logo

Code-formatters expose thousands of secrets from banks, govt, tech orgs

ID: 4ab3e766-b1be-5057-8f96-cfa8cf9472b4

STIX ID: report--4ab3e766-b1be-5057-8f96-cfa8cf9472b4

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-11-25

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Researchers found that JSONFormatter and CodeBeautify's unprotected 'Recent Links' feature exposed over 80,000 user pastes (≈5GB) containing highly sensitive secrets—API keys, private keys, production AWS credentials, Active Directory credentials, PII and configuration files—across government, finance, healthcare, telecom and other high-risk sectors; honeypot keys were accessed after upload, and many affected organizations had not remediated the exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.