectively protect app intellectual property and prevent runtime tampering, with a straightforward approach compatible with both iOS and Android. Attendees will learn:

  • How the EU Digital Markets Act exposes the limitations of Google and Apple mobile security.
  • Why the two main challenges for mobile app security are: (1) The protection of intellectual property and the need for app shielding; and (2) Runtime threats to apps and the need for app attestation.
  • How to easily and effectively defend against these threats as the EU DMA takes effect
  • How PreEmptive and Approov together provide an effective and easy-to-deploy security solution for mobile apps that is not dependent on Apple or Google.

Register for the webinar here: https://approov.io/info/joint-webinar-comprehensive-and-effective-mobile-security

Are Giants Hiding Behind “App Store Security?” New Approov Blog Discusses This

Posted in Commentary with tags on December 20, 2023 by itnerd

Approov, leaders in mobile app security, have just published:  Limitations of Google Play Integrity API (ex SafetyNet).

Given recent lawsuits on Google’s & Apple’s app stores, are the giants hiding behind “app store security” to rake in commissions, and if so, what might change? The Approov blog examines some of the security gaps that researchers have repeatedly found, and lists nine specific Google Play App Store security issues and gaps that impact integrity – all of which can be addressed in a less restrictive, more open marketplace. 

Ted Miracco, CEO of Approov, adds these comments: 

   “Google and Apple have faced increased scrutiny and legal action recently over their app store policies and alleged anti-competitive behavior. Google was found by a California jury to have engaged in anticompetitive conduct related to the Google Play Store on Android devices in their case against Epic Games. Additionally, Google settled a related lawsuit with over 30 US states for $700 million and agreed to changes in Play Store policies. Meanwhile, Apple faces ongoing appeals over a similar lawsuit brought by Epic Games regarding App Store policies for iOS devices.

   “These legal actions could bring significant changes to the mobile app ecosystems that are now controlled tightly by Google and Apple. The lawsuits have focused heavily on the 30% commission charged by the app stores, with plaintiffs arguing that this fee is excessive and only possible due to the app store operators’ monopolistic power. Forced reductions in this commission percentage could have major financial implications for Google and Apple.

   “Additionally, policy changes that enable alternative payment processing and easier sideloading of apps could threaten the dominance of both the Play Store and App Store. If third-party app stores can gain traction, bypassing the tech giants’ review processes and fees, it would reduce both their control and access to valuable end user data. 

   “Google and Apple have staunchly defended their walled garden approaches by arguing it provides critical security protections for users. For example, Google claimed its policies “retain strong security protections” in its recent $700 million settlement. Apple makes similar statements about App Store security safeguards. History indicates otherwise.

   “This is where mobile app attestation solutions like Approov come in. Approov provides advanced integrity checking of apps to verify they are genuine and untampered, while also checking the security integrity of user devices. By leveraging Approov across apps distributed through third-party stores, the security justification for restrictive policies rings hollow. App integrity and security can be maintained without the excessive control and fees imposed by Google and Apple.

   “The recent legal action could force app store policy changes and reduce the dominance of Google and Apple in mobile software distribution. And innovative technologies like Approov’s app attestation enables security confidence in alternative app sources, blowing holes through the app security arguments Apple and Google depend on to restrict competition. The results could be substantial shifts in power and revenue in the mobile app ecosystem.”