Tag: api
-
AI Security Incident Case: Encrypted Reasoning Blocks of Proprietary LLMs Can Be Stolen via Cross-Model Replay
Overview On August 10, 2026, MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and other institutions jointly published the paper Stealing Reasoning Traces from Proprietary LLM APIs. The research reveals a common architectural flaw in the reasoning model APIs of three major AI providers, Anthropic, OpenAI, and Google, which allows……
-
Quantum-Safe Isn’t Cyber-Safe
Tags: access, ai, api, breach, communications, compliance, computer, computing, credentials, cryptography, cyber, data, defense, encryption, exploit, flaw, google, group, ml, openai, password, radius, risk, threat, update<div cla In the same week federal agencies began scoping migrations under the White House’s new Post-Quantum Cryptography Executive Order, a group of academic researchers published a paper that, on its face, had nothing to do with quantum computing at all. It described a flaw in how three of the most security-conscious engineering organizations on…
-
659 Stripe Merchant API Keys Leaked Online, Exposing 688,000 Customer Records
A data leak published on a cybercrime data-trading forum has exposed live Stripe API credentials for 659 merchant accounts, along with approximately 35 GB of customer- and payment-related data. The exposure affects an estimated 688,363 customer records across merchants in 42 countries, but available evidence indicates that Stripe’s own infrastructure was not breached. The dataset…
-
50,000 Stripe Secrets Leaked in Public Code
Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total. The research…
-
Nicht-menschliche Identitäten: Warum Unternehmen Maschinen, Dienste und KI-Agenten besser steuern müssen
Service-Konten, API-Schlüssel, Zertifikate und KI-Agenten sind heute zentrale Bausteine digitaler Geschäftsprozesse zugleich aber oft kaum gesteuerte Risikoträger. Unternehmen müssen nicht-menschliche Identitäten deshalb konsequent inventarisieren, begrenzen und überwachen, um Angriffsflächen zu reduzieren, Compliance-Anforderungen zu erfüllen und Automatisierung sicher zu skalieren. Management Summary Nicht-menschliche Identitäten entwickeln sich in hybriden IT-, Cloud- und KI-Umgebungen zu einer… First seen…
-
Identity Is the New Perimeter, AI Is Blowing It Wide Open
CyberEdBoard Webinar Panel to Explore Non-Human Identity Risks, AI Governance. Enterprises have never been able to fully secure human identities, but now CISOs are responsible for securing millions of non-human identities including AI agents, APIs, service accounts. Join this CyberEdBoard panel for perspectives on shadow AI, zero trust, legal issues and governance. First seen on…
-
OpenAI Workload Identity Federation: Aembit Brings Secretless Access to the OpenAI API
3 min readAembit already covers a lot of ground when it comes to securing AI workload access. For OpenAI’s ChatGPT, workloads can authenticate to the ChatGPT API using static API key injection, with the Aembit proxy handling direct access transparently. Today, we’re extending that coverage with the introduction of the OpenAI Workload Identity Federation Credential…
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/
-
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/
-
Verschlüsselte KI-Denkprotokolle geknackt Schwachstelle bei OpenAI, Anthropic und Google
Forscher haben eine gravierende Schwachstelle bei der Absicherung sogenannter Reasoning-Logs entdeckt. Verschlüsselte Denkprotokolle moderner KI-Modelle lassen sich demnach unter bestimmten Bedingungen über ein schwächeres Modell desselben Anbieters entschlüsseln. Besonders brisant: In öffentlich zugänglichen Datensätzen fanden die Forscher bereits personenbezogene Daten, Zugangsdaten, API-Schlüssel und Passwörter. Forscher von MATS Research, dem Max-Planck-Institut für intelligente Systeme, dem ELLIS…
-
Claude-Powered Agent Exploits Australian Gym API, Removes Waitlisted Member
A Claude-powered AI agent exploited an Australian gym API flaw, removed a member from a waitlist, and exposed new risks from autonomous agents. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-claude-ai-agent-australian-gym-api-flaw-apac/
-
LexisNexis shuts down services after suspicious activity on servers
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/lexisnexis-shuts-down-services-after-suspicious-activity-on-servers/
-
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that has been observed delivering a browser wallet and credential stealer.The names of the extensions are below – helper-beeps.solidity-pro web3devtoolsx.solidity-proAlthough neither of the extensions is now available on Open VSX, the GitHub repository First seen on thehackernews.com Jump…
-
Claude-Powered AI Agent Exploits API Authorization Flaw to Hack Gym Booking System
An Australian AI agent powered by Anthropic’s Claude reportedly exploited an authorization flaw in a gym booking platform, allowing it to book classes outside of permitted time frames and cancel another user’s waitlist reservation without explicit permission. This incident underscores how increasingly autonomous AI agents can turn routine online tasks into cybersecurity issues when granted…
-
The Hidden Risks of Ignoring API Security During Mobile Application Security Testing
Mobile applications don’t operate in isolation. Behind every login screen, payment flow, and push notification sits a network of APIs quietly moving data between the app, the backend, and third-party services. Yet when organizations plan mobile application security testing, API security is often treated as an afterthought, something to “get to later” once the app’s……
-
Account-Farming für Claude & Co.: Wie billige KI-Tokens zum Security-Risiko werden
Graumärkte verkaufen Zugänge zu Frontier-KI bis zu 90 Prozent günstiger. Okta zeigt die Risiken durch Account-Farming, Proxies und statische API-Keys. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/account-farming-fuer-claude-co-wie-billige-ki-tokens-zum-security-risiko-werden/a46052/
-
How AI Agents Widen the Enterprise Blast Radius
AWS’s Matt Girdharry and Varonis’ Matt Radolec on Data Security, Machine-Speed Risk. Agentic AI can act at machine speed across data, APIs and cloud services, expanding enterprise risk beyond traditional controls. AWS’ Matt Girdharry and Varonis’ Matt Radolec explain why AI governance, least privilege and runtime visibility now matter more than ever for security teams.…
-
AI Generated Code Risks: Why Business Owners Should Never Trust Software That Simply Works
AI can now generate working software in minutes. Ask Claude, GitHub Copilot, ChatGPT, or another AI coding tool to create an API, authentication flow, admin…Read More First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/ai-generated-code-risks-why-business-owners-should-never-trust-software-that-simply-works/
-
Contrast Security Launches CVE Shield for Runtime Exploit Protection
Contrast Security has launched CVE Shield, a runtime control that detects, monitors and blocks exploitation of known vulnerabilities in production applications and APIs while teams work on permanent fixes. Announced July 29 ahead of Black Hat USA 2026, CVE Shield operates inside running applications and uses a microsandbox for each supported CVE. Contrast said the..…
-
Broadcom adds multi-tenant security and API protection to VMware, opens MSP opportunities
First seen on scworld.com Jump to article: www.scworld.com/news/broadcom-adds-multi-tenant-security-and-api-protection-to-vmware-opens-msp-opportunities

