DeepSeek Data Leak Exposes 12,000 Hardcoded API Keys and Passwords
ID: 589fe676-ff9f-56af-bf21-4b8a1238d12c
STIX ID: report--589fe676-ff9f-56af-bf21-4b8a1238d12c
Feed Name: GBHackers
Truffle Security scanned the December 2024 Common Crawl corpus and identified ~12,000 live credentials (including AWS root keys, Slack webhooks, and Mailchimp API keys) across millions of pages, many reused across sites and verified as active; the report warns this exposure enables account takeover, phishing, and data theft and cautions that LLMs trained on this data may learn and propagate insecure practices, recommending expanded secret scanning, redaction in training pipelines, and embedded model guardrails.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
