A major security investigation has analyzed 1.8 million Android apps available on the Google Play Store, focusing on those that explicitly claim AI features, and identified worrying security flaws which may be exposing secrets.
From the initial research pool, Cybernews researchers identified 38,630 Android AI apps and examined their internal code for exposed credentials and cloud service references, finding widespread data handling failures that extended far beyond isolated developer mistakes. Overall, the researchers found nearly three-quarters (72%) of the analyzed Android AI apps contained at least one hardcoded secret embedded directly in application code – and on average, each affected app leaked 5.1 secrets.
Read more…
Source: TechRadar News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- A bug in an Irish government website exposed COVID-19 vaccination records
March 14, 2024
Two years ago, the Irish government fixed a vulnerability in its national COVID-19 vaccination portal that exposed the vaccination records of around a million residents. But details of the vulnerability weren’t revealed until this week after attempts to coordinate public disclosure with the government agency stalled and ended. Security researcher Aaron Costello said he discovered the ...
- Chinese international purchasing agency for military equipment has agency qualification revoked for serious risk of information leakage
March 13, 2024
A Chinese international purchasing agency has had its purchasing agency qualification revoked for serious risk of information leakage due to the company’s internal mismanagement and poor practices around managing sensitive data, the Equipment Development Department (EDD) of China’s Central Military Commission (CMC) announced in a statement on Tuesday. According to the investigation, China Far East International ...
- U.S. Army Intelligence Analyst Arrested and Charged with Conspiracy to Obtain and Disclose National Defense Information
March 7, 2024
Korbein Schultz, a U.S. Army soldier and intelligence analyst, was arrested today at Fort Campbell following an indictment by a federal grand jury charging him with conspiracy to obtain and disclose national defense information, exporting technical data related to defense articles without a license, conspiracy to export defense articles without a license, and bribery of ...
- Germany: Use of non-secure line behind Taurus talk leak to Russia
March 5, 2024
The Ministry of Defence blamed an unnamed individual’s improper use of a “non-secure data line” for the recent leak of a German army conversation about the Taurus weapon system to Russia. The mistake was made by the participant who took part in the conversation from Singapore and had dialled in via a “non-secure data line” such ...
- US airman pleads guilty to leaking classified documents
March 5, 2024
Jack Teixeira, a member of the Massachusetts Air National Guard charged with leaking classified military documents on a social media platform, pleaded guilty on Monday to carrying out one of the most serious U.S. national security breaches in years. The 22-year-old pleaded guilty to six counts of willful retention and transmission of classified information relating to ...
- LockBit cyberattack: Fulton County refuses to pay ransom as deadline passes
March 1, 2024
Fulton County leaders say they have not paid any ransom to the criminal group claiming responsibility for the cyberattack that affected several of the county’s agencies. The group LockBit had set a deadline of 8:49 a.m. on Thursday for Fulton County to pay the ransom or risk having stolen data leaked onto the dark web. This ...

