discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Apps Marketed to US Troops Are Shipping Chinese and Russian Code

A recent study found that over one in eight mobile apps marketed to US military personnel contain software built by companies in China, Russia, or other foreign nations, raising concerns about data harvesting and national security.

By Joshua Shinkle, a Purdue University PhD researcher·Jul 20·wired.com·3 min read

Intelligence analysis by Llama

Apps Marketed to US Troops Are Shipping Chinese and Russian Code
Image: wired.com

Researchers at Purdue University, the US Military Academy at West Point, and Florida International University examined hundreds of mobile apps marketed to US military personnel and found that nearly two-thirds contained third-party code, including code from China, Russia, and other foreign nations. This code can track user behavior, including locations, and share that information with…

Why it matters

The study highlights the risks of data harvesting and national security threats posed by mobile apps marketed to US military personnel, and underscores the need for greater transparency and regulation in the advertising industry.

Imagine you're a soldier, and you download an app to help you rate living conditions on your base. But what if that app is secretly sending your location and other information to a company in China or Russia? That's what happened with over one in eight mobile apps marketed to US military personnel, according to a recent study. The apps contained software built by companies in foreign nations, which can track user behavior and share that information with outside companies. This raises concerns about data harvesting and national security.

Analysis

A $60B Vote of Confidence

The study's findings are a stark reminder of the risks posed by the largely unregulated advertising industry that tracks Americans online. Despite evidence that exposure can reveal troop deployments, unit movements, and the routines of personnel within intelligence facilities and hardened shelters, the industry continues to treat civilians and service members mostly the same, unless there is profit in telling them apart. The stakes are no longer hypothetical, as the US Central Command acknowledged in a letter to Senator Ron Wyden that it had received multiple threat reports of adversaries exploiting commercial location data to target or surveil American personnel in the Middle East.

Why Cursor?

The researchers examined more than 220 mobile apps marketed to US military personnel, pulled from the Google Play store and military subreddits. Nearly two-thirds of these apps contained third-party code, known as SDKs, which can track user behavior, including locations, and share that information with outside companies. Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings. The most common SDKs came from Google and Facebook, the two companies that dominate US digital advertising. But 76 turned up in all, including code traced back to China, Russia, Israel, India, Germany, and others.

The Road Ahead

The study's findings have significant implications for the Pentagon and the advertising industry. The researchers observed no data actually going to Huawei servers, but an SDK can be updated remotely at any time. Code that is dormant today can still be spyware tomorrow. In at least one case, noted by the study, the Huawei code arrived without the app's developer's knowledge, smuggled in as a dependency in a commercial notification tool. The researchers also surveyed 103 military-affiliated Americans about the data practices they encountered on their own phones. More than 83 percent used at least one app engaging in data practices they said made them uncomfortable.

Key points

  • Over one in eight mobile apps marketed to US military personnel contain software built by companies in China, Russia, or other foreign nations.
  • Nearly two-thirds of these apps contained third-party code, known as SDKs, which can track user behavior, including locations, and share that information with outside companies.
  • Forty percent of the apps collected or shared more data than they disclosed in their Google or Apple store listings.
  • The most common SDKs came from Google and Facebook, the two companies that dominate US digital advertising.
  • The study's findings have significant implications for the Pentagon and the advertising industry.
The Upside

The study's findings could lead to greater transparency and regulation in the advertising industry, which could help protect the data of US military personnel and civilians. Additionally, the researchers' recommendations for mitigations, such as in-phone warnings and stricter bans on foreign code in military-marketed apps, could be implemented to reduce the risks posed by these apps.

The Downside

The study's findings highlight the ongoing risks posed by the largely unregulated advertising industry, which continues to track Americans online and share their data with outside companies. The stakes are high, as the study's findings could be used by adversary governments to harvest data revealing where service members live, work, and deploy.

Originally reported at

wired.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritydata harvestingnational securityadvertising industrymilitary personnel

Author

Joshua Shinkle, a Purdue University PhD researcher

Intelligence analysis by

Llama

Published

Jul 20, 2026

Source

wired.com

Share

Topics

securitydata harvestingnational securityadvertising industrymilitary personnel

Related

More from this desk

Jul 20·schneier.com

On Flock License Plate Tracking Cameras

A writer was mistakenly identified, tracked, and arrested using data from Flock cameras due to a misread license plate number. The incident highlights the potential for errors in AI-powered surveillance systems.

Jul 20·bleepingcomputer.com

Microsoft Confirms Windows Server Update Services Sync Delays

Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. WSUS was introduced almost twenty years ago to help IT administrators schedule updates for Microsoft products…

Jul 20·bleepingcomputer.com

Microsoft Fixes Windows Bug Causing Some Dell PCs to Shut Down

Microsoft has released emergency updates to fix a known issue causing some Dell PCs to experience performance issues or shut down after installing the July 2026 Windows 11 security updates.

Jul 20·wired.com

The ACLU Is Arming Lawyers to Expose State Surveillance Secrets

The American Civil Liberties Union of Massachusetts is releasing an online toolkit for criminal defense attorneys to uncover whether police used surveillance technologies in secret. The toolkit includes handcrafted legal motions that force prosecutors to reveal whether su…