CloudSEK’s Attack Surface Monitoring Platform has uncovered 3,207 apps that are leaking Twitter application programming interface (API) keys, which can be used to access or to take over Twitter accounts.That news comes via a new report, "How Leaked Twitter API’s Can Be Used to Build a Bot Army," from CloudSEK, a contextual artificial intelligence company that predicts cyberthreats.
230 Apps Can Take Over Twitter Accounts
According to the CloudSEK report:- The CloudSEK Attack Surface Monitoring Platform discovered 3207 apps were leaking valid Consumer Key and Consumer Secret.
- 230 apps, some of which are unicorns, can be used to fully take over their Twitter Accounts to perform critical/sensitive actions, such as:
- Read Direct Messages
- Retweet
- Like
- Delete
- Remove followers
- Follow any account
- Get account settings
- Change display picture