By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Confluence News - Breaking News, Latest News and VideosConfluence News - Breaking News, Latest News and Videos
Notification Show More
Latest News
Did investors learn nothing from last year’s market meltdown?
Uncategorized
Larry Summers: More likely the Fed can pull off a soft landing, but don’t get hopes up
Uncategorized
Japan’s workers haven’t had a raise in 30 years. Companies are under pressure to pay up
Uncategorized
Foxconn January sales hit record high after production restored at world’s biggest iPhone factory
Uncategorized
Chinese savers stashed away $2.6 trillion last year but property crash will cool ‘revenge spending’
Uncategorized
Aa
  • Home
  • Politics
  • Business
  • LifeStyle
  • Sports
  • Entertainment
  • Health
  • Tech
Reading: Hundreds of iOS apps could be leaking AWS credentials
Share
Aa
Confluence News - Breaking News, Latest News and VideosConfluence News - Breaking News, Latest News and Videos
  • ES Money
  • U.K News
  • Entertainment
  • Science
  • Technology
  • Insider
Search
  • Home
  • Politics
  • Business
  • Sports
  • Entertainment
  • Health
  • Life Style
  • Tech
Have an existing account? Sign In
Follow US
Confluence News - Breaking News, Latest News and Videos > Blog > Tech > Hundreds of iOS apps could be leaking AWS credentials
Tech

Hundreds of iOS apps could be leaking AWS credentials

Last updated: 2022/09/02 at 3:53 PM
Share
SHARE

Hundreds of mobile apps have been found to be leaking Amazon Web Services (AWS) credentials.

A recent Symantec analysis identified 1,859 publicly available apps, 98% of which are iOS apps, containing hard-coded AWS credentials that could be putting your data at risk.

The company found over three-quarters (77%) of the apps contained valid AWS access tokens allowing access to private AWS cloud services, and nearly half (47%) contained valid AWS tokens that also gave full access to numerous, often millions, of private files via the Amazon Simple Storage Service (Amazon S3).

AWS passwords leaks

Some of the reasons for vulnerabilities, says security researcher Kevin Watkins, include the unbeknown use of vulnerable external software libraries and SDKs, the outsourcing of app development, and cross-team collaboration which could present numerous opportunities for missing information and ineffective communication.

> Here’s the best endpoint protection software

> AWS is upping its security and malware protection

> Malicious Python packages dump your AWS secrets online 

The analysis highlights three real-world examples of affected companies. The first, an unnamed B2B company that provides an intranet and communications platform, had provided a mobile SDK to its customers that exposed the company’s cloud infrastructure keys, exposing things like financial records and private data. 

The second example cites a number of iOS banking apps that had outsourced the digital ID and authentication component of their respective apps. Affected users of this SDK had their personal data exposed, including names and dates of birth. Furthermore, over 300,000 biometric digital fingerprints were leaked by five banking apps.

Finally, a hospitality and entertainment company that had teamed up with another company to share its technology platform was found to be exposing business and customer data from a library that was being used by 16 different apps.

The research findings have been shared with the companies involved, however it’s not yet known if the issues have been ironed out with immediate effect.

Stay safe with our pick of the best firewall tools around

Via Bleeping Computer

 

You Might Also Like

Bing and ChatGPT might be the future of search, even if Google doesn’t believe it

Google expanding SafeSearch by blurring explicit images by default

It turns out lots of us still want to use tablets at

Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times

September 2, 2022
Share this Article
Facebook Twitter Email Print
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Social Medias
Facebook Like
Twitter Follow
Youtube Subscribe
Telegram Follow

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!

[mc4wp_form]
Popular News

US opposes Al Jazeera’s push to take the Abu Akleh case to ICC

December 6, 2022
Somalia claims capture of key port town from al-Shabab
Bank of England economist criticises government interaction with ‘other institutions’
Retired general: Russia accusing Ukraine of planning a ‘dirty bomb’ could be a warning CNN.com – RSS Channel – HP Hero
2022 World Series: Astros-Phillies Game 3 postponed due to rain in Philadelphia
- Advertisement -
Ad imageAd image
Global Coronavirus Cases

Confirmed

0

Death

0

More Information:Covid-19 Statistics

Categories

  • ES Money
  • Insider
  • Science
  • Technology
  • LifeStyle

About US

We influence 20 million users and is the number one business and technology news network on the planet.
Quick Link
  • Economy
  • Politics
  • Life Style
  • Contact Us
Top Categories
  • Business
  • Tech
  • Top
  • Health
  • Entertainment

Subscribe US

Subscribe to our newsletter to get our newest articles instantly!

© confluencenews. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?