Lookout’s new Mobile Security Exposure Center (MSEC) creates SBOMs for enterprise mobile apps to uncover vulnerable components and hidden risks. By cross‑referencing known vulnerability databases and planning to use frontier AI for unknown threats, it shifts security from reactive to proactive.
Key Takeaways
- Lookout’s MSEC generates SBOMs for every mobile app in an enterprise fleet.
- MSEC cross‑references components with known vulnerability databases such as CISA’s KEV list.
- Future plans include using frontier AI models to discover previously unknown vulnerabilities.
Mobile devices present a serious security problem: they operate outside the security perimeter and beyond the visibility of the security team. While security may know what applications live on those devices, they rarely understand the components and dependencies that comprise those applications, nor the vulnerabilities buried within them.
Lookout CEO Jim Dolce highlighted the WolfSSL library – a small, fast SSL/TLS implementation used in over a billion devices – which contains a critical flaw that could let attackers mimic a banking app and steal credentials.
To address such blind spots, Lookout introduced the Mobile Security Exposure Center (MSEC). MSEC scans every device in an organization’s mobile fleet, inventories all installed apps, and builds a proprietary SBOM from each app’s binary. It then maps every component against known vulnerability databases, feeding the results into the organization’s CTEM for remediation.
Why This Matters
BozokMedia analysis shows that without deep visibility into software composition, enterprise security teams remain stuck in reactive mode. MSEC’s proactive approach not only patches known flaws but also prepares organizations for emerging threats.
“Visibility into the software bill of materials is the missing link in mobile risk management,” says Dr. Anita Patel, mobile security analyst.
MSEC complements Lookout’s existing AI Visibility & Governance product, delivering a unified view of AI usage and software composition. Together they enable a shift from reactive application management to proactive exposure management.
Frequently Asked Questions
- Does MSEC only identify known vulnerabilities? Currently it correlates components with databases like CISA’s KEV list, but Lookout plans to leverage frontier AI models to discover unknown flaws.
- Can MSEC integrate with existing security tools? Yes, its output can be fed into CTEM and other security platforms for automated remediation.