Advertising Software Development Kit (SDK): serving up more than just in-app ads and logging sensitive data. [Research Saturday]
CyberWire Daily19 Des 2020

Advertising Software Development Kit (SDK): serving up more than just in-app ads and logging sensitive data. [Research Saturday]

On August 24, 2020, Snyk announced the discovery of suspicious behaviors in the iOS version of a popular advertising SDK known as Mintegral. At that time, they had confirmed with partners in the advertising attribution space that at minimum, Mintegral appeared to be using this functionality to gather large amounts of data and commit ad attribution fraud. Their research showed that Mintegral was using code obfuscation and method swizzling to modify the functionality of base iOS SDK methods without the application owner’s knowledge. Further, their research proved that Mintegral was logging all HTTP requests including its headers which could even contain authorization tokens or other sensitive data. Since that time Mintegral announced that they were opening the source of their SDK to the market. While the SDK can only be downloaded by registered partners, a major game publisher shared the source code with Snyk for further analysis. They also continued their research by digging deeper into the Android versions of the SDK in which they hadn’t found similar behaviors at the time of the initial disclosure. This has resulted in some significant discoveries that necessitate an update to the previous disclosure. Additionally, Mintegral and the community at large have responded to the situation, and Snyk felt a summary of the events was a good way to finalize their research into this SDK. Joining us on Research Saturday to discuss their research is Snyk's Alyssa Miller. The original blog and Snyk's update can be found here: SourMint: malicious code, ad fraud, and data leak in iOS SourMint: iOS remote code execution, Android findings, and community response

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(3715)

SAFE and sound.

SAFE and sound.

The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights ...

5 Aug 35min

NPM? Not my problem.

NPM? Not my problem.

New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV app...

4 Aug 29min

Water you waiting for?

Water you waiting for?

Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerab...

3 Aug 26min

The hidden risks in space supply chains. [T-Minus: Space-Cyber Briefing]

The hidden risks in space supply chains. [T-Minus: Space-Cyber Briefing]

As the space ecosystem continues to expand, the sector has become increasingly filled with new suppliers, manufacturers, and operators. However, while this development has led to the introduction of n...

2 Aug 19min

Black Hat preview: "Vulnerability Research in the Agentic Age." [Special Edition]

Black Hat preview: "Vulnerability Research in the Agentic Age." [Special Edition]

In this special edition, guest Yan Shoshitaishvili, Associate Professor, University of Arizona, joins host ⁠Dave Bittner⁠ to share a preview of his Black Hat USA 2026 keynote "Vulnerability Research i...

2 Aug 24min

The driver's seat to ransomware. [Research Saturday]

The driver's seat to ransomware. [Research Saturday]

This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable...

1 Aug 23min

Claude outside the lines.

Claude outside the lines.

Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels, an...

31 Jul 30min

Building a great firewall around AI.

Building a great firewall around AI.

China embraces open AI models, then worries it’s become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI super...

30 Jul 25min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
stopp-verden
popradet
rss-gukild-johaug
det-store-bildet
hanna-de-heldige
rss-ness
rss-penger-polser-og-politikk
dine-penger-pengeradet
nokon-ma-ga
aftenpodden-usa
e24-podden
aftenbla-bla
unitedno
frokostshowet-pa-p5
lydartikler-fra-aftenposten
rss-utenrikskomiteen-med-bogen-og-grasvik
bt-dokumentar-2