logo

New Research Exposes Critical Gap: 64% of Third-Party Applications Access Sensitive Data Without Authorization

ID: 274665de-b6d4-5e73-b2bc-539f0c0a4bc7

STIX ID: report--274665de-b6d4-5e73-b2bc-539f0c0a4bc7

Feed Name: cybersecurityNews.com

Date Published: 2026-01-21

Date Updated: 2026-04-21

Author: Cybernewswire

...
...

**Reflectiz** released its 2026 State of Web Exposure Research, finding a significant rise in client‑side risk: 64% of third‑party apps access sensitive data without valid justification, public‑sector malicious activity jumped from 2% to 12.9%, and 1 in 7 education sites show active compromise. The study attributes much of the exposure to over‑permissioned marketing and third‑party tools (e.g., Google Tag Manager, Shopify, Facebook Pixel), and notes compromised sites exhibit more external connections, trackers, and recently registered domains. The 43‑page report offers sector breakdowns, a list of high‑risk applications, technical indicators of compromise, and best‑practice guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.