It is usually a mistake to think of security as either it is or it isn't. You really need to do a basic risk assessment. As a comparison, ask the question "Is my house secure?" The answer to this question is not yes or no. It really depends on factors like where your house is located i.e. 30 miles from the nearest town is possibly safer than in a suburb with a high level of crime or burglaries. for my house in the country, I might have just standard locks, but for my house in the city, I might have high quality deadbolt locks, alarms, a guard dog etc. If on the other hand, I collect valuable art work and keep it in my country house and I just use my town hose as a crash pad for when I'm in town, I might invest in alarms and dogs for my country house and not really worry about the town hose as there isn't much value there and even if someone does break in, it probably won't have much impact to me.
the other point to consider is that if someone really wants to break into my house, I probably won't be able to stop them. All I can really do is make the cost of breaking in for the thief higher than the reward/value they will obtain.
The same ideas apply with respect to the use of SMS for verification etc. There are numerous reports of people having their Google mail account hacked despite using Google's two step verification (which includes an SMS code). See for example http://gizmodo.com/how-hackers-reportedly-side-stepped-gmails-two-factor-a-1653631338 In addition to the risk of a malicious app on your phone stealing that information (there are numerous reports of banking malware which does this), there is also the risk that someone will hack your service provider and redirect your number to their phone. This is why most of the better systems don't rely only on the SMS. Often the SMS is just one bit of information which is required to gain access.
However, just like the house example, whether it is secure really depends on evaluating the risks. For example, I use an app which records todo items, bookmarks and other notes. It uses SMS as a way to recover my account should I forget my password or whenever I access it from a new device. Is this secure? For me, it is secure enough. If someone was to redirect my phone and get my SMS code and access the site, so what? They get access to my todo list and SMS messages. Most likely, it would just be an inconvenience. However, if my bank just used an SMS code to authenticate me, I would probably switch banks because this would be a much higher risk.
So, in general, SMS on its own as a form of authentication is not great, but may be sufficient for some things and is definitely not sufficient for others. If it is only part of the authentication process and requires additional information, that is probably better, but for some applications, may be a little excessive. Essentially, you need to evaluate its use in context and be wary of sweeping statements that say it is or isn't secure.