Subscribe Share Full episode and show notes Application security , AI/ML , AI benefits/risks The AI Threat Multiplier: Securing Mobile Apps in the Automated Era – Ryan Lloyd, Jason Cortlund – ASW #400 While agents and LLMs haven’t fundamentally changed core mobile vulnerability types, they have supercharged speed, scale, and accessibility—democratizing threats like automated phishing, synthetic identity fraud, and easier identification of hard-coded secrets. Ryan Lloyd and Jason Cortlund break down how threat actors leverage LLMs as a force multiplier to accelerate mobile app attacks. Then we discuss actionable defense strategies, from viewing agents as an active adversary to leveraging server-side threat telemetry, attestation, and layered defense strategies combined with polymorphic code releases. This segment is sponsored by Guardsquare. Visit https://securityweekly.com/guardsquare to ... September 15, 2026 This episode is sponsored by Full Segment Notes While agents and LLMs haven't fundamentally changed core mobile vulnerability types, they have supercharged speed, scale, and accessibility—democratizing threats like automated phishing, synthetic identity fraud, and easier identification of hard-coded secrets. Ryan Lloyd and Jason Cortlund break down how threat actors leverage LLMs as a force multiplier to accelerate mobile app attacks. Then we discuss actionable defense strategies, from viewing agents as an active adversary to leveraging server-side threat telemetry, attestation, and layered defense strategies combined with polymorphic code releases. This segment is sponsored by Guardsquare. Visit https://securityweekly.com/guardsquare to learn more about them! Guests Ryan Lloyd Chief Product Officer at Guardsquare Ryan has spent the past 25 years working for companies that build software tools for developer teams. Version control, issue tracking, automated testing and app security. In his current role as Chief Product Officer for Guardsquare he engages customers to help identify and solve the biggest challenges in mobile application security. Jason Cortlund Technical Marketing Writer at Guardsquare Jason Cortlund is a mobile application security evangelist at Guardsquare. His recent work includes examining cloned-app proliferation and broader AppSec trends across various industries, including healthcare, banking, and retail. Host Mike Shema https://dangerouserrors.com Announcements You shipped it, but is it still exposed? Shadow APIs, forgotten endpoints, and unmanaged services are expanding your attack surface beyond what AppSec teams can track. So what’s still out there? At the Attack Surface Management Virtual Cybersecurity Summit on September 16th, learn how to discover exposed applications and APIs and reduce risk across your environment. Security Weekly listeners can register for free at https://securityweekly.com/asm using the promo code: CSS26-SW InfoSec World is introducing a fresh experience for 2026, with new voices, a new venue, and new topics reflecting the challenges security teams are facing now. Join practitioners and leading professionals from across industries in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026. List of Articles Mike Shema An alignment assessment of recent cybersecurity incidents Anthropic OpenAI agents carried out an undisclosed cyber-attack on RubyGems See also more unmonitored activity in " Discovery of a new OpenAI agent message board ." CVE-2026-82329: Unauthenticated Administrative Access in JFrog Artifactory via an Empty Cluster Join Key The Anthropic Glasswing Receipts Are Starting to Trickle In | Blog | VulnCheck Cybersecurity Benchmarking: Why, Why Not, When and How Here's an example of exploring benchmarks that distinguish between the coding effectiveness of a model from the effectiveness of the coding tools that exercise that model. Evaluating AGENTS.md: Are Repository-Level Context Files Helpful for Coding Agents? OWASP MCP Taxonomy · GitHub Show More Stay in the Know, No Smoke and Mirrors – Join Our Newsletter Get expert insights and technical breakdowns straight to your inbox. Join Now Related Segments Vulnerability Management Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 – Michael Leland, Sean Murphy, Idan Plotnik, Ido Geffen – ASW #399 Application security Fixing Software Weaknesses Rather Than Just Finding More Flaws – Nidhi Aggarwal, Gil Geron, Braden Russell – ASW #398 Application security Applying Zero Trust Principles to Agents – Kieran Human – ASW #397 Related Content AI/ML Trump pushes back on Anthropic CEO’s call for an AI slowdown Exposure management Total AI awareness: Gaining full visibility of the AI attack surface AI/ML Dead drops in public: What the AI agent stashed on Hugging Face You can skip this ad in 5 seconds
The article discusses how AI agents and LLMs act as a threat multiplier for mobile app security, accelerating attacks like automated phishing and synthetic identity fraud by increasing the speed, scale, and accessibility of exploitation. It does not describe a specific vulnerability with a CVE, CVSS score, or affected versions. Recommended defense strategies include treating AI as an active adversary and implementing server-side telemetry, attestation, and layered defenses with polymorphic code.