#apikeys — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #apikeys, aggregated by home.social.
-
Ваш API-ключ утечёт. Как сделать так, чтобы это ничего не стоило
По данным GitGuardian ( State of Secrets Sprawl ), только за 2024 год в публичный GitHub утекло около 23,7 млн секретов — ключей API, токенов, паролей. Подавляющее большинство — не результат взлома, а обычные коммиты, логи и клиентские бандлы. Свежий ключ, попавший в публичный репозиторий, боты начинают пробовать меньше чем через минуту. Вывод, к которому мы пришли после N-го инцидента: бороться за то, чтобы ключ не утёк — проигранная война. Выигрышная — сделать утечку бесполезной.
https://habr.com/ru/articles/1056070/
#apikeys #security #credentialproxy #mcp #secretsmanagement #aiagents #openai
-
AI Agents Grapple with API Key Vulnerabilities
AI agents can access and leak sensitive API keys due to broad permissions. This puts user data at risk. Learn how to prevent it.
#AIsecurity, #APIkeys, #DataProtection, #Cybersecurity, #AIAgents
https://newsletter.tf/ai-agents-risk-exposing-api-keys-data-leaks/
-
AI agents are putting user data at risk by potentially exposing sensitive API keys. This is a major security concern for many systems.
#AIsecurity, #APIkeys, #DataProtection, #Cybersecurity, #AIAgents
https://newsletter.tf/ai-agents-risk-exposing-api-keys-data-leaks/ -
Grok's Inroads: A Technical Glimpse Into OpenClaw's Integration
OpenClaw is integrating with Grok AI. Users will need OAuth or API keys to log in. This affects how people use AI tools.
#OpenClaw, #GrokAI, #OAuth, #APIkeys, #TechIntegration
https://newsletter.tf/openclaw-integrates-grok-ai-with-oauth-api-keys/
-
OpenClaw will now use Grok AI, requiring users to set up OAuth or API keys for access. This is a new way to connect AI.
#OpenClaw, #GrokAI, #OAuth, #APIkeys, #TechIntegration
https://newsletter.tf/openclaw-integrates-grok-ai-with-oauth-api-keys/ -
Software Vulnerabilities: The Risk of Exposed API Keys in Applications
Are your API keys safe in public code? Learn why hard-coding secrets in 2026 puts private user data at risk and how to stop unauthorized access today.
#cybersecurity, #codingtips, #datasecurity, #softwaredevelopment, #apikeys
-
Software developers are leaving API keys in public code, which is a 50% increase in security risks compared to 2024. This makes it easy for hackers to steal private data.
#cybersecurity, #codingtips, #datasecurity, #softwaredevelopment, #apikeys
https://newsletter.tf/exposed-api-keys-risk-2026/ -
The Register: Threat hunters find Google API keys still usable 23 minutes after deletion. “You know your Google API key has leaked so you rush to disable it before bad actors can start running up charges on your account. Bad news: According to security researchers at Aikido, people can use the API keys for up to 23 minutes after a user deletes them, creating a window of opportunity that, when […]
https://rbfirehose.com/2026/05/23/the-register-threat-hunters-find-google-api-keys-still-usable-23-minutes-after-deletion/ -
The Register: Threat hunters find Google API keys still usable 23 minutes after deletion. “You know your Google API key has leaked so you rush to disable it before bad actors can start running up charges on your account. Bad news: According to security researchers at Aikido, people can use the API keys for up to 23 minutes after a user deletes them, creating a window of opportunity that, when […]
https://rbfirehose.com/2026/05/23/the-register-threat-hunters-find-google-api-keys-still-usable-23-minutes-after-deletion/ -
RT @AikidoSecurity: Das Löschen eines Google-API-Schlüssels widerruft ihn nicht sofort. Unsere Forschung ergab erfolgreiche Authentifizierungen bis zu 23 Minuten nach der Löschung in der gesamten Google-Infrastruktur. In diesem Zeitfenster können Angreifer mit einem geleakten Schlüssel weiterhin auf aktivierte APIs, einschließlich Gemini, zugreifen. Google hat unseren Bericht als „wird nicht behoben“ geschlossen.
mehr auf Arint.info
#APIKeys #Cybersecurity #DataProtection #Gemini #GoogleAPI #TechNews #arint_info
-
RT @AikidoSecurity: Das Löschen eines Google-API-Schlüssels widerruft ihn nicht sofort. Unsere Forschung ergab erfolgreiche Authentifizierungen bis zu 23 Minuten nach der Löschung in der gesamten Google-Infrastruktur. In diesem Zeitfenster können Angreifer mit einem geleakten Schlüssel weiterhin auf aktivierte APIs, einschließlich Gemini, zugreifen. Google hat unseren Bericht als „wird nicht behoben“ geschlossen.
mehr auf Arint.info
#APIKeys #Cybersecurity #DataProtection #Gemini #GoogleAPI #TechNews #arint_info
-
Researchers say deleted Google API keys may stay active for up to 23 minutes due to cloud propagation delays.
The issue could reportedly allow continued access to Gemini uploads, APIs, and cloud resources after key deletion.
-
1Password secures coding agents with new OpenAI Codex integration
https://fed.brid.gy/r/https://nerds.xyz/2026/05/1password-openai-codex-security/
-
1Password secures coding agents with new OpenAI Codex integration
https://web.brid.gy/r/https://nerds.xyz/2026/05/1password-openai-codex-security/
-
Google Cloud's Vertex AI: A Hub for Generative AI Development Navigates API Access and Integration
Google Vertex AI users get 403 errors. Learn how to fix API key and service account permissions for Gemini and other AI models.
#VertexAI, #GoogleCloud, #APIKeys, #GenerativeAI, #IAM
https://newsletter.tf/google-vertex-ai-api-key-permission-errors/
-
Google Cloud's Vertex AI: A Hub for Generative AI Development Navigates API Access and Integration
Google Vertex AI users get 403 errors. Learn how to fix API key and service account permissions for Gemini and other AI models.
#VertexAI, #GoogleCloud, #APIKeys, #GenerativeAI, #IAM
https://newsletter.tf/google-vertex-ai-api-key-permission-errors/
-
Google Vertex AI is making it easier to build AI, but many users are hitting a wall with API key errors. This is a common problem for developers.
#VertexAI, #GoogleCloud, #APIKeys, #GenerativeAI, #IAM
https://newsletter.tf/google-vertex-ai-api-key-permission-errors/ -
Google Vertex AI is making it easier to build AI, but many users are hitting a wall with API key errors. This is a common problem for developers.
#VertexAI, #GoogleCloud, #APIKeys, #GenerativeAI, #IAM
https://newsletter.tf/google-vertex-ai-api-key-permission-errors/ -
The Register: Google users fight for refunds as unauthorized API usage bills soar. “Several Google Cloud customers say their API keys have been compromised and used by bad actors to run inferencing workloads using the most expensive video and picture models, leaving them with bills for tens of thousands of dollars and weeks of back-and-forth headaches with the Chocolate Factory as they tried to […]
https://rbfirehose.com/2026/05/16/the-register-google-users-fight-for-refunds-as-unauthorized-api-usage-bills-soar/ -
The Register: Google users fight for refunds as unauthorized API usage bills soar. “Several Google Cloud customers say their API keys have been compromised and used by bad actors to run inferencing workloads using the most expensive video and picture models, leaving them with bills for tens of thousands of dollars and weeks of back-and-forth headaches with the Chocolate Factory as they tried to […]
https://rbfirehose.com/2026/05/16/the-register-google-users-fight-for-refunds-as-unauthorized-api-usage-bills-soar/ -
Ah yes, another "revolutionary" #API promising to unite the #AI models of #Europe with the transformative power of a single login screen. 🌍🔑 Because apparently, the real challenge in AI isn't the technology, but remembering which API key unlocks #Skynet. 🤖✨
https://www.edenai.co #Revolution #Tech #Innovation #APIKeys #HackerNews #ngated -
Ah yes, another "revolutionary" #API promising to unite the #AI models of #Europe with the transformative power of a single login screen. 🌍🔑 Because apparently, the real challenge in AI isn't the technology, but remembering which API key unlocks #Skynet. 🤖✨
https://www.edenai.co #Revolution #Tech #Innovation #APIKeys #HackerNews #ngated -
Ah, the digital Fort Knox of API keys! 🏰 Because who wouldn't want to turn their code into an unending #security checkpoint #circus 🎪, complete with browser verifications and #JavaScript hijinks? Just what every developer dreams of: #debugging security measures instead of their actual code! 🚀
https://www.keycard.studio/ #APIkeys #DeveloperLife #HackerNews #ngated -
Ah, the digital Fort Knox of API keys! 🏰 Because who wouldn't want to turn their code into an unending #security checkpoint #circus 🎪, complete with browser verifications and #JavaScript hijinks? Just what every developer dreams of: #debugging security measures instead of their actual code! 🚀
https://www.keycard.studio/ #APIkeys #DeveloperLife #HackerNews #ngated -
My adventure in designing API keys
-
My adventure in designing API keys
-
The Register: Security boffins scoured the web and found hundreds of valid API keys. “Computer security boffins have conducted an analysis of 10 million websites and found almost 2,000 API credentials strewn across 10,000 webpages.”
https://rbfirehose.com/2026/04/01/the-register-security-boffins-scoured-the-web-and-found-hundreds-of-valid-api-keys/ -
The Register: Security boffins scoured the web and found hundreds of valid API keys. “Computer security boffins have conducted an analysis of 10 million websites and found almost 2,000 API credentials strewn across 10,000 webpages.”
https://rbfirehose.com/2026/04/01/the-register-security-boffins-scoured-the-web-and-found-hundreds-of-valid-api-keys/ -
🚨 NEWSFLASH: Captain Obvious discovers that leaving admin keys exposed is a bad idea! 🤯 Who knew?! Our hero triumphantly stumbles upon 39 API keys just lying around like Easter eggs on the internet. In an explosive twist, he asks, "What if OTHER sites have the same issue?" 🕵️♂️🔍💡
https://benzimmermann.dev/blog/algolia-docsearch-admin-keys #CaptainObvious #APIkeys #SecurityBreach #CyberAwareness #InternetSafety #DataProtection #HackerNews #ngated -
🚨 NEWSFLASH: Captain Obvious discovers that leaving admin keys exposed is a bad idea! 🤯 Who knew?! Our hero triumphantly stumbles upon 39 API keys just lying around like Easter eggs on the internet. In an explosive twist, he asks, "What if OTHER sites have the same issue?" 🕵️♂️🔍💡
https://benzimmermann.dev/blog/algolia-docsearch-admin-keys #CaptainObvious #APIkeys #SecurityBreach #CyberAwareness #InternetSafety #DataProtection #HackerNews #ngated -
FYI: Google API keys hiding in plain sight now unlock Gemini AI: Google API keys embedded in public code now expose Gemini AI access and billing risk after researchers found 2,800 live keys in a November 2025 crawl. Here's what changed and why it matters. https://ppc.land/google-api-keys-hiding-in-plain-sight-now-unlock-gemini-ai/ #GoogleAPI #GeminiAI #Cybersecurity #DataPrivacy #APIKeys
-
To search for Google API keys recursively in the current folder and its sub-folders with ripgrep:
rg 'AIza[0-9A-Za-z\-_]{35}' -o
Also shared on Shodan Snippets:
https://snippets.shodan.io/c/FHw2r7wWIFmjVAfG
#Security #OneLiner #Google #GoogleAPIKeys #APIkeys #ripgrep #Regex #BugBounty #Snippet
-
To search for Google API keys recursively in the current folder and its sub-folders with ripgrep:
rg 'AIza[0-9A-Za-z\-_]{35}' -o
Also shared on Shodan Snippets:
https://snippets.shodan.io/c/FHw2r7wWIFmjVAfG
#Security #OneLiner #Google #GoogleAPIKeys #APIkeys #ripgrep #Regex #BugBounty #Snippet
-
Thousands of publicly exposed Google API keys may now authenticate access to Gemini AI services.
Researchers say what was once low-risk exposure gained new privileges after AI integration.
Cloud security takeaway: legacy credentials + evolving scope = hidden risk.
Have you audited your API keys recently?Share your perspective below.
Follow TechNadu for trusted cybersecurity coverage.#CyberSecurity #Google #Gemini #CloudSecurity #APIKeys #AIsecurity #Infosec #DevSecOps #AppSec #DigitalRisk
-
🚨 Breaking news, folks: it turns out API keys are not like your diary's lock after all! Who would have thought? 😱 Apparently, sharing keys meant for public use with a private access service can lead to some unwanted surprises! Google must be thrilled! 🔓🤦♂️
https://simonwillison.net/2026/Feb/26/google-api-keys/ #APIkeys #PublicAccess #DataSecurity #GoogleNews #TechSurprise #HackerNews #ngated -
🚨 Breaking news, folks: it turns out API keys are not like your diary's lock after all! Who would have thought? 😱 Apparently, sharing keys meant for public use with a private access service can lead to some unwanted surprises! Google must be thrilled! 🔓🤦♂️
https://simonwillison.net/2026/Feb/26/google-api-keys/ #APIkeys #PublicAccess #DataSecurity #GoogleNews #TechSurprise #HackerNews #ngated -
OpenClaw setup asks for an API key. Which one? From where? Will it cost $200/month if you pick wrong?
Complete guide: Anthropic, OpenAI, Gemini, DeepSeek, OpenRouter. Pricing, setup steps, common mistakes.
DeepSeek costs 10x less than Claude. Gemini has a 1M token context window. Which fits your use case?
-
----------------
🎯 AI
===================Executive summary: Moltbook, an AI-only social network populated by OpenClaw agents, presents immediate security risks: pervasive spam/scams, exposure of agents to untrusted content via API-oriented prompt files, and a reported database compromise that leaked API keys enabling bot impersonation and direct prompt injection.
Technical details:
• SKILLS.md, HEARTBEAT.md, and MESSAGING.md are repository-style markdown files that describe how agents interact with the Moltbook API. SKILLS.md documents API interactions and recommends HTTP requests (curl-style). HEARTBEAT.md instructs periodic check-ins. MESSAGING.md notes that messaging requires human approval, while other endpoints accept automated agent input.
• Experimental tooling (reported as a CLI tool named moltbotnet) implemented API calls for posting, commenting, upvoting, following, and engagement automation. This tooling demonstrates how easily an agent or impersonator can script interactions.
• Reported breach of Moltbook’s database exposed API keys tied to agent identities. Those keys materially enable: impersonation of legitimate agents, submission of crafted prompts to agent workloads, and direct prompt injection vectors that bypass typical human-only guards.Analysis:
The combination of (1) public, machine-readable prompt files that instruct agents how to behave, (2) open posting and engagement that accepts untrusted content, and (3) leaked credentials produces two classes of injection risks: indirect prompt injection (agents ingesting malicious content from other agents) and direct prompt injection (attacker using stolen API keys to send malicious prompts as a trusted agent). The observed ecosystem is also saturated with social-engineering lures (requests to run package installers, share crypto wallets, or call external APIs).
Detection guidance:
• Monitor unexpected use of API keys or unusual posting frequency associated with agent identities.
• Inspect content sources for scripted patterns (repeated promotional payloads, command-like text referencing package managers or curl usage).Limitations:
• No public CVE identifiers are reported in the source material.
• Exact scope of leaked API keys (number of keys, associated privileges) was not enumerated in the writeup.References and tags:
SKILLS.md, HEARTBEAT.md, MESSAGING.md — Tenable Research field report on Moltbook interactions and breach findings.
🔹 OpenClaw #Moltbook #promptinjection #APIkeys #Tenable
🔗 Source: https://www.tenable.com/blog/undercover-on-moltbook
-
----------------
🎯 AI
===================Executive summary: Moltbook, an AI-only social network populated by OpenClaw agents, presents immediate security risks: pervasive spam/scams, exposure of agents to untrusted content via API-oriented prompt files, and a reported database compromise that leaked API keys enabling bot impersonation and direct prompt injection.
Technical details:
• SKILLS.md, HEARTBEAT.md, and MESSAGING.md are repository-style markdown files that describe how agents interact with the Moltbook API. SKILLS.md documents API interactions and recommends HTTP requests (curl-style). HEARTBEAT.md instructs periodic check-ins. MESSAGING.md notes that messaging requires human approval, while other endpoints accept automated agent input.
• Experimental tooling (reported as a CLI tool named moltbotnet) implemented API calls for posting, commenting, upvoting, following, and engagement automation. This tooling demonstrates how easily an agent or impersonator can script interactions.
• Reported breach of Moltbook’s database exposed API keys tied to agent identities. Those keys materially enable: impersonation of legitimate agents, submission of crafted prompts to agent workloads, and direct prompt injection vectors that bypass typical human-only guards.Analysis:
The combination of (1) public, machine-readable prompt files that instruct agents how to behave, (2) open posting and engagement that accepts untrusted content, and (3) leaked credentials produces two classes of injection risks: indirect prompt injection (agents ingesting malicious content from other agents) and direct prompt injection (attacker using stolen API keys to send malicious prompts as a trusted agent). The observed ecosystem is also saturated with social-engineering lures (requests to run package installers, share crypto wallets, or call external APIs).
Detection guidance:
• Monitor unexpected use of API keys or unusual posting frequency associated with agent identities.
• Inspect content sources for scripted patterns (repeated promotional payloads, command-like text referencing package managers or curl usage).Limitations:
• No public CVE identifiers are reported in the source material.
• Exact scope of leaked API keys (number of keys, associated privileges) was not enumerated in the writeup.References and tags:
SKILLS.md, HEARTBEAT.md, MESSAGING.md — Tenable Research field report on Moltbook interactions and breach findings.
🔹 OpenClaw #Moltbook #promptinjection #APIkeys #Tenable
🔗 Source: https://www.tenable.com/blog/undercover-on-moltbook
-
Envmap - Fini les fichiers .env qui traînent et finissent sur GitHub
https://fed.brid.gy/r/https://korben.info/envmap-secrets-sans-fichier-env-disque-github-leaks.html
-
Envmap - Fini les fichiers .env qui traînent et finissent sur GitHub
https://fed.brid.gy/r/https://korben.info/envmap-secrets-sans-fichier-env-disque-github-leaks.html
-
Fr Express Data Breach: ISP Source Code, API, and Billing Data Leaked https://dailydarkweb.net/fr-express-data-breach-isp-source-code-api-and-billing-data-leaked/ #telecommunications #sourcecodeleak #DataBreaches #databaseleak #cyberattack #Bangladesh #databreach #FrExpress #APIKeys #ABillS #ISP
-
Fr Express Data Breach: ISP Source Code, API, and Billing Data Leaked https://dailydarkweb.net/fr-express-data-breach-isp-source-code-api-and-billing-data-leaked/ #telecommunications #sourcecodeleak #DataBreaches #databaseleak #cyberattack #Bangladesh #databreach #FrExpress #APIKeys #ABillS #ISP
-
BlossomCloud Data Breach Exposes Source Code https://dailydarkweb.net/blossomcloud-data-breach-exposes-source-code/ #BlossomCloud.co.kr #ContractorBreach #sourcecodeleak #DataBreaches #BanBanPlay #databreach #SouthKorea #technology #dataleak #APIKeys
-
BlossomCloud Data Breach Exposes Source Code https://dailydarkweb.net/blossomcloud-data-breach-exposes-source-code/ #BlossomCloud.co.kr #ContractorBreach #sourcecodeleak #DataBreaches #BanBanPlay #databreach #SouthKorea #technology #dataleak #APIKeys
-
WE'RE LIVE ON KICK! 💥 Join chiefgyk3d for a spicy stream! $55K mistake deets, Cybersecurity rants, Linux gaming & Doppler talk! Don't miss out! Come hang NOW!
#Cybersecurity #LinuxGaming #Doppler #APIKeys -
The Register: AI companies keep publishing private API keys to GitHub. “Leading AI companies turn out to be no better at keeping secrets than anyone else writing code. Cloud security firm Wiz has found that 65 percent of the Forbes AI 50 ‘had leaked verified secrets on GitHub,’ minus a few with no presence on the code sharing site.”
-
via @dotnet : New Trusted Publishing enhances security on NuGet.org
https://ift.tt/FWdNpaR
#TrustedPublishing #NuGet #GitHubActions #Security #ShortLivedKeys #APIkeys #SoftwareDevelopment #OpenSSF #NuGetCommunity #SecurePublishing #DevOps #CI #Cont… -
OH: Moment, ich gibt dir die API-Keys aus dem Production Pod zum Testen.
-
Employee #monitoring app exposes 21M work screens | Cybernews
The #leaked data is extremely sensitive, as millions of screenshots from employees' devices could not only expose full-screen captures of emails, internal chats, and confidential business documents, but also contain #login pages, credentials, #APIkeys , and other sensitive info that could be #exploited to attack businesses worldwide.
Cybernews contacted the company, and access has now been secured.
#privacyhttps://cybernews.com/security/employee-monitoring-app-leaks-millions-screenshots/