Tag: api
-
AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated container registry exposed to the internet. The registry contained the attackers’ entire toolchain…
-
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
Tags: adobe, api, attack, cisa, control, cve, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.The vulnerabilities are listed below – CVE-2026-5430 (CVS score: 9.8) – A path traversal vulnerability in WSO2 API Control Plane, First…
-
AI Drives Surge in Bot and API Threats
Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-drives-surge-in-bot-and-api/
-
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds harvest browser data, password-manager and 2FA-extension artifacts, cryptocurrency-wallet files, application credentials, and AI assistant credential folders, potentially exposing…
-
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds harvest browser data, password-manager and 2FA-extension artifacts, cryptocurrency-wallet files, application credentials, and AI assistant credential folders, potentially exposing…
-
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco’s Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues
-
API-Key geleakt: Plötzlich Malware über 100.000 Websites verbreitet
Angreifer sind an einen API-Schlüssel von Brevo gelangt. Dieser hat mit einem Schlag Clickfix-Attacken über mehr als 100.000 Websites ermöglicht. First seen on golem.de Jump to article: www.golem.de/news/api-key-geleakt-ploetzlich-malware-ueber-100-000-websites-verbreitet-2609-213201.html
-
WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST API functionality, comments, XML-RPC, and plugin management. Site administrators are strongly urged to update immediately due to the potential impacts of stored cross-site scripting, authenticated path traversal, authorization bypasses, and information disclosure flaws. This release…
-
Hardcoded MCP credentials found in public GitHub files
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/
-
OpenAI Reveals AI Models Concealing Mistakes, Using Exposed API Keys and Sharing Files
OpenAI has introduced a new framework for reporting model misalignment after discovering instances where its AI systems concealed mistakes, accessed exposed API keys, fabricated data, uploaded files without authorization, and communicated through unintended channels. The company released six initial reports detailing behaviors observed during model training and evaluation. They argue that AI developers need more…
-
Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/
-
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.”This vulnerability is due to insufficient authentication control on an API endpoint,” Cisco said. “An attacker First seen on thehackernews.com…
-
Salt Security expands CrowdStrike integration to tackle AI agent security
Salt Security has expanded its integration with CrowdStrike to give security teams greater visibility into how AI agents connect to enterprise systems, use APIs and exercise their permissions. The expanded partnership brings together Salt’s Agentic API platform with CrowdStrike Falcon Foundry, Falcon Next-Gen SIEM and Falcon Firewall Management. According to the companies, the integration is designed…
-
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
Tags: api, authentication, backup, cisa, cisco, cve, cybersecurity, exploit, flaw, google, identity, infrastructure, kev, service, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, CiscoISE, and Google Pixelflaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw…
-
One runaway AI agent racked up a $50,000 cloud bill
Organizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud environments. At the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/google-mandiant-enterprise-ai-security-risks-report/
-
NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery
The National Institute of Standards and Technology (NIST) has published new implementation guidance to safeguard identity tokens, access tokens, and assertions used in single sign-on, cloud federation, and application programming interface (API) environments. Released on September 15, 2026, NIST Internal Report 8587, titled >>Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for…
-
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr.The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw.”JWT…
-
SaaS API Security Incidents: What 2026 Breach Data Shows
Key TakeawaysAn analysis of 60 disclosed API breaches in 2025 found broken authentication caused 52 percent of incidents, with unsafe consumption of third party APIs accounting for another 27 percent.SaaS companies accounted for 8 percent of breaches in that same… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/saas-api-security-incidents-what-2026-breach-data-shows/
-
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress has announced it’s launching an automated security review for every release of a plugin before it’s distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved.”New plugins are reviewed before they enter the directory, but updates ship continuously after that,” David Perez,…
-
What is API Penetration Testing?
If your business uses any app or third-party integration, then chances are it’s held together by APIs. APIs, in a nutshell, are the invisible connections that allow your systems to talk to one another by transferring data. They have become… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/what-is-api-penetration-testing/
-
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read Exploited Within 24 Hours
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request…
-
OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem’s documentation build process to execute code remotely and attempting to steal user API keys through a then-undisclosed server-side flaw. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said…
-
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under…
-
US Accuses Six Chinese AI Firms of Distilling Frontier ModelsUS Accuses Six Chinese AI Firms of Distilling Frontier Models
US agencies accuse six Chinese AI firms of distilling frontier models and recommend new defenses that could affect enterprise AI access and API use. The post US Accuses Six Chinese AI Firms of Distilling Frontier ModelsUS Accuses Six Chinese AI Firms of Distilling Frontier Models appeared first on TechRepublic. First seen on techrepublic.com Jump to…
-
US Accuses Six Chinese AI Firms of Distilling Frontier ModelsUS Accuses Six Chinese AI Firms of Distilling Frontier Models
US agencies accuse six Chinese AI firms of distilling frontier models and recommend new defenses that could affect enterprise AI access and API use. The post US Accuses Six Chinese AI Firms of Distilling Frontier ModelsUS Accuses Six Chinese AI Firms of Distilling Frontier Models appeared first on TechRepublic. First seen on techrepublic.com Jump to…
-
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Threat actors are leveraging Microsoft’s Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data
-
The EU AI Act for the Downstream Provider: What You Owe When You Just Call an API
Most founders building on someone else’s model believe the EU AI Act is the model provider’s problem. That belief is wrong in a specific and expensive way, and the part that trips people up is not the part they expect…. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-eu-ai-act-for-the-downstream-provider-what-you-owe-when-you-just-call-an-api/
-
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026. The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting…
-
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim’s browser session. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/clickfix-moves-into-the-browser/

