TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Digital fraud in the pandemic world

    August 8, 2022

    Nvidia Q2 gaming revenue falls short of 2021’s mark by over a billion dollars

    August 8, 2022

    Greek prime minister ‘unaware’ opposition politician’s phone was bugged

    August 8, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Nvidia Q2 gaming revenue falls short of 2021’s mark by over a billion dollars

      August 8, 2022

      99 percent of Netflix subscribers haven’t tried its games yet

      August 8, 2022

      How to start experimenting with Google Lens

      August 8, 2022

      Leaked video shows DJI’s rumored cinewhoop FPV drone in action

      August 8, 2022

      Google sues Sonos over smart speaker and voice control tech

      August 8, 2022
    • Business
    • Cyber Security

      Deepfakes, cyber extortion, API attacks and other emerging cyber threats

      August 8, 2022

      The top identity-based attacks and how to stop them

      August 8, 2022

      Top malware strains observed in 2021

      August 5, 2022

      $9 million research grant targets software supply chain security

      August 5, 2022

      Annette Southgate named Director of Security at Cranfield University

      August 5, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»3207 apps are leaking Twitter API keys
    Cyber Security

    3207 apps are leaking Twitter API keys

    August 3, 2022Updated:August 3, 2022No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers at CloudSEK have uncovered a set of 3,207 mobile apps exposing Twitter API keys to the public, potentially enabling a threat actor to take over users’ Twitter accounts. 

    CloudSEK analyzed large app sets for potential data leaks and found the apps leaking a valid Consumer Key and Consumer Secret for the Twitter API. CloudSEK found that 230 apps were leaking all 4 Auth Creds and can be used to fully take over Twitter accounts to perform critical/sensitive actions such as read direct messages, retweet, like, delete, remove followers, follow any account, get account settings and change display pictures.

    Scott Gerlach, Co-Founder and CSO at StackHawk, says, “Exposing an ‘all access’ API key is essentially giving away the keys to the front door as a single key controls all of the data in the API. You have to understand how to manage user access to an API and how to securely provision access to the API. If you don’t understand that, you have put yourself way behind the eight ball.”

    This type of vulnerability is one of the easiest to prevent, says Ray Kelly, Fellow at Synopsys Software Integrity Group. “When assessing a mobile app for security gaps, it is important to test the backend server, the network layer and in this case, the device itself. Failure to encrypt API secrets on the device is akin to wrapping your ATM card in a Post-It note with your PIN written on it,” Kelly explains. “However, in this case, the consequences are much more severe and could lead to attackers executing misinformation campaigns or impersonation attacks that can be targeted to specific Twitter users.”

    CloudSEK urged developers to conduct standardized code reviews, ensure files containing “environment variables” in the source code are not included, and rotate API keys. 

    For more information, visit cloudsek.com.

    API keys cyber security risk management Twitter Security
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Deepfakes, cyber extortion, API attacks and other emerging cyber threats

    August 8, 2022 Cyber Security

    The top identity-based attacks and how to stop them

    August 8, 2022 Cyber Security

    Top malware strains observed in 2021

    August 5, 2022 Cyber Security

    $9 million research grant targets software supply chain security

    August 5, 2022 Cyber Security

    Annette Southgate named Director of Security at Cranfield University

    August 5, 2022 Cyber Security

    The rise of phygital attacks on critical infrastructure — and how to stop them

    August 5, 2022 Cyber Security
    Editors Picks

    Nvidia Q2 gaming revenue falls short of 2021’s mark by over a billion dollars

    August 8, 2022

    Greek prime minister ‘unaware’ opposition politician’s phone was bugged

    August 8, 2022

    Deepfakes, cyber extortion, API attacks and other emerging cyber threats

    August 8, 2022

    99 percent of Netflix subscribers haven’t tried its games yet

    August 8, 2022
    Trending Now

    SoftBank/Son: downhill march proves painful for Grand Old Duke of Tech

    By techbizweb

    Leaked video shows DJI’s rumored cinewhoop FPV drone in action

    By techbizweb

    Crypto Downturn Hits Luxury Watches Market Sales

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2022 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.