News alert: Reflectiz study finds most third-party web apps access sensitive data without justification
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。首先,我得仔细阅读文章,抓住主要信息。 文章主要讲的是Reflectiz发布的2026年网络暴露研究报告。里面提到第三方应用、营销工具和未管理的数字整合导致客户端风险激增。数据方面,64%的第三方应用访问敏感数据而没有正当理由,比去年增加了25%。政府和教育网站的恶意活动也显著增加,分别从2%升到12.9%,教育网站被攻击的比例翻了四倍。 还有提到一些常用工具如Google Tag Manager、Shopify和Facebook Pixel过度授权或部署不当。报告还指出营销部门引入了大部分第三方风险,而IT部门缺乏可见性。最后,报告提供了行业趋势、技术指标和最佳实践。 现在我需要把这些信息浓缩到100字以内。重点包括:研究发现、第三方应用的问题、数据比例、恶意活动的增长、原因以及解决方案建议。 可能的结构是:Reflectiz的研究显示第三方应用访问敏感数据无正当理由增加到64%,政府和教育网站恶意活动上升,原因包括预算限制和人手不足,营销部门引入大部分风险,建议加强治理。 </think> Reflectiz的研究显示,全球网站客户端风险激增,64%的第三方应用访问敏感数据无正当理由。政府和教育网站的恶意活动分别增长至12.9%和四倍。预算限制和人手不足是主要原因。营销部门引入大部分风险,需加强治理与监控。 2026-1-21 20:9:29 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

BOSTON, Jan. 21, 2026, CyberNewswireReflectiz today announced the release of its 2026 State of Web Exposure Research, revealing a sharp escalation in client?side risk across global websites, driven primarily by third?party applications, marketing tools, and unmanaged digital integrations.

According to the new analysis of 4,700 leading websites, 64% of third?party applications now access sensitive data without legitimate business justification, up from 51% last year — a 25% year-over-year spike highlighting a widening governance gap.

The report also exposes a dramatic surge in malicious web activity across critical public?sector infrastructure. Government websites saw malicious activity rise from 2% to 12.9%, while 1 in 7 Education websites now show active compromise, quadrupling year-over-year. Budget constraints and limited manpower were cited as primary obstacles by public?sector security leaders.

The research identifies several widely used third-party tools as top drivers of unjustified sensitive-data exposure, including Google Tag Manager (8%), Shopify (5%), and Facebook Pixel (4%), which were frequently found to be over?permissioned or deployed without adequate scoping.

“Organizations are granting sensitive-data access by default rather than exception — and attackers are exploiting that gap,” said VP of Product at Reflectiz, Simon Arazi. “This year’s data shows that marketing teams continue to introduce the majority of third?party risk, while IT lacks visibility into what’s actually running on the website.”

Key findings include:

•64% of apps accessing sensitive data have no valid justification.

•47% of applications running in payment frames (checkout environments) are unjustified.

•Compromised sites connect to 2.7× more external domains, load 2× more trackers, and use recently registered domains 3.8× more often than clean sites.

•Marketing and Digital departments account for 43% of all third-party risk

The report also introduces updated Security Leadership Benchmarks, highlighting the very small group of organizations meeting all eight criteria. Only one website — ticketweb.uk — achieved a perfect score across the framework.

The 2026 report includes:

•Sector-by-sector breakdowns of web exposure risk

•Full list of high-risk third-party applications

•Year-over-year industry trends

•Technical indicators of compromise

•Best-practice controls for security and digital teams

The complete 43-page analysis is available for download:

https://www.reflectiz.com/learning-hub/web-exposure-2026-research/

About Reflectiz:

Reflectiz empowers organizations to secure their websites and digital assets against modern web threats. Its award-winning, agentless platform provides continuous visibility into all client-side activity, detecting and prioritizing security, privacy and compliance risks. Reflectiz is trusted by global enterprises across financial services, e-commerce, and healthcare to protect their data, users, and brand reputation.

Media contact: Daniel Sharabi, VP Marketing, Reflectiz, [email protected]

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization

January 21st, 2026 | News Alerts | Top Stories

*** This is a Security Bloggers Network syndicated blog from The Last Watchdog authored by cybernewswire. Read the original post at: https://www.lastwatchdog.com/news-alert-reflectiz-study-finds-most-third-party-web-apps-access-sensitive-data-without-justification/


文章来源: https://securityboulevard.com/2026/01/news-alert-reflectiz-study-finds-most-third-party-web-apps-access-sensitive-data-without-justification/
如有侵权请联系:admin#unsafe.sh