Monday, December 6 2021

A recent report highlights app developers’ misconfiguration and poor implementation of third party cloud services, which may have exposed sensitive data of over 100 million users.

An investigation of 23 Android applications by researchers at Check Point Research led to the discovery of numerous misconfigurations of cloud services including real-time databases, push notification managers, and cloud storage that could potentially facilitate malicious actors in their misconduct. This not only places sensitive user data—passwords, private chats, device locations, payment details, and more—in jeopardy, but also compromises protection of developers’ internal resources.

Much to the researchers’ dismay, developers of 13 of the applications failed to equip their real-time databases with authentication features. The researchers effortlessly tapped into the real-time database of a taxi booking app with over 50,000 users—with one request, the team was able to access chat messages between drivers and passengers, their locations, phone numbers, and full names.

The researchers also found that the keys used for accessing cloud storage were embedded into the app itself for 10 of the applications. The research team was able to decipher keys used by a screen recorder application to gain access to recordings and fax documents by analyzing the application files. Another app used keys embedded in the application file to send push notifications, which enabled attackers to send fraudulent notifications to users to request personal or payment information.

As third-party cloud services are nearly omnipresent in mobile applications, CPR stressed the need for mobile app developers to use best practices in configuring and implementing cloud services.

Previous

EU Extends Sanctions to Hackers—Banks, Cyber Insurers Face Dilemma

Next

S&P Hints at Rating Downgrades for Poor Cyber… Again

Check Also

Widget

Don’t Miss

Cyber Deals: Coinbase, Armis, CyCognito, Brivo

Van Michael

Coinbase acquires cryptographic security provider Unbound Security.  Armis realizes $3.4 Billion valuation.  Brivo goes public through its recent merger and CyCognito sees an influx of $100 Million. Funding Armis closes latest investment round at valuation of $3.4 billion. One Equity Partners, in conjunction with existing investors, made a combined $300 million investment to accelerate its strategic platform development and global GTM […]

Cyber Deals: Resilience, Stellar Cyber, XM Cyber, Bricata

Van Michael

Early-stage cybersecurity startups exit stealth mode. Low maintenance tech propel ShieldIOT and Zenity to finalize initial seeding. XM Cyber realizes respectable exit with the sale of a majority stake. BlueVoyant announces strategic partnership with Bytes Technology Group.  DNV merges with Applied Risk to form world’s largest industrial cyber security practice. Funding ShieldIOT, an Internet of Things (IoT) cybersecurity […]

Themis Neepa Patel AuthID board

Cyber People Moves

Kevin Webb

Biometric authentication firm AuthID.ai appointed Neepa Patel to its board of directors. Patel is chief executive of governance and compliance solutions provider Themis. Digital services provider Presidio nabbed Dan Lohrmann, Michigan’s first chief security officer, as its field chief information security officer for the public sector. Lohrmann joins Presidio from Security Mentor, where he served as […]

Cyber Deals: Lacework, BlueVoyant, Keyless, Snap Labs.

Van Michael

The world continues to digest the cyber security investments of the bipartisan infrastructure bill and tech continues to move forward. Netography’s concept for the atomized network realizes a substantial early capital influx. Lacework claims it has raised the largest funding round in security industry history. Biometric authentication technology intends to eliminate account takeover.  Numerous outfits prioritize the security […]

Cyber DealS: McAfee, Socure, Contrast Security, SCYTHE.

Van Michael

Cybersecurity venture funding and mergers announced this week. Socure closes Series E funding round at $450 million. Infosec mergers continue full steam ahead.

Cyber Deal Update: IBM, Horizon3.ai, Gryphon Technologies, Micro Focus.

Van Michael

Cybersecurity mergers and venture funding trends this week:. IBM consumes ReaQta to leverage AI security platform. Micro Focus and Celerit Solutions are acquired for their risk management tech.  Wabbi turns away investors at the close of oversubscribed seeding.  SlashNext finds new capital to scale customer acquisition.  Other startups focusing on cloud-native security find interested investors. Funding Viakoo secures $10 million […]