Lookout Launches Mobile Software Exposure Center Amid AI-Driven Threat Surge
Lookout introduces the Mobile Software Exposure Center (MSEC) to address the growing threat of AI-accelerated vulnerability exploitation in mobile applications.

Lookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC), a new tool designed to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities within an organization's mobile software ecosystem. Integrated directly into the Lookout Mobile Endpoint Security platform, MSEC aims to close a critical gap in current threat exposure management strategies.
The cybersecurity landscape is rapidly evolving due to advancements in artificial intelligence. Frontier AI models are significantly reducing the time and cost associated with discovering vulnerabilities, developing exploits, and orchestrating complex attacks. This shift is transforming cyber offense from a manual, time-consuming process into an automated one that can operate at machine speed, leading security researchers to warn of an impending "Zero-Day Flash Flood" – a wave of AI-driven attacks capable of weaponizing vulnerabilities almost instantaneously.
Lookout's recent discovery of DarkSword, a sophisticated iOS exploitation framework, highlights a critical limitation in existing Continuous Threat Exposure Management (CTEM) platforms. While CTEM solutions offer broad visibility across desktops, servers, cloud infrastructure, and network assets, they have historically struggled to provide adequate coverage for mobile software. This oversight leaves a significant blind spot in an organization's overall security posture.
Mobile software is inherently complex, often assembled from a diverse supply chain including proprietary code, open-source libraries, third-party SDKs, and operating system frameworks. Traditional security tools are ill-equipped to inspect compiled mobile software, leaving organizations unaware of exploitable risks until vulnerabilities are actively weaponized in the wild. "Enterprise Exposure Management platforms cannot protect what they cannot see," stated Jim Dolce, CEO of Lookout, emphasizing the need for extended visibility into mobile assets.
MSEC addresses this challenge by offering five core capabilities. It provides fleet-wide risk correlation by measuring software exposure across mobile devices and identifying deployed software versions affected by known vulnerabilities. The tool integrates with CVE databases, threat intelligence feeds, and the CISA Known Exploited Vulnerabilities (KEV) catalog to transform raw inventory data into actionable risk insights.
Furthermore, MSEC delivers component-level exposure impact analysis by automatically generating Software Bills of Materials (SBOMs) from compiled mobile application binaries, even without access to source code. This allows security teams to instantly identify all affected applications and devices when a new vulnerability is disclosed, drastically reducing assessment and remediation times. The platform also features adaptive, context-aware enforcement policies that adjust to vulnerability severity and remediation status, minimizing disruption to users and operations.
Beyond technical detection, MSEC includes vendor security hygiene tracking, evaluating software publishers' responsiveness to security issues and calculating a Mean Time to Patch (MTTP) metric. This enables organizations to assess vendor reliability and reduce reliance on those with a history of slow security updates. Crucially, MSEC integrates seamlessly with existing CTEM and Cyber Risk Management (CRM) platforms, allowing mobile software exposure to be managed alongside other critical IT assets within established workflows.
Lookout's long-standing focus on mobile security, backed by extensive telemetry from millions of devices and applications, positions MSEC to provide the specialized mobile software intelligence that has been missing from broader exposure management solutions. This new offering complements Lookout's AI Visibility and Governance solution, creating a comprehensive Mobile AI Security platform that protects both enterprise data and the foundational mobile software infrastructure.