< ciso
brief />
Tag Banner

All news with #hardcoded secrets tag

39 articles

Expanding Credential Layer: Visibility and Risk

πŸ”’ GitGuardian outlines why the credential layer deserves immediate attention and how detection is the first essential step. The article explains that credential sprawl spans repositories, endpoints, collaboration tools, and AI agents, increasing attack surfaces and making discovery urgent. It highlights research showing rising hardcoded secrets and explains the need for context β€” validity, ownership, permissions, and dependencies β€” to prioritize remediation. The piece argues security teams must connect multiple discovery sources to measure coverage and reduce exposure.
read more β†’

MCP Python SDK flaw risks leaking OAuth credentials

πŸ”’ The official MCP Python SDK had a vulnerability that allowed a malicious MCP server to trick clients into sending OAuth credentials to an attacker-controlled token endpoint. Affected releases exposed the client secret, authorization code, and PKCE proof key; fixes were released in versions 1.30.0 and 2.2.0. The issue impacts clients using specific OAuth providers over HTTP and requires upgrades plus configuration changes to fully mitigate.
read more β†’

Understanding the Risks of Vibe‑Coded Mobile Apps

πŸ”’ Vibe coding lets developers generate apps quickly using AI, but this speed can introduce security and privacy oversights. Common issues include hardcoded secrets, missing input validation, weak encryption, and public-by-default settings that expose user data. Users should vet apps by checking the developer's reputation, permissions requested, privacy policy, security model, and any AI access. If an app is breached, change passwords, enable MFA, revoke connected permissions, and consider uninstalling or factory-resetting compromised devices.
read more β†’

Detecting and Quarantining Exposed AWS IAM Keys

πŸ”Ž This article examines how AWS mitigates publicly exposed IAM access keys through the AWSCompromisedKeyQuarantine managed policy, tracing its evolution across versions and explaining its role in responding to leaked credentials. It details the GitHub secret scanning partnership with AWS, a real-world timeline from a public exposure test, and practical monitoring strategies security teams can use to detect quarantine events in their logging environments. The piece also outlines Palo Alto Networks services that can assist organizations in assessment and incident response.
read more β†’

ThreatsDay: AI Agents, Exposed Services, and Ransomware

πŸ“° This week's ThreatsDay Bulletin tracks diverse attack trends where keys and secrets are repeatedly exposed across AI tools, internet-facing services, old vulnerabilities, and weak credentials. Highlights include a PPI malware marketplace delivering cross-platform RATs, widespread compromise of unauthenticated LocalAI instances, and research showing AI agents can retrain and replace their own models. Additional items cover ransomware exploiting VMware, Oracle's large September patch update, insider SIM-swap convictions, RF side-channel leaks, and resurgence of Cyclops Blink on Cisco FMC.
read more β†’

Compromised AWS Key Exposes Data of UK Charities

πŸ”’ Beacon attributes a cyber-attack to a compromised AWS access key likely exposed in public Javascript build artifacts, allowing an attacker to download CRM data belonging to about 1,500 UK charities. The incident, identified in activity starting on July 27, saw data decrypted during download despite being encrypted at rest. Beacon has reset credentials, found no evidence of persistence, and instructed customers to report the breach to the ICO. Affected charities have been notified, and there is no confirmation that stolen data has been published or misused.
read more β†’

Beacon CRM Breach Impacts Around 1,500 UK Charities

πŸ”’ Around 1500 UK charities may have had personal data accessed after a cyber incident at CRM provider Beacon. The provider says customers should assume all stored data, including attachments, was likely downloaded and has notified all affected organisations. Beacon attributes the breach to a compromised access key, is working with external experts to investigate and has contained the incident, while advising charities on reporting and payment safety steps.
read more β†’

Critical Active Storage flaw risks app secrets

πŸ›‘οΈ Ruby on Rails released patches for a critical Active Storage vulnerability (CVE-2026-66066) that can let unauthenticated attackers read arbitrary files via crafted image uploads. The issue affects applications using libvips for image processing and can expose secrets like secret_key_base, master keys, database credentials, and API tokens. Operators should upgrade Rails and libvips, and rotate any credentials potentially accessible to the Rails process.
read more β†’

Study: 282 iOS Apps Expose LLM API Keys in Traffic

πŸ” Researchers tested 444 iPhone AI chatbot apps and found 282 leaking paid AI access via network traffic, often as plaintext keys, reusable tokens, or unsecured backend relays. The team used a tool called LLMKeyLens to capture credentials without jailbreaking. Only 28% of affected apps were fixed after three months; many tokens remained valid and susceptible to costly misuse.
read more β†’

NAVTOR NavBox hard-coded SOAP credentials fix

πŸ”’ NAVTOR NavBox through version 4.16.1.20 contained hard-coded credentials in its Windows Communication Foundation (SOAP) implementation. If SOAP is enabled, a local attacker could extract those credentials to authenticate to privileged WCF methods and write or overwrite files within application-defined paths, disrupting operations. NAVTOR released a patch in April 2026; versions 4.17.2.6 and later include the fix, and connected NavBox users will be updated automatically.
read more β†’

KnowledgeDeliver zero-day enables web shell installs

πŸ›‘οΈ Mandiant found attackers exploited a critical unauthenticated deserialization flaw (CVE-2026-5426) in KnowledgeDeliver LMS to deliver the Godzilla web shell. The issue stemmed from a shared hardcoded ASP.NET machineKey across customer deployments, allowing signed malicious ViewState payloads and remote code execution. Compromised installations were used to push fake installers, deploy Cobalt Strike beacons, and modify site scripts to load attacker-controlled payloads.
read more β†’

AI Coding Fuels Secrets Sprawl, CISOs Struggle to Contain

πŸ›‘οΈ The rapid rise of AI-assisted and vibe coding is accelerating secrets sprawl, with developers and AI agents increasingly introducing credentials, tokens, and private data into code and collaboration tools. Security researchers from Wiz and independent analysts found a Jan. 28, 2026 Moltbook backend misconfiguration on Supabase that exposed 1.5 million API authentication tokens, tens of thousands of emails, and private messages. Organizations report that detection is outpacing remediation: many teams can find leaks but lack governance and processes to revoke, rotate, and purge secrets at scale. Experts urge treating the issue as identity governance, embedding security into the SDLC, and enforcing short-lived credentials and automated rotation.
read more β†’

MAXHUB Pivot Client Vulnerability Exposes Emails Now

⚠️The MAXHUB Pivot client (versions prior to v1.36.2) contains a vulnerability (CVE-2026-6411) that can expose tenant email addresses and related metadata in cleartext due to a hardcoded AES key embedded in the application. An attacker who obtains the encrypted data can decrypt it, and the product's MQTT enrollment mechanism may be abused to register multiple unauthorized devices, potentially causing denial of service. MAXHUB released v1.36.2 via OTA; update immediately.
read more β†’

LLM-Generated Passwords Are Structurally Predictable

πŸ” Two independent research efforts from Irregular and Kaspersky demonstrate that modern LLMs produce passwords that are structurally predictable and far lower in effective entropy than they appear. Models often repeat the same strings across sessions and conform to human-like patterns that fool standard strength meters. Autonomous coding agents are embedding these credentials into configuration files and repositories, and conventional secret scanners lack the means to detect them. Organizations should audit codebases, rotate suspect credentials, and require explicit use of cryptographically secure RNGs for all generated secrets.
read more β†’

State of Secrets Sprawl 2026: AI-Driven Credential Risk

πŸ”’ GitGuardian's State of Secrets Sprawl 2026 shows leaks accelerated in 2025, uncovering 29 million new hardcoded secrets β€” a 34% year-over-year increase and the largest single-year jump recorded. The report highlights three core trends: AI-driven credential exposures, unexpectedly widespread internal-repo and collaboration-tool leaks, and persistent remediation failures. It urges a shift from detection to continuous non-human identity governance, secrets vaulting, and automated rotation to reduce attacker access.
read more β†’

South Korea NTS Publishes Seed Phrase, Loses $4.8M Crypto

πŸ”‘ South Korea's National Tax Service (NTS) accidentally included a photograph in a press release that exposed a handwritten cryptocurrency mnemonic seed phrase next to a seized Ledger device. Within hours the wallet holding roughly 4 million PRTG tokens (about US $4.8M) was emptied. The NTS removed the release and issued an apology; the incident underscores that publishing a wallet's seed phrase instantly nullifies any cold-storage security.
read more β†’

Korean Tax Service Exposes Wallet Seed, $4.8M Stolen

πŸ”“ South Korea’s National Tax Service inadvertently exposed the mnemonic recovery phrase of a seized Ledger hardware wallet in a press release, enabling an attacker to drain approximately $4.8 million in crypto. The assets were confiscated during raids on 124 high-value tax evaders, but photos released by authorities showed a handwritten seed phrase that was not redacted. On-chain analysis shows the attacker deposited ETH for gas and moved 4 million Pre-Retogeum (PRTG) tokens to a new address in three transactions. The NTS removed the press release, and it is unclear whether a formal investigation has been launched.
read more β†’

Android Mental Health Apps Found with Security Flaws

⚠️ Security researchers found widespread vulnerabilities across ten Android mental-health apps that together exceed 14.7 million installs and could expose highly sensitive therapy and medical data. Oversecured's scans from January 22–23, 2026 identified 1,575 issues β€” 54 high-, 538 medium-, and 983 low-severity β€” which could enable credential interception, HTML injection, spoofing, and location leaks. Findings include use of Intent.parseUri() on external input, plaintext API endpoints and hardcoded Firebase URLs, insecure token generation with java.util.Random, and overly permissive local file access.
read more β†’

Why secrets in JavaScript bundles remain exposed at scale

πŸ” Intruder's research scanned roughly 5 million web applications and identified over 42,000 exposed tokens across 334 secret types, revealing widespread leakage in front-end JavaScript bundles. The report shows how traditional path-and-regex scanners, many SAST tools, and some DAST deployments miss secrets introduced during build and deployment, especially in SPAs. High-impact findings included active GitHub/GitLab personal access tokens, project-management API keys, and hundreds of live webhooks; Intruder developed automated SPA secrets detection to close these gaps.
read more β†’

Leaked Home Depot GitHub Token Exposed Internal Systems

πŸ”“ A security researcher reported that a Home Depot employee accidentally published a private GitHub access token in early 2024, which granted access to private repositories and cloud infrastructure. When tested, the token allowed write permissions to Home Depot repos and access to order fulfillment and inventory systems. The researcher said multiple disclosure emails went unanswered; the token was removed after TechCrunch contacted the company.
read more β†’