#apikeys

2025-04-25

Employee #monitoring app exposes 21M work screens​ | Cybernews

The #leaked data is extremely sensitive, as millions of screenshots from employees' devices could not only expose full-screen captures of emails, internal chats, and confidential business documents, but also contain #login pages, credentials, #APIkeys , and other sensitive info that could be #exploited to attack businesses worldwide.

Cybernews contacted the company, and access has now been secured.
#privacy

cybernews.com/security/employe

2025-01-29

Exposed #DeepSeek Database Revealed #Chat Prompts and Internal Data

China-based DeepSeek has exploded in popularity, drawing greater scrutiny. Case in point: #Security researchers found more than 1 million records, including user data and #APIkeys , in an open database.
#china #api

wired.com/story/exposed-deepse

2024-12-13

Prometheus Security Breach 300K Instances Expose Credentials and API Keys
Today, we're diving into the alarming news of a massive security breach involving Prometheus, a popular monitoring and alerting tool used by countless organizations worldwide

cloudhosting.evostrix.eu/prome

2024-10-20

'Some random guy' is emailing me on behalf the Internet Archive Team, @internetarchive .

#internetarchive #internetarchivebreach #zendesktoken #apikeys

The Internet Archive Team (Internet Archive)

Oct 20, 2024, 05:42 CDT

It's dispiriting to see that even after being made aware of the breach 2 weeks ago, IA has still not done the due diligence of rotating many of the API keys that were exposed in their gitlab secrets.

As demonstrated by this message, this includes a Zendesk token with perms to access 800K+ support tickets sent to info@archive.org since 2018.

Whether you were trying to ask a general question, or requesting the removal of your site from the Wayback Machine—your data is now in the hands of some random guy. If not me, it'd be someone else.

Here's hoping that they'll get their shit together now.
Gonçalo Valériodethos@s.ovalerio.net
2024-04-27

"tl;dr Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, it’s become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a variety of popular SaaS and cloud providers."

trufflesecurity.com/blog/postm

#security #api #postman #apikeys #cybersecurity

2023-11-29

👉 #SAML, #OAuth 2.0, and #JWT establish a robust framework for securing #API authentication and authorization processes.

Explore other key #apisecurity protocols essential for securing your API endpoints: bit.ly/3Rn96bb

#apiattacks #apiendpoints #authentication #authorization #apibreaches #databreaches #vulnerabilities #apikeys #apptrana #indusface

2023-08-08

I'm failing to grok how #APIKeys and #GCP (#GoogleCloudPlatform) "projects" work.

I need to distinguish between different customers calling my #API via their API keys. The official documentation says "create a separate GCP project for each [customer]" (source: cloud.google.com/endpoints/doc)

I could have hundreds or more of different customers. Am I expected to create a GCP project for each one?

gtbarrygtbarry
2023-07-18

JumpCloud says nation-state hackers breached its systems

JumpCloud, a directory platform that allows enterprises to authenticate, authorize and manage users and devices, told customers it had reset their API keys “out of an abundance of caution”

JumpCloud said it determined a nation-state actor gained unauthorized access to its systems and targeted a “small and specific” set of customers.

techcrunch.com/2023/07/17/jump

Gareth Emslie 🇿🇦 🇪🇦 🇨🇭keyoke_za@hachyderm.io
2023-05-18

Microsoft has announced that API keys will be retired for querying application insights. Users will need to transition to Azure AD authentication, which provides additional features such as multi-factor authentication and hybrid integration for password protection policies. The deadline for transitioning to... azure.microsoft.com/en-us/upda #AzureAD #APIkeys #applicationinsights #softcorpremium

ₛᵤₙdᵣᵤᵢdSundruid@infosec.exchange
2023-02-21

Question for the local community:

When you generate API secrets as an administrator of the application, you have access to them. Very common when creating secrets for a service accounts etc. But the logs will always point to the user you created and is open to abuse.

Under API security, is there a 'best practice' or some regulation guidance that says that this form of delegation has to be accurately authenticated 'by user' in a logging mechanism? #apikeys #gdpr #logging #infosec

hobshobson
2022-02-02

Dealing with my first for a system I'm responsible for.
T0: Dev pushed cloud platform to
T0+30 min: Beijing IP attempted to create docker-machine host and security group allowing that IP ingress. When permissions were insufficient immediately deleted security group.
T0 +40 min: later our customer (owner of the cloud platform account) forwarded an alert email from the platform.
T0 +50 min: our lockdown and began

2020-09-28

Twitter Warns Developers of API Bug That Exposed App Keys, Tokens - Twitter has fixed a caching issue that could have exposed developers' API keys and tokens. threatpost.com/twitter-bug-exp #developer.twitter.com #twitterdevelopers #oauthapirequests #vulnerabilities #applications #dataexposure #websecurity #appsecurity #cachingbug #security #apikeys #twitter #tokens

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst