News alert: Reflectiz study finds most third-party web apps access sensitive data without justification
ID: 26bd1fa6-670a-520e-b195-bc378648ecdd
STIX ID: report--26bd1fa6-670a-520e-b195-bc378648ecdd
Feed Name: Security Boulevard
Reflectiz’s 2026 State of Web Exposure Research reports a sharp rise in client-side web risks driven by third-party apps and unmanaged integrations: 64% of such apps access sensitive data without valid justification (up from 51%); government sites saw malicious activity surge from 2% to 12.9% and 1 in 7 education sites show active compromise. Common over-permissioned tools include Google Tag Manager (8%), Shopify (5%), and Facebook Pixel (4%); 47% of apps in payment frames are unjustified; compromised sites contact 2.7× more external domains, load 2× more trackers, and use recently registered domains 3.8× more often; Marketing/Digital teams account for 43% of third‑party risk. Only ticketweb.uk met all eight Security Leadership criteria. The full report includes sector risk breakdowns, a list of high-risk apps, trends, technical IOCs, and best-practice controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
