Tags: cybersecurity

Widespread Exposure of API Keys Across Thousands of Websites Revealed

Widespread Exposure of API Keys Across Thousands of Websites Revealed Digital Trends
Researchers who scanned millions of webpages discovered that thousands of sites are unintentionally publishing API credentials for major services such as Amazon Web Services, Stripe and OpenAI. The majority of leaks originate from JavaScript files that are publicly accessible, allowing anyone to misuse the keys. The study uncovered 1,748 distinct credentials across nearly 10,000 pages, with some keys remaining exposed for up to a year or longer. Experts say the problem stems from developers embedding private keys in front‑end code, and they recommend live‑site scanning, stricter tool controls and better detection by service providers. Read more

LiteLLM Malware Incident Highlights Compliance Concerns

LiteLLM Malware Incident Highlights Compliance Concerns TechCrunch
An open‑source AI project called LiteLLM was compromised by malware that entered through a software dependency and harvested login credentials. The breach was uncovered by a security researcher after his machine shut down, prompting a rapid investigation with Mandiant. While LiteLLM advertises SOC 2 and ISO 27001 certifications from the compliance startup Delve, the incident raises questions about the effectiveness of such certifications in preventing supply‑chain attacks. Read more