logo

Security boffins scoured the web and found hundreds of valid API keys

ID: 5099c777-ac97-502b-a384-1eaa511f2396

STIX ID: report--5099c777-ac97-502b-a384-1eaa511f2396

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-03-27

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

A research study scanning ~10 million websites found nearly 2,000 exposed API credentials across thousands of pages, including AWS, GitHub, Stripe, and other sensitive service tokens. Most exposures were in JavaScript bundles and persisted for an average of 12 months; researchers reported findings to affected parties and observed a substantial reduction after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.