logo

New Research Exposes Critical Gap: 64% of Third-Party Applications Access Sensitive Data Without Authorization

ID: 626441d8-2ffd-5395-86eb-3487556e479e

STIX ID: report--626441d8-2ffd-5395-86eb-3487556e479e

Feed Name: HackRead

Date Published: 2026-01-21

Date Updated: 2026-04-22

Author: CyberNewswire

...
...

Reflectiz’s 2026 State of Web Exposure Research highlights escalating client-side risk across 4,700 websites, with 64% of third-party apps accessing sensitive data without valid justification and a sharp public-sector surge in malicious activity (government: 2%→12.9%; education: 1 in 7 compromised). The report identifies over-permissioned marketing and commerce tools (e.g., Google Tag Manager 8%, Shopify 5%, Facebook Pixel 4%) as key drivers and notes that compromised sites connect to 2.7× more external domains, load 2× more trackers, and use recently registered domains 3.8× more often. It includes sector risk breakdowns, a list of high-risk apps, year-over-year trends, technical indicators of compromise, and best-practice controls, with only ticketweb.uk meeting all eight Security Leadership Benchmark criteria.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.