A major security investigation has analyzed 1.8 million Android apps available on the Google Play Store, focusing on those that explicitly claim AI features, and identified worrying security flaws which may be exposing secrets.
From the initial research pool, Cybernews researchers identified 38,630 Android AI apps and examined their internal code for exposed credentials and cloud service references, finding widespread data handling failures that extended far beyond isolated developer mistakes. Overall, the researchers found nearly three-quarters (72%) of the analyzed Android AI apps contained at least one hardcoded secret embedded directly in application code – and on average, each affected app leaked 5.1 secrets.
Read more…
Source: TechRadar News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- National Security Agency employee indicted for ‘leaking top secret info’
April 1, 2022
The United States Department of Justice (DoJ) has accused an NSA employee of sharing top-secret national security information with an unnamed person who worked in the private sector. According to a DoJ announcement and the indictment, an NSA staffer named Mark Unkenholz “held a TOP SECRET/Sensitive Compartmented Information (SCI) clearance and had lawful access to classified ...
- Apple and Meta Gave User Data to Hackers Who Used Forged Legal Requests
March 30, 2022
Apple Inc. and Meta Platforms Inc., the parent company of Facebook, provided customer data to hackers who masqueraded as law enforcement officials, according to three people with knowledge of the matter. Apple and Meta provided basic subscriber details, such as a customer’s address, phone number and IP address, in mid-2021 in response to the forged “emergency ...
- Israel: Mossad head’s personal files, photos leaked by Iran-linked Telegram group
March 16, 2022
Photos and personal documents disclosing information on Mossad director David Barnea and his family were leaked in a Telegram channel called “Open Hands” on Tuesday, Walla reported. Created hours before the leak was published to some 30 followers, the channel is reportedly linked to Iranian groups. A video released in the leak claims the documents and photos ...
- NVIDIA DLSS source code leaked as part of cyberattack
March 2, 2022
The attack on NVIDIA continues, this time with an alleged leak of the source code for the company’s DLSS tech. A ransomware group known as Lapsus has allegedly shared NVIDIA’s DLSS source code as part of a cyberattack. The group has demanded that NVIDIA remove mining limitations from RTX 30-series graphics cards. The leaked DLSS source code ...
- Conti ransomware group’s source code leaked
March 2, 2022
Infamous ransomware group Conti is now the target of cyberattacks in the wake of its announcement late last week that it fully supports Russia’s ongoing invasion of neighboring Ukraine, with the latest hit being the leaking of its source code for the public to see. This disclosure comes just days after an archive leaked containing more ...
- Signal says messages circulating about app’s hacking false
March 1, 2022
Instant messaging app Signal said on Monday rumors circulating on several apps that its messaging platform has been “compromised and hacked” is false. Signal said in a tweet that it saw an uptick in usage in Eastern Europe and the rumor messages were often attributed to official government sources that read “attacks on Signal platform.” Read more… Source: ...

