Android apps have leaked over 730TB of user data and Google secrets


A major security investigation has analyzed 1.8 million Android apps available on the Google Play Store, focusing on those that explicitly claim AI features, and identified worrying security flaws which may be exposing secrets.

From the initial research pool, Cybernews researchers identified 38,630 Android AI apps and examined their internal code for exposed credentials and cloud service references, finding widespread data handling failures that extended far beyond isolated developer mistakes. Overall, the researchers found nearly three-quarters (72%) of the analyzed Android AI apps contained at least one hardcoded secret embedded directly in application code – and on average, each affected app leaked 5.1 secrets.

Read more…
Source: TechRadar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Quarter of a million lawyer disciplinary records leak

    February 28, 2022

    Approximately 260,000 nonpublic disciplinary records stored on behalf of The State Bar of California were found to be exposed to the public and to have been republished on Judyrecords.com, a website that aggregates over 630 million public court records. The sensitive records exposed include the case number, filing date, case type, case status, and respondent and ...

  • Danish intelligence chief held over suspected information leaks

    January 10, 2022

    The head of Denmark’s foreign intelligence unit, Lars Findsen, has been remanded in custody over his involvement in a case of “highly classified” information leaks, public broadcaster DR reported on Monday. Denmark’s two intelligence services have been thrown into disarray since four current and former employees were detained in December over allegations of leaking highly classified ...

  • 1.1M Compromised Accounts Found at 17 Major Companies

    January 5, 2022

    There have been more than 1.1 million online accounts compromised in a series of credential-stuffing attacks against 17 different companies, according to a New York State investigation. Credential-stuffing attacks, such as last year’s attack on Spotify, use automated scripts to try high volumes of usernames and password combinations against online accounts in an effort to take ...

  • Top 10 healthcare breaches in the U.S. exposed data of 19 million

    December 31, 2021

    The healthcare sector has been the target of hundreds of cyberattacks this year. A tally of public data breach reports so far shows that tens of millions of healthcare records have been exposed to unauthorized parties. Most of the largest data breaches result from ransomware attacks and the first ten of them account for more than ...

  • T-Mobile confirms SIM swapping attacks led to breach

    December 30, 2021

    T-Mobile has confirmed a data breach that was caused in part by SIM swapping attacks, according to a statement from the company. The T-Mo Report, a blog tracking T-Mobile, obtained internal reports showing that some data was leaked from a subset of customers. Some individuals had their customer proprietary network information (CPNI) leaked, which includes information about ...

  • UK National Crime Agency finds 225 million previously unexposed passwords

    December 21, 2021

    The United Kingdom’s National Crime Agency and National Cyber Crime Unit have uncovered a colossal trove of stolen passwords. We know this because Troy Hunt, of Have I Been Pwned (HIBP) fame, yesterday announced the agency has handed them over to his service, which lets anyone conduct a secure search of stolen passwords to check if ...