Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research …
First seen on helpnetsecurity.com
Jump to article: www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/
![]()

