AWS, Azure auth keys found in Android and iOS apps used by millions
ID: ce5c977d-b634-56f9-97cf-9d13a4c9f6d0
STIX ID: report--ce5c977d-b634-56f9-97cf-9d13a4c9f6d0
Feed Name: Bleeping Computer
Threat Score
Symantec discovered hardcoded, unencrypted cloud credentials (AWS, Microsoft Azure, Twilio) embedded in the code of multiple popular iOS and Android apps — some with millions of downloads — potentially exposing storage buckets, user data, and source code to unauthorized access; researchers advise using secrets management, encryption, code reviews, and automated scanning to remediate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
