Mobile Track Spotlight

BlackHat Asia 2026

24 April 2026

Date: April 24, 2026 (Fri) 14:55
Event: BlackHat Asia 2026
Location: Marina Bay Sands, Singapore
Format: Track Spotlight Panel
Moderator: Anant Shrivastava (Mobile Track Lead)
Panelists: Shanna Daly, Pamela O’Shea

Overview

Track Spotlight session showcasing the Mobile Track at BlackHat Asia 2026. The Mobile Track encompasses everything mobile — all layers of phones (OS, baseband, hardware, software, apps), mobile infrastructure, mobile device management, telecommunications protocols, GPS, and related telecom topics. This spotlight brings the track lead and invited panelists together to discuss the year’s selected research, recurring themes across submissions, and what’s shaping the mobile security landscape heading into 2026.

As Mobile Track Lead on the BlackHat Asia Review Board, Anant moderates the conversation with panelists Shanna Daly and Pamela O’Shea, drawing on accepted talks and broader industry context to unpack where mobile security research is heading next.

AI Generated Summary

AI Generated Content Disclaimer

Note: This summary is AI-generated and may contain inaccuracies, errors, or omissions. If you spot any issues, please contact the site owner for corrections. Errors or omissions are unintended.

At BlackHat Asia 2026 (Marina Bay Sands, Singapore, April 24, 2026), the Mobile Track Spotlight panel brought three Mobile Track review board members on stage for a candid, audience-driven discussion on the state of mobile security. Anant Shrivastava — founder of Cyfinoid Research, working in mobile software supply chain and cloud security — moderated, introducing panelists Shanna Daly (Sydney; runs Torren Cyber Group, specializing in digital forensics, incident response, and SOC work) and Pamela O’Shea (Melbourne; a pentest company specializing in mobile testing, web testing, and code review). With no prepared slides, the session ran on audience questions plus a few backup “filler questions,” covering AI-generated code bloat, hardware-backed security, jailbreak detection economics, AI-driven offensive research, and how practitioners should actually learn mobile security.

Summary

Key Topics

AI-generated code bloat

PWAs, React Native, and cross-platform code

Help out your pentesters and give them the source code, please. — Pamela O’Shea

AI in penetration testing

…we have to do exactly the one thing anyone in IT hates: write good documentation. — Anant Shrivastava

Hardware-backed security (secure enclave / StrongBox)

Jailbreak detection, SSL pinning, and security economics

You don’t secure 10 rupees with 20,000. You always secure assets with things that are less costlier than the assets themselves. — Anant Shrivastava

Q&A Highlights

Has AI found truly good offensive attacks on mobile apps?

I think the best automation engine on Android is still Monkey, which basically does not have any sense of what it is doing. It just sends random click events. — Anant Shrivastava

How do you detect that a mobile app is running in a compromised environment?

Learning Resources

Key Takeaways