logo

New Research Exposes Critical Gap: 64% of Third-Party Applications Access Sensitive Data Without Authorization

ID: 63b8c503-7ecb-5dcf-93d0-dbaa7eee732c

STIX ID: report--63b8c503-7ecb-5dcf-93d0-dbaa7eee732c

Feed Name: Security Boulevard

Date Published: 2026-01-21

Date Updated: 2026-04-22

Author: cybernewswire

...
...

Reflectiz announced its 2026 State of Web Exposure Research, analyzing 4,700 websites and reporting a sharp rise in client-side risk driven by third-party apps and marketing tools, with 64% of such apps accessing sensitive data without valid justification; malicious activity on government sites jumped from 2% to 12.9% and one in seven education sites show active compromise, while tools like Google Tag Manager (8%), Shopify (5%), and Facebook Pixel (4%) are key drivers of unjustified exposure; compromised sites exhibit more external connections, trackers, and recently registered domains, marketing/digital teams account for 43% of third-party risk, and only ticketweb.uk met all eight security leadership benchmarks; the full report offers sector breakdowns, a list of high-risk apps, trends, technical IOCs, and best-practice controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.