How many web apps do you have on your phone? Probably a ton. Here’s something you likely didn’t know. Based on the latest research from Positive Technologies, nearly half of them (48 percent) are vulnerable to unauthorized access.
As bad as that is, it’s just the tip of the proverbial iceberg.
Here are some additional disturbing stats from their report :
44 percent of the apps with vulnerabilities place the user’s personal data at risk
70 percent are prone to leak critical information stored on the device
96 percent of them contain flaws that would allow any malicious actor to exploit them to launch an attack on the target device
Of those, one in six (17 percent) has a flaw severe enough that it would allow an attacker to assume complete control over the app, and from there, the device itself
The majority of these flaws (some 65 percent) are the result of simple coding errors, with improper configuration of web servers being the most common of these.
There is one bright spot in the otherwise dismal report, though. The percentage of apps with critical vulnerabilities has declined slightly, down from 52 percent last year, and 59 percent the year before. So the numbers, while frustratingly large, are trending in the right direction.
Ed Keary, the CEO of Edgescan had this to say on the topic:
“DevSecOps needs to be embraced such that security is throughout the development pipeline. Application component security management (software components used by developers) is still not commonplace in terms of supporting frameworks and software components and is a common source of vulnerability.”
If your firm designs such applications, pay special attention to this report and review your code base at the earliest opportunity. Even if you don’t, it pays to be mindful of the percentages, because odds are that your employees have several at-risk apps on the devices they’re connecting to your network.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
ZDNet Researcher Ryan Stevenson recently found a big problem on T-Mobile’s website regarding an unprotected API. As a result of the flaw, untold millions of T-Mobile’s customers’ account information was left exposed and completely unprotected. Literally anyone who stumbled across the site and tried to abuse it could access a wide range of customer information with no password required.
Karanbir Singh (a program manager at Microsoft) is on a mission:
The on-again, off-again talks about a merger between T-Mobile and Sprint is definitely back on, with T-Mobile planning to buy Sprint for a staggering $26 billion.
If you are a fan of, and regularly use Goo.gl (the URL shortener service), brace for impact. The company has announced that as of March 30, 2019, the service will be shut down for good. Long before then, beginning April 18th of this year, only existing users will be able to shorten links via goo.gl. No new signups will be allowed.
There’s a new threat on the horizon, according to security researchers from Check Point. A group of hackers in China are busy building a massive botnet that so far, totals almost five million Android smartphones. The hackers are quietly taking control of these devices using a strain of malware known as “RottenSys.”
According to a Microsoft security researcher, a massive malware attack attempted to install a cryptocurrency mining software on more than 400,000 computers in less than twelve hours. The failed campaign is noteworthy because of the attack vector used. It was a supply chain attack implemented by compromising Bittorrent, a highly popular program used to share and download files.
According to a new report published by Spiceworks, nearly 90 percent of businesses will use some type of biometric technology for authentication by the year 2020. In fact, some 62 percent of companies already use biometrics in some form, with another 24 percent stating their intention to do so within the next two years.
Google has another new product out. A slimmed down, streamlined version of the Android OS called “Go.” Unfortunately, it’s release didn’t gather as much press as you’d expect when a new OS is released. The reason for that is simple. The new, slimmer, sleeker Android Go was designed for low-end phones with limited storage capacity, which don’t typically get much press either.
Do you have a Mi-Cam in your home? Even if you don’t have kids, you may have one. They’re a highly popular, inexpensive means of keeping tabs on the comings and goings inside your home when you’re not around.