A major security investigation has analyzed 1.8 million Android apps available on the Google Play Store, focusing on those that explicitly claim AI features, and identified worrying security flaws which may be exposing secrets.
From the initial research pool, Cybernews researchers identified 38,630 Android AI apps and examined their internal code for exposed credentials and cloud service references, finding widespread data handling failures that extended far beyond isolated developer mistakes. Overall, the researchers found nearly three-quarters (72%) of the analyzed Android AI apps contained at least one hardcoded secret embedded directly in application code – and on average, each affected app leaked 5.1 secrets.
Read more…
Source: TechRadar News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- 267M Facebook Users’ Phone Numbers Exposed Online
December 19, 2019
A database exposing the names, phone numbers and Facebook user IDs of millions of platform users was left unsecured on the web for nearly two weeks before it was removed. Security researcher Bob Diachenko, who along with Comparitech discovered the unsecured Elasticsearch database, believe it belongs to a cybercriminal organization, as opposed to Facebook. Diachenko went to ...
- Data-Enriched Profiles on 1.2B People Exposed in Gigantic Leak
November 25, 2019
An open Elasticsearch server has exposed the rich profiles of more than 1.2 billion people to the open internet. First found on October 16 by researchers Bob Diachenko and Vinny Troia, the database contains more than 4 terabytes of data. It consists of scraped information from social media sources like Facebook and LinkedIn, combined with names, ...
- Open database leaked 179GB in customer, US government, and military records
October 21, 2019
An open database exposing records containing the sensitive data of hotel customers as well as US military personnel and officials has been disclosed by researchers. On Monday, vpnMentor’s cybersecurity team, led by Noam Rotem and Ran Locar, said the database belonged to Autoclerk, a service owned by Best Western Hotels and Resorts group. Autoclerk is a reservations management system used ...
- Equifax failed to take even the most basic precautions, alleges lawsuit
October 21, 2019
A lawsuit on the 2017 data breach allege that Equifax staffers used the default – ‘admin’ – as the username and password to secure customer information portal How would you secure a portal containing valuable, personal finance information of 148 million accounts of customers spread across the US, Canada and the UK? Equifax employees chose default and ...
- Tax and PII records of 20 million Russians stored without encryption, leaked online
October 2, 2019
Over 20 million tax records belonging to Russian citizens were left unprotected and exposed through an online database accessible to the public, researchers say. This week, cybersecurity researchers from Comparitech, in partnership with Bob Diachenko, said that the unsecured server contained highly sensitive information spanning from 2009 to 2016. The Amazon Web Services (AWS) Elasticsearch cluster, which was ...
- UNICEF leaks personal data of 8,000 users
September 12, 2019
The United Nations’ children’s agency UNICEF has leaked thousands of individuals’ personal data through its online learning portal Agora. An email was mistakenly sent on 26 August to 20,000 Agora users containing the private data belonging to 8,253 people who enrolled on the platform’s immunisation courses. Agora offers courses on child rights, humanitarian action, data, research and ...

