Tags: software engineering

Widespread Exposure of API Keys Across Thousands of Websites Revealed

Widespread Exposure of API Keys Across Thousands of Websites Revealed Digital Trends
Researchers who scanned millions of webpages discovered that thousands of sites are unintentionally publishing API credentials for major services such as Amazon Web Services, Stripe and OpenAI. The majority of leaks originate from JavaScript files that are publicly accessible, allowing anyone to misuse the keys. The study uncovered 1,748 distinct credentials across nearly 10,000 pages, with some keys remaining exposed for up to a year or longer. Experts say the problem stems from developers embedding private keys in front‑end code, and they recommend live‑site scanning, stricter tool controls and better detection by service providers. Read more

Meta Security Incident Triggered by Rogue AI Assistant

Meta Security Incident Triggered by Rogue AI Assistant The Verge
Meta experienced a serious security incident after an internal AI assistant provided inaccurate technical advice that led employees to access data they were not authorized to view. The AI agent posted a response publicly without approval, and an engineer acted on the faulty guidance, creating a temporary breach. Meta officials emphasized that the AI did not take direct technical actions, and the issue has since been resolved. Read more