Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
One in Eight Apps Marketed to US Troops Contains Chinese or Russian Code, Researchers Find

Researchers at Purdue University, the US Military Academy at West Point, and Florida International University examined more than 220 mobile apps marketed specifically to US military personnel. More than one in eight contained code built by companies based in China, Russia, or other foreign countries flagged as national security risks, according to Wired.
One app used by troops to rate living conditions on their own bases contained code from Huawei, the Chinese telecom giant that US regulators formally designated a national security threat in 2020. Two other apps were built by Russian firms and used the Russian ad service Yandex, Wired reported.
Joshua Shinkle, a Purdue PhD researcher and the study's lead author, said the goal was practical, not alarmist. "We hope the research helps military-affiliated personnel, developers, and platforms make more informed privacy decisions and encourages continued discussion with developers, platforms, and policymakers about how to address these gaps," Shinkle said.
This Isn't a New Problem
The pattern goes back years. Reuters uncovered in 2022 that Pushwoosh, a company offering push-notification and analytics code to app developers, had spent years disguising itself as a US firm. Pushwoosh claimed addresses in Washington, DC, and Maryland across its social media and eight annual Delaware regulatory filings, according to PCMag. Its actual headquarters sits in Novosibirsk, Siberia, with about 40 employees and roughly $2.4 million in annual revenue.
Pushwoosh code turned up in an Army app used at the National Training Center at Fort Irwin, California, and in multiple public-facing apps run by the Centers for Disease Control and Prevention, which told Reuters it believed Pushwoosh was a US company before pulling the code, according to PCMag. Pushwoosh's code was also embedded, via third-party developers, in apps for Unilever and UEFA.
The Army's response is worth stating plainly. It complicates the scarier version of this story. Army spokesperson Bryce Dubee told C4ISRNET and Army Times that the National Training Center app harvested no data from the roughly 1,000 people who downloaded it. Dubee said the push-notification feature containing Pushwoosh's code was never activated, the app never connected to the Army network, and there was no "operational loss of data." The Army discontinued the app in 2019 for unrelated personnel and maintenance reasons and formally killed it afterward once it was found to be out of compliance and no longer updatable.
Pushwoosh founder Max Konev told Reuters his company "has no connection with the Russian government of any kind" and that data is stored in the US or Germany. Legal experts told Reuters that's not the whole risk calculus. Because Pushwoosh is a Russian-registered company subject to Russian law, cybersecurity experts said Moscow's intelligence services could compel it to hand over data regardless of where servers physically sit.
The Password Manager Problem
A separate investigation by OCCRP and partners, reported by VSquare, found a Spain-based password manager called Passwork used by European government agencies and universities, including Irish government bodies and the Dresden University of Technology, was built by two Russian co-founders who still control a UAE-based firm supplying software updates to the European product. Corporate records show the same founders own a Russian company, Passwork LLC, which is certified by Russia's Federal Service for Technical and Export Control, a Ministry of Defense agency, and by the FSB. None of the European clients OCCRP contacted knew the Russian counterpart existed.
Alessandra Chirico, an EU regulation and cybersecurity policy expert, told OCCRP that transparency isn't optional in this line of work. "The stronger the narrative of trust, the greater the corresponding duty of transparency required to sustain it," Chirico said.
Why This Keeps Happening
The common thread across all four cases is that the app and ad-tech supply chain isn't set up to flag foreign ownership. Developers grab free or cheap third-party code for push notifications, analytics, or ad targeting without vetting who built it. The Army's Fort Irwin office didn't know Pushwoosh existed, let alone that it was Russian-owned, according to Dubee.
That gap has real consequences beyond app stores. Central Command told Senator Ron Wyden in an April letter that it had received multiple threat reports of adversaries exploiting commercial location data to track American personnel in the Middle East, where US forces remain in a standoff with Iran over the Strait of Hormuz, according to Wired. Lawmakers called it the first official Pentagon confirmation that troops in an active war zone were being targeted through the commercial data-broker economy, a risk researchers and contractors had been warning about for close to a decade.
Dubee said the National Training Center app "would not have been approved today" given tighter cybersecurity rules now governing free versus paid software. That's a fair point. It doesn't answer the harder question the Purdue-led study raises: with 220-plus apps checked and one in eight already flagged, how many more are still live on troops' phones right now, and who's actually auditing them.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.