How many web apps do you have on your phone? Probably a ton. Here’s something you likely didn’t know. Based on the latest research from Positive Technologies, nearly half of them (48 percent) are vulnerable to unauthorized access.
As bad as that is, it’s just the tip of the proverbial iceberg.
Here are some additional disturbing stats from their report :
44 percent of the apps with vulnerabilities place the user’s personal data at risk
70 percent are prone to leak critical information stored on the device
96 percent of them contain flaws that would allow any malicious actor to exploit them to launch an attack on the target device
Of those, one in six (17 percent) has a flaw severe enough that it would allow an attacker to assume complete control over the app, and from there, the device itself
The majority of these flaws (some 65 percent) are the result of simple coding errors, with improper configuration of web servers being the most common of these.
There is one bright spot in the otherwise dismal report, though. The percentage of apps with critical vulnerabilities has declined slightly, down from 52 percent last year, and 59 percent the year before. So the numbers, while frustratingly large, are trending in the right direction.
Ed Keary, the CEO of Edgescan had this to say on the topic:
“DevSecOps needs to be embraced such that security is throughout the development pipeline. Application component security management (software components used by developers) is still not commonplace in terms of supporting frameworks and software components and is a common source of vulnerability.”
If your firm designs such applications, pay special attention to this report and review your code base at the earliest opportunity. Even if you don’t, it pays to be mindful of the percentages, because odds are that your employees have several at-risk apps on the devices they’re connecting to your network.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Apple’s Legions of users love FaceTime, but there’s a problem with the highly popular app. It only allows you to see and talk to one person at a time. Apple fans have been clamoring for Group FaceTime for almost as long as the app has existed, and soon, they’ll get their wish.
ZDNet Researcher Ryan Stevenson recently found a big problem on T-Mobile’s website regarding an unprotected API. As a result of the flaw, untold millions of T-Mobile’s customers’ account information was left exposed and completely unprotected. Literally anyone who stumbled across the site and tried to abuse it could access a wide range of customer information with no password required.
If you use Apple products, you may have noticed an annoying “feature”. If you’re using the messaging app on your phone and texting someone and then you move to your Mac and access the same program there, the conversation you were having on your phone isn’t present. The two devices are messaging islands that can’t reliably communicate with each other. Since they can’t, you can’t start a conversation on one device and then pick it up later on another.
Karanbir Singh (a program manager at Microsoft) is on a mission:
Apple promised that its iTunes app would be available on the Microsoft Store by the end of 2017. The announcement was greeted with enthusiasm, but unfortunately, the company didn’t meet their own deadline. They cited the need for more time to build a more robust user experience for Windows users.
The on-again, off-again talks about a merger between T-Mobile and Sprint is definitely back on, with T-Mobile planning to buy Sprint for a staggering $26 billion.
After more than two decades in the business, Apple is officially going to stop selling routers. The writing has been on the wall for a while now, since the company’s “AirPort” family of products hasn’t received a significant update in more than five years.
Owners of Apple devices have a new attack vector to worry about, called “TrustJacking.” Symantec researchers recently stumbled across a pair of scenarios that take advantage of Wi-Fi syncing of various Apple devices. These are scenarios that also take advantage of the trust users have in the security of their own devices, allowing hackers to take complete control over those devices.
If you recently bought a 13-inch MacBook Pro (without a Touch Bar), you’ll want to head to Apple’s website. The company didn’t make a big announcement, but they’ve quietly introduced a battery replacement program that impacted what the company described as a “limited number” of laptops.