New Research Exposes Critical Gap: 64% of Third-Party Applications Access Sensitive Data Without Authorization
ID: d746475c-765a-58df-b59b-0865c67da5ce
STIX ID: report--d746475c-765a-58df-b59b-0865c67da5ce
Feed Name: securityonline.info
Reflectiz announced its 2026 State of Web Exposure Research, reporting a sharp rise in client-side risk from third-party web apps: 64% access sensitive data without justification (up from 51%), malicious activity on government sites climbed from 2% to 12.9%, and 1 in 7 education sites show active compromise; commonly implicated tools include Google Tag Manager, Shopify, and Facebook Pixel, while compromised sites contact more external domains, load more trackers, and use newly registered domains more frequently; the study introduces updated Security Leadership Benchmarks (only ticketweb.uk achieved a perfect score) and promises sector breakdowns, high-risk app lists, IOCs, and best-practice controls in the full report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
