Advertising Software Development Kit (SDK): serving up more than just in-app ads and logging sensitive data. [Research Saturday]
CyberWire Daily19 Dec 2020

Advertising Software Development Kit (SDK): serving up more than just in-app ads and logging sensitive data. [Research Saturday]

On August 24, 2020, Snyk announced the discovery of suspicious behaviors in the iOS version of a popular advertising SDK known as Mintegral. At that time, they had confirmed with partners in the advertising attribution space that at minimum, Mintegral appeared to be using this functionality to gather large amounts of data and commit ad attribution fraud. Their research showed that Mintegral was using code obfuscation and method swizzling to modify the functionality of base iOS SDK methods without the application owner’s knowledge. Further, their research proved that Mintegral was logging all HTTP requests including its headers which could even contain authorization tokens or other sensitive data. Since that time Mintegral announced that they were opening the source of their SDK to the market. While the SDK can only be downloaded by registered partners, a major game publisher shared the source code with Snyk for further analysis. They also continued their research by digging deeper into the Android versions of the SDK in which they hadn’t found similar behaviors at the time of the initial disclosure. This has resulted in some significant discoveries that necessitate an update to the previous disclosure. Additionally, Mintegral and the community at large have responded to the situation, and Snyk felt a summary of the events was a good way to finalize their research into this SDK. Joining us on Research Saturday to discuss their research is Snyk's Alyssa Miller. The original blog and Snyk's update can be found here: SourMint: malicious code, ad fraud, and data leak in iOS SourMint: iOS remote code execution, Android findings, and community response

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(3716)

AI without adult supervision.

AI without adult supervision.

Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce ne...

6 Aug 25min

SAFE and sound.

SAFE and sound.

The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights ...

5 Aug 35min

NPM? Not my problem.

NPM? Not my problem.

New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV app...

4 Aug 29min

Water you waiting for?

Water you waiting for?

Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerab...

3 Aug 26min

The hidden risks in space supply chains. [T-Minus: Space-Cyber Briefing]

The hidden risks in space supply chains. [T-Minus: Space-Cyber Briefing]

As the space ecosystem continues to expand, the sector has become increasingly filled with new suppliers, manufacturers, and operators. However, while this development has led to the introduction of n...

2 Aug 19min

Black Hat preview: "Vulnerability Research in the Agentic Age." [Special Edition]

Black Hat preview: "Vulnerability Research in the Agentic Age." [Special Edition]

In this special edition, guest Yan Shoshitaishvili, Associate Professor, University of Arizona, joins host ⁠Dave Bittner⁠ to share a preview of his Black Hat USA 2026 keynote "Vulnerability Research i...

2 Aug 24min

The driver's seat to ransomware. [Research Saturday]

The driver's seat to ransomware. [Research Saturday]

This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable...

1 Aug 23min

Claude outside the lines.

Claude outside the lines.

Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels, an...

31 Juli 30min

Populärt inom Politik & nyheter

svenska-fall
p3-krim
aftonbladet-daily
aftonbladet-krim
rss-sanning-konsekvens
rss-krimstad
flashback-forever
rss-krimreportrarna
tv4-nyheterna-story
rss-vad-fan-hande
mannen-utan-spar
motiv
de-fyras-gang
rss-flodet
spar
politiken
rss-aftonbladet-krim
rss-frandfors-horna
rss-svalan-krim
olyckan-inifran