DEV Community

Cover image for 83% of Financial Apps Ship a CSP That Doesn't Work
OBI EBUKA DAVID
OBI EBUKA DAVID

Posted on

83% of Financial Apps Ship a CSP That Doesn't Work

We scanned 618 public apps from 347 African banks, fintechs and payment companies across 21 countries. One passive request each. No logins, no probing, nobody named.

Half graded C or below.

83% exposed to XSS. 39% with no clickjacking protection on the page customers log in through. 79 running WordPress under a bank brand. 14 on expired certificates today.

It took one afternoon from a laptop.

That is the same view an attacker has of your estate right now. The difference is they are running it with AI, across a whole market, before lunch.

And a third of these institutions publish a public API. Nothing in this report protects that part. No header stops a request that is perfectly well formed and simply should not have been allowed.

The research: https://www.nemesislabs.xyz/state-of-app-security/
Check your own app, free: https://www.nemesislabs.xyz/protect/

Autogon #Omniguard #Nemesis #ApplicationSecurity #Finance #AI

Top comments (0)