We scanned 618 public apps from 347 African banks, fintechs and payment companies across 21 countries. One passive request each. No logins, no probing, nobody named.
Half graded C or below.
83% exposed to XSS. 39% with no clickjacking protection on the page customers log in through. 79 running WordPress under a bank brand. 14 on expired certificates today.
It took one afternoon from a laptop.
That is the same view an attacker has of your estate right now. The difference is they are running it with AI, across a whole market, before lunch.
And a third of these institutions publish a public API. Nothing in this report protects that part. No header stops a request that is perfectly well formed and simply should not have been allowed.
The research: https://www.nemesislabs.xyz/state-of-app-security/
Check your own app, free: https://www.nemesislabs.xyz/protect/
Top comments (0)