New Research Exposes Critical Gap: 64% of Third-Party Applications Access Sensitive Data Without Authorization
ID: 626441d8-2ffd-5395-86eb-3487556e479e
STIX ID: report--626441d8-2ffd-5395-86eb-3487556e479e
Feed Name: HackRead
Reflectiz’s 2026 State of Web Exposure Research highlights escalating client-side risk across 4,700 websites, with 64% of third-party apps accessing sensitive data without valid justification and a sharp public-sector surge in malicious activity (government: 2%→12.9%; education: 1 in 7 compromised). The report identifies over-permissioned marketing and commerce tools (e.g., Google Tag Manager 8%, Shopify 5%, Facebook Pixel 4%) as key drivers and notes that compromised sites connect to 2.7× more external domains, load 2× more trackers, and use recently registered domains 3.8× more often. It includes sector risk breakdowns, a list of high-risk apps, year-over-year trends, technical indicators of compromise, and best-practice controls, with only ticketweb.uk meeting all eight Security Leadership Benchmark criteria.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
