- Almost all Enterprise Mobile -Apps come with security risks, experts warn
- Most frequent deficiencies include incorrectly configured sky storage, hard -coded credentials or outdated cryptography
- Zimperium shares its advice on how to remain safe
If your business uses mobile apps, there is a good chance that these apps will delicate sensitive information and put your entire operation at risk of data violations, loss of trust, legislative fines and a whole range of other headaches.
CyberSecurity -Scientists Zimperium analyzed more than 17,000 Enterprise Mobile apps and revealed many carriers such as incorrectly configured cloud storage, hard -coded credentials or outdated cryptography, and although these are not tied to a particular platform, there were significantly more iOS apps -evaluable ( Android).
By breaking down the numbers, the researchers found 83 Android apps with incorrectly configured or otherwise unprotected Sky storage and 10 Android apps with exposed AWS legitimation information.
Spoofing SharePoint
Almost all of the analyzed apps used weak or defective cryptography, and five of the 100 best apps had cryptographic deficiencies with high difficulty. Others, also from the Top 100, had warehouse catalogs exposed to the public.
“Our research found that 88% of all apps and 43% of the 100 best use one or more cryptographic methods that do not follow best practices,” the researchers said. “In some cases – cryptographic deficiencies with high severity.”
To avoid these risks, Zimperium suggests that any company’s mobile device fleet manager gets visibility in app behavior patterns. In this way, they will be able to identify incorrectly configured cloud storage settings, detect exposed credentials and API keys and evaluate cloud service integration security.
In addition, they should validate encryption methods and key management, identify outdated or weak algorithms, assess the security of integrated cloud-SDKs, validate third-party cryptographic implementations and monitor for known vulnerabilities.
“We can’t change apps, but we can choose which apps we allow to secure our data security,” they concluded.