RASMISER Blog

Insights on mobile app security

How we help teams find vulnerabilities, secure emerging technology like AI, and keep clients confident in every release.

Illustration of an AI model generating personalised phishing messages targeting employees on mobile devices
Cyber Threats7 min read

AI-Generated Phishing: Why Every Employee Is Now a High-Value Target

LLMs can now write flawless, hyper-personalised phishing messages at industrial scale. The generic mass-phish is dead — what replaced it is far harder to spot and your app is the delivery mechanism.

Sarah Chen · July 10, 2026

Illustration of an AI malware strand mutating its code to bypass antivirus detection layers
Cyber Threats8 min read

Autonomous AI Malware: The Threat That Rewrites Itself to Escape Detection

A new class of AI-driven malware can observe its environment, modify its own payload, and wait for the ideal conditions to strike. Static signatures are no longer enough, and your app binary is a target.

Marcus Webb · July 8, 2026

Illustration of a corrupted SDK package being imported into a mobile app build pipeline
App Security7 min read

The AI SDK Supply Chain Attack: When Your Most-Trusted Package Becomes a Weapon

Attackers are now using AI to generate convincing, functional SDK forks with hidden backdoors. One malicious import can hand over every user token in your app. Here is how to defend your build pipeline.

Elena Rodriguez · July 5, 2026

Illustration of a cracked AI model lock with exploit code fragments leaking out
Cyber Threats6 min read

Universal LLM Jailbreaks Are Getting Faster and More Transferable

New research shows adversarial suffix attacks optimized on one model now transfer to closed-source frontier models in under an hour. Every embedded LLM is in scope.

Sarah Chen · June 23, 2026

Illustration of malicious documents being injected into a RAG vector database pipeline
Cyber Threats6 min read

RAG Poisoning: How Attackers Corrupt Your AI Knowledge Base

Injecting a handful of malicious documents into a RAG pipeline can silently redirect an AI assistant's answers for every user. Your vector database is now an attack surface.

Marcus Webb · June 22, 2026

Illustration of an AI agent bypassing access control gates through privilege escalation
Emerging Tech7 min read

AI Agent Privilege Escalation: From Chat to Root in Three Steps

Researchers chained prompt injection with over-scoped tool permissions to escalate from a harmless chat query to full device access. Agentic apps need a least-privilege rethink.

Elena Rodriguez · June 21, 2026

Illustration of a multimodal AI model reading hidden instructions embedded in an image
Cyber Threats5 min read

Seeing Is Deceiving: Visual Prompt Injection in Multimodal AI

Attackers are hiding instructions inside images that multimodal models faithfully execute. A photo processed by your AI feature can now carry a hidden command.

Sarah Chen · June 20, 2026

Illustration of an AI assistant connected to multiple MCP tool servers, one of them compromised
Emerging Tech6 min read

MCP Servers Are the New Attack Surface for AI Agents

The Model Context Protocol lets AI agents plug into your tools, but a single malicious or over-permissioned MCP server can hand an attacker the keys to everything.

Marcus Webb · June 18, 2026

Illustration of a smartphone receiving a call with an AI voice waveform morphing into a fake face
Cyber Threats5 min read

AI Voice Deepfakes Make Vishing a Mobile-First Threat

Real-time voice cloning now powers phishing calls that sound exactly like your CEO. The phone in your pocket is the front line, and your app may be the target.

Sarah Chen · June 18, 2026

Illustration of corporate data flowing out of an office into unsanctioned AI chatbot apps
App Security5 min read

Shadow AI: The Data Leak Hiding in Your Employees' Apps

Staff are pasting source code, customer data, and secrets into unsanctioned AI tools every day. Shadow AI is the fastest-growing data-exfiltration channel of 2026.

Elena Rodriguez · June 17, 2026

Illustration of poisoned data droplets being injected into a clean AI training data stream
Cyber Threats6 min read

Data Poisoning: Corrupting AI Before It Ever Ships

Researchers showed that poisoning a tiny fraction of training data can backdoor a model. If your app bundles or fine-tunes a model, the attack starts upstream.

Sarah Chen · June 17, 2026

Illustration of a self-replicating AI worm spreading through a software supply chain
Cyber Threats6 min read

AI Worms Are Here: Miasma and IronWorm Target Your Dev Tools

Self-replicating AI worms now hunt coding assistants, embedding backdoors in config files to steal API keys. The software supply chain just got a new predator.

Marcus Webb · June 16, 2026

Illustration of an AI model generating an exploit from a security patch
Cyber Threats6 min read

When AI Writes Exploits in Hours: The Patch Gap Just Collapsed

Frontier models like Claude Mythos can now generate working exploits from a patch within hours. N-day vulnerabilities are suddenly far more dangerous.

Sarah Chen · June 16, 2026

Illustration of a prompt injection attack exfiltrating data through a trusted search proxy
Cyber Threats5 min read

SearchLeak: How Prompt Injection Turns Trusted Tools Against You

The SearchLeak attack used malicious query parameters to bypass Copilot guardrails and exfiltrate data through Bing as a trusted proxy. Prompt injection is still unsolved.

Marcus Webb · June 16, 2026

Illustration of an autonomous AI agent performing a multi-step cyber attack kill chain
Cyber Threats5 min read

Autonomous Kill Chains: The Risk of Unauthenticated AI Agents

Attackers now use agentic frameworks to run real-time, multi-step intrusions. Unauthenticated agent endpoints can be coerced into executing unauthorized tasks.

Elena Rodriguez · June 16, 2026

Illustration of an AI agent making an authorized payment through a chat interface
Top News6 min read

AI Agents Can Now Pay: What Visa x OpenAI Means for App Security

Visa and OpenAI just let AI agents make authorized payments through ChatGPT. Agentic commerce is here, and it reshapes the mobile attack surface overnight.

Marcus Webb · June 11, 2026

Illustration of an AI model with safety guardrails being broken open
Top News5 min read

Fable 5 Was Jailbroken on Day One: Lessons for App Builders

Anthropic shipped a guardrailed consumer model and researchers broke it within hours. If you embed an LLM in your app, assume its safety layer will fail.

Sarah Chen · June 11, 2026

Illustration of an AI chatbot reply going viral on social media
Viral Moments4 min read

"Based Grok" Goes Viral: The Hidden Risk of No-Filter AI

A candid Grok reply blew up across X this week. Beyond the memes, no-filter AI in your app is a reputational and security liability worth scanning for.

Elena Rodriguez · June 11, 2026

Illustration of a smartphone being scanned for vulnerabilities
App Security6 min read

The 7 Security Gaps Hiding in Every New Build App

Most vulnerabilities ship on day one. Here are the seven issues we catch most often in brand-new mobile apps and how to close them before launch.

Sarah Chen · May 28, 2026

Illustration of a mobile app connected to an AI neural network with a padlock
Emerging Tech7 min read

Securing AI-Powered Apps: The New Attack Surface

LLM features, on-device models, and AI APIs introduce risks traditional scanners miss. Here is what changes and how we help teams ship AI safely.

Marcus Webb · June 4, 2026

Illustration of a CI/CD pipeline with a security gate
DevSecOps5 min read

Shift Left: Making Security a Build Step, Not a Blocker

Security checks at the end of a release cycle slow everyone down. Here is how automated scanning in CI/CD keeps teams fast and clients confident.

Elena Rodriguez · June 9, 2026