RASMISER Blog
Insights on mobile app security
How we help teams find vulnerabilities, secure emerging technology like AI, and keep clients confident in every release.

AI-Generated Phishing: Why Every Employee Is Now a High-Value Target
LLMs can now write flawless, hyper-personalised phishing messages at industrial scale. The generic mass-phish is dead — what replaced it is far harder to spot and your app is the delivery mechanism.
Sarah Chen · July 10, 2026

Autonomous AI Malware: The Threat That Rewrites Itself to Escape Detection
A new class of AI-driven malware can observe its environment, modify its own payload, and wait for the ideal conditions to strike. Static signatures are no longer enough, and your app binary is a target.
Marcus Webb · July 8, 2026

The AI SDK Supply Chain Attack: When Your Most-Trusted Package Becomes a Weapon
Attackers are now using AI to generate convincing, functional SDK forks with hidden backdoors. One malicious import can hand over every user token in your app. Here is how to defend your build pipeline.
Elena Rodriguez · July 5, 2026

Universal LLM Jailbreaks Are Getting Faster and More Transferable
New research shows adversarial suffix attacks optimized on one model now transfer to closed-source frontier models in under an hour. Every embedded LLM is in scope.
Sarah Chen · June 23, 2026

RAG Poisoning: How Attackers Corrupt Your AI Knowledge Base
Injecting a handful of malicious documents into a RAG pipeline can silently redirect an AI assistant's answers for every user. Your vector database is now an attack surface.
Marcus Webb · June 22, 2026

AI Agent Privilege Escalation: From Chat to Root in Three Steps
Researchers chained prompt injection with over-scoped tool permissions to escalate from a harmless chat query to full device access. Agentic apps need a least-privilege rethink.
Elena Rodriguez · June 21, 2026

Seeing Is Deceiving: Visual Prompt Injection in Multimodal AI
Attackers are hiding instructions inside images that multimodal models faithfully execute. A photo processed by your AI feature can now carry a hidden command.
Sarah Chen · June 20, 2026

MCP Servers Are the New Attack Surface for AI Agents
The Model Context Protocol lets AI agents plug into your tools, but a single malicious or over-permissioned MCP server can hand an attacker the keys to everything.
Marcus Webb · June 18, 2026

AI Voice Deepfakes Make Vishing a Mobile-First Threat
Real-time voice cloning now powers phishing calls that sound exactly like your CEO. The phone in your pocket is the front line, and your app may be the target.
Sarah Chen · June 18, 2026

Shadow AI: The Data Leak Hiding in Your Employees' Apps
Staff are pasting source code, customer data, and secrets into unsanctioned AI tools every day. Shadow AI is the fastest-growing data-exfiltration channel of 2026.
Elena Rodriguez · June 17, 2026

Data Poisoning: Corrupting AI Before It Ever Ships
Researchers showed that poisoning a tiny fraction of training data can backdoor a model. If your app bundles or fine-tunes a model, the attack starts upstream.
Sarah Chen · June 17, 2026

AI Worms Are Here: Miasma and IronWorm Target Your Dev Tools
Self-replicating AI worms now hunt coding assistants, embedding backdoors in config files to steal API keys. The software supply chain just got a new predator.
Marcus Webb · June 16, 2026

When AI Writes Exploits in Hours: The Patch Gap Just Collapsed
Frontier models like Claude Mythos can now generate working exploits from a patch within hours. N-day vulnerabilities are suddenly far more dangerous.
Sarah Chen · June 16, 2026

SearchLeak: How Prompt Injection Turns Trusted Tools Against You
The SearchLeak attack used malicious query parameters to bypass Copilot guardrails and exfiltrate data through Bing as a trusted proxy. Prompt injection is still unsolved.
Marcus Webb · June 16, 2026

Autonomous Kill Chains: The Risk of Unauthenticated AI Agents
Attackers now use agentic frameworks to run real-time, multi-step intrusions. Unauthenticated agent endpoints can be coerced into executing unauthorized tasks.
Elena Rodriguez · June 16, 2026

AI Agents Can Now Pay: What Visa x OpenAI Means for App Security
Visa and OpenAI just let AI agents make authorized payments through ChatGPT. Agentic commerce is here, and it reshapes the mobile attack surface overnight.
Marcus Webb · June 11, 2026

Fable 5 Was Jailbroken on Day One: Lessons for App Builders
Anthropic shipped a guardrailed consumer model and researchers broke it within hours. If you embed an LLM in your app, assume its safety layer will fail.
Sarah Chen · June 11, 2026

"Based Grok" Goes Viral: The Hidden Risk of No-Filter AI
A candid Grok reply blew up across X this week. Beyond the memes, no-filter AI in your app is a reputational and security liability worth scanning for.
Elena Rodriguez · June 11, 2026

The 7 Security Gaps Hiding in Every New Build App
Most vulnerabilities ship on day one. Here are the seven issues we catch most often in brand-new mobile apps and how to close them before launch.
Sarah Chen · May 28, 2026

Securing AI-Powered Apps: The New Attack Surface
LLM features, on-device models, and AI APIs introduce risks traditional scanners miss. Here is what changes and how we help teams ship AI safely.
Marcus Webb · June 4, 2026

Shift Left: Making Security a Build Step, Not a Blocker
Security checks at the end of a release cycle slow everyone down. Here is how automated scanning in CI/CD keeps teams fast and clients confident.
Elena Rodriguez · June 9, 2026