Android apps have leaked over 730TB of user data and Google secrets


A major security investigation has analyzed 1.8 million Android apps available on the Google Play Store, focusing on those that explicitly claim AI features, and identified worrying security flaws which may be exposing secrets.

From the initial research pool, Cybernews researchers identified 38,630 Android AI apps and examined their internal code for exposed credentials and cloud service references, finding widespread data handling failures that extended far beyond isolated developer mistakes. Overall, the researchers found nearly three-quarters (72%) of the analyzed Android AI apps contained at least one hardcoded secret embedded directly in application code – and on average, each affected app leaked 5.1 secrets.

Read more…
Source: TechRadar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Military Contractor’s Vendor Leaks Resumes in Misconfigured AWS S3

    September 5, 2017

    Thousands of resumes and job applications containing the personal information of U.S. veterans, many with top secret clearances, and law enforcement officers were left exposed in an Amazon Web Services S3 bucket, continuing a trend where poorly configured cloud-storage services are putting people at risk. The applicants were seeking employment with a private military contractor from ...

  • Anonymous Hacks NHS System, Data of 1.2 Million Patients Allegedly Exposed

    August 21, 2017

    The NHS has once again been the target of hackers, this time with a member of the famous group Anonymous managing to breach the appointment booking system and expose details of 1.2 million patients. SwiftQueue, who handles appointments of eight NHS trusts, confirmed the hack, but said that only some 32,500 “lines of administrative data” had ...

  • How Top Companies Accidentally Leaking Terabytes of Sensitive Data Online

    August 9, 2017

    An anti-malware detection service provider and premium security firm has been accused of leaking terabytes of confidential data from several Fortune 1000 companies, including customer credentials, financial records, network intelligence and other sensitive data. However, in response to the accusations, the security firm confirmed that they are not pulling sensitive files from its customers; instead, it’s ...

  • Sweden data leak ‘a disaster’, says PM

    July 24, 2017

    The Swedish government has admitted to a huge data leak made by one of its own departments during an IT outsourcing procedure in 2015. Sweden’s prime minister said it was “a disaster”, Swedish media reported. Reports say that confidential data about military personnel, along with defence plans and witness protection details, were exposed by the Transport Agency. They ...