financetom
Business
financetom
/
Business
/
Malicious 3rd party apps leak personal data from Facebook, Twitter
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Malicious 3rd party apps leak personal data from Facebook, Twitter
Nov 28, 2019 1:08 PM

Malicious applications have leaked personal data of Facebook and Twitter users to third party, according to an advisory issued by cyber security watchdog Cert-In without disclosing the impact on Indian subscribers. India is among largest market for Facebook and Twitter.

Share Market Live

NSE

The apps violated Facebook platform policy by installing software in their apps by sending information to two companies-- OneAudience and Mobiburn, the advisory said.

Twitter shared that a software development kit (SDK) developed by OneAudience contains privacy-violating component which may have passed some of its users' personal information like email, username, tweet to OneAudience servers, it added.

"It has been reported that personal data of Facebook and Twitter users were improperly accessed by a pair of malicious SDKs used in certain third-party apps," Cert-in said in the advisory note on November 27.

When contacted Facebook said that security researchers recently notified the company about two bad actors, One Audience and Mobiburn, who were paying developers to use malicious software developer kits (SDKs) in a number of apps available in popular app stores.

"After investigating, we removed the apps from our platform for violating our platform policies and issued cease and desist letters against One Audience and Mobiburn. We plan to notify people whose information we believe was likely shared after they had granted these apps permission to access their profile information like name, email and gender," Facebook spokesperson said.

Twitter said the breach has not happened due to a vulnerability in Twitter's software, but rather the "lack of isolation between SDKs within an application".

"We have evidence that this SDK was used to access people's personal data for at least some Twitter account holders using Android, however, we have no evidence that the iOS version of this malicious SDK targeted people who use Twitter for iOS," Twitter said in a blogpost.

It further said that the microblogging platform has also informed Google and Apple about the malicious SDK so they can take further action if needed.

"We have also informed other industry partners about this issue," Twitter said.

First Published:Nov 28, 2019 10:08 PM IST

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
EXPLAINER-What is helium and why is it used in rockets?
EXPLAINER-What is helium and why is it used in rockets?
Sep 6, 2024
BENGALURU, Sept 7 (Reuters) - Two NASA astronauts aboard Boeing's ( BA ) Starliner will stay on the International Space Station for months because of a faulty propulsion system whose problems included helium leaks. Back on Earth, SpaceX's Polaris Dawn mission has been delayed because of helium issues on ground equipment. Boeing's ( BA ) Starliner spacecraft landed uncrewed in...
Without astronauts, Boeing's Starliner returns to Earth
Without astronauts, Boeing's Starliner returns to Earth
Sep 6, 2024
* Starliner lands in New Mexico desert after troubled mission * NASA astronauts Wilmore and Williams to return on SpaceX vehicle in February 2025 * Boeing's ( BA ) Starliner program faces $1.6 billion in cost overruns since 2016 (Updates after Starliner returns to earth) By Joey Roulette WASHINGTON, Sept 6 (Reuters) - Boeing's ( BA ) Starliner spacecraft landed...
Lawmakers want US to address risks posed by Chinese agriculture drones
Lawmakers want US to address risks posed by Chinese agriculture drones
Sep 6, 2024
WASHINGTON (Reuters) -A dozen Republican U.S. lawmakers urged the Biden administration on Friday to address the use of Chinese-manufactured agriculture drones, saying their use on American farms poses national security risks. The House members, including Representatives Elise Stefanik, Ashley Hinson and John Moolenaar, who chairs a select committee on China, asked the Agriculture Department and Cybersecurity and Infrastructure Security Agency,...
Democrat to vote against bill restricting China's WuXi Biologics, BGI
Democrat to vote against bill restricting China's WuXi Biologics, BGI
Sep 6, 2024
(Reuters) - An influential Democratic U.S. congressman said on Friday that he will vote against legislation that would restrict business with China's WuXi Biologics ( WXIBF ), BGI and other biotech companies on national security grounds. Rep. Jim McGovern of Massachusetts, the ranking member on the House Rules committee, told Reuters he is trying to convince colleagues to join him...
Copyright 2023-2025 - www.financetom.com All Rights Reserved