financetom
Business
financetom
/
Business
/
Malicious 3rd party apps leak personal data from Facebook, Twitter
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Malicious 3rd party apps leak personal data from Facebook, Twitter
Nov 28, 2019 1:08 PM

Malicious applications have leaked personal data of Facebook and Twitter users to third party, according to an advisory issued by cyber security watchdog Cert-In without disclosing the impact on Indian subscribers. India is among largest market for Facebook and Twitter.

Share Market Live

NSE

The apps violated Facebook platform policy by installing software in their apps by sending information to two companies-- OneAudience and Mobiburn, the advisory said.

Twitter shared that a software development kit (SDK) developed by OneAudience contains privacy-violating component which may have passed some of its users' personal information like email, username, tweet to OneAudience servers, it added.

"It has been reported that personal data of Facebook and Twitter users were improperly accessed by a pair of malicious SDKs used in certain third-party apps," Cert-in said in the advisory note on November 27.

When contacted Facebook said that security researchers recently notified the company about two bad actors, One Audience and Mobiburn, who were paying developers to use malicious software developer kits (SDKs) in a number of apps available in popular app stores.

"After investigating, we removed the apps from our platform for violating our platform policies and issued cease and desist letters against One Audience and Mobiburn. We plan to notify people whose information we believe was likely shared after they had granted these apps permission to access their profile information like name, email and gender," Facebook spokesperson said.

Twitter said the breach has not happened due to a vulnerability in Twitter's software, but rather the "lack of isolation between SDKs within an application".

"We have evidence that this SDK was used to access people's personal data for at least some Twitter account holders using Android, however, we have no evidence that the iOS version of this malicious SDK targeted people who use Twitter for iOS," Twitter said in a blogpost.

It further said that the microblogging platform has also informed Google and Apple about the malicious SDK so they can take further action if needed.

"We have also informed other industry partners about this issue," Twitter said.

First Published:Nov 28, 2019 10:08 PM IST

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Merck Says European Commission Approves 2 New Indications for Keytruda
Merck Says European Commission Approves 2 New Indications for Keytruda
Nov 2, 2024
09:07 AM EDT, 10/24/2024 (MT Newswires) -- Merck ( MRK ) said Thursday its anti-PD-1 therapy Keytruda has received two new indications in gynecologic cancers from the European Commission. The approvals are for Keytruda in combination with carboplatin and paclitaxel, and in combination with chemoradiotherapy, the company said. The first approval is for the first-line treatment of primary advanced or...
Linde to De-Captivate Air Separation Units, Expand Industrial Gases Supply to Tata Steel
Linde to De-Captivate Air Separation Units, Expand Industrial Gases Supply to Tata Steel
Nov 2, 2024
09:12 AM EDT, 10/24/2024 (MT Newswires) -- Linde ( LIN ) said Thursday it signed agreements to de-captivate two air separation units and expand its existing supply of industrial gases to Tata Steel Limited's iron and steel making facility in India. Linde ( LIN ) said it is acquiring two additional ASUs, which are both under construction and expected to...
Tractor Supply to Acquire Online Pet Pharmacy Allivet
Tractor Supply to Acquire Online Pet Pharmacy Allivet
Nov 2, 2024
09:03 AM EDT, 10/24/2024 (MT Newswires) -- Tractor Supply ( TSCO ) said Thursday it has agreed to acquire Allivet, a private online pet pharmacy. The acquisition will strengthen Tractor Supply's ( TSCO ) offerings for companion animals, equestrian and livestock customers while creating new growth opportunities. The company also said that the acquisition will provide a low-cost pharmacy service...
OSI Systems Fiscal Q1 Earnings, Revenue Gain; Raises FY2025 Outlook
OSI Systems Fiscal Q1 Earnings, Revenue Gain; Raises FY2025 Outlook
Nov 2, 2024
09:04 AM EDT, 10/24/2024 (MT Newswires) -- OSI Systems ( OSIS ) shares were up 9% premarket Thursday after the company reported fiscal Q1 earnings and revenue that beat analysts' expectations and lifted its fiscal-year 2025 guidance. The electronic systems and components manufacturer reported fiscal Q1 adjusted earnings of $1.25 per diluted share, up from $0.91 a year earlier. Analysts...
Copyright 2023-2025 - www.financetom.com All Rights Reserved