Close Menu
    National News Brief
    Friday, June 26
    • Home
    • Business
    • Lifestyle
    • Science
    • Technology
    • International
    • Arts & Entertainment
    • Sports
    National News Brief
    Home » Security credentials inadvertently leaked on thousands of websites

    Security credentials inadvertently leaked on thousands of websites

    Team_NationalNewsBriefBy Team_NationalNewsBriefMarch 23, 2026 Science No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Leaked keys could have let attackers take control of a company’s digital infrastructure

    Vertigo3d/Getty Images

    Critical security credentials are inadvertently being exposed on thousands of websites – including those run by some banks and healthcare providers.

    The leaked details could have given snoopers access to sensitive data like RSA private keys, which allow attackers to impersonate servers, decrypt private communications or gain full administrative control of a company’s digital infrastructure. “This is a very significant issue, and it doesn’t affect only small companies, but some very big companies,” says Nurullah Demir at Stanford University in California.

    Demir and his colleagues analysed 10 million web pages to uncover how many leaked application programming interface (API) credentials. API keys allow different software systems to seamlessly communicate, acting as access tokens for cloud platforms, payment processors and messaging services.

    By scanning the web, the researchers identified 1748 verified, active credentials from 14 major service providers – including Amazon Web Services, Stripe, GitHub and OpenAI – scattered across nearly 10,000 websites.

    The vulnerability isn’t the fault of those companies, but of the software developers and website operators who used their services to build and run websites. While the researchers didn’t directly name the companies affected, they did disclose that they include a “global systematically important financial institution”, a “firmware developer” and a “major hosting platform”.

    “We notified all the companies which we have identified an exposure for,” says Demir. Within two weeks, about 50 per cent of the organisations removed the exposed API keys, but some of them didn’t respond, he says.

    The exposed credentials remained publicly accessible for an average of 12 months, with some online for as long as five years. The majority of those credentials exposed – some 84 per cent of those found – were discovered within JavaScript environments, something the researchers believe may be a consequence of software developers using bundler tools to package their code in a way that can be used online.

    Another 16 per cent of the exposed credentials stemmed from third-party resources, meaning a poorly configured external plug-in or script could broadcast an organisation’s sensitive keys across the internet.

    “None of these developers intended to be insecure; many of them didn’t even actually make a mistake in the first place,” says Katie Paxton-Fear at Manchester Metropolitan University, UK. The API keys were instead made public because of programming quirks associated with how the language works and runs on the server. “They did everything right and it went into the machine that is their development pipeline and it was revealed,” she says.

    Leaked API keys and credentials are “a real issue in modern software development”, says Nick Nikiforakis at Stony Brook University, New York. “API keys act in lieu of credentials and they allow whoever has them to act as an authorised user on a given service.” The problem is that sometimes those can be misconfigured and end up being inadvertently shared publicly – with catastrophic consequences. “Accidentally revealing an API key to the public allows attackers who find it to abuse it,” says Nikiforakis.

    Tackling the problem is a shared responsibility, says Demir. “Developers, of course, have to [take] care when they use these API credentials,” he says, making sure they configure development environments in the right way. The creators of website-building tools need to design their software so that secret keys are hidden automatically by default, rather than relying on developers to manually secure them, he adds, and the companies hosting these websites should actively scan for leaked keys and deactivate them immediately.

    Topics:



    Source link

    Team_NationalNewsBrief
    • Website

    Keep Reading

    Can home batteries help save the climate and save you money?

    Lost books by ancient philosophers recovered from ‘unreadable’ scrolls

    We’ve uncovered a master gene that switches on human development

    Where, when and how to watch the 2026 solar eclipse

    Record-breaking IBM chip uses trick to cram in 100 billion transistors

    Extreme heat is muddling animals’ brains—and even triggering aggression

    Add A Comment

    Comments are closed.

    Editors Picks

    Not a Brexit reversal: UK seeks closer EU ties to cut trade barriers

    June 2, 2026

    Mariners prove strength of lineup in season-best performance  

    July 13, 2025

    Get 8 Microsoft Office Apps For One Low Price

    May 25, 2025

    DOJ Sues Alabama To Permit Migrant Voting

    October 4, 2024

    USC professor’s tech has improved autism diagnosis

    November 27, 2024
    Categories
    • Arts & Entertainment
    • Business
    • International
    • Latest News
    • Lifestyle
    • Opinions
    • Politics
    • Science
    • Sports
    • Technology
    • Top Stories
    • Trending News
    • World Economy
    About us

    Welcome to National News Brief, your one-stop destination for staying informed on the latest developments from around the globe. Our mission is to provide readers with up-to-the-minute coverage across a wide range of topics, ensuring you never miss out on the stories that matter most.

    At National News Brief, we cover World News, delivering accurate and insightful reports on global events and issues shaping the future. Our Tech News section keeps you informed about cutting-edge technologies, trends in AI, and innovations transforming industries. Stay ahead of the curve with updates on the World Economy, including financial markets, economic policies, and international trade.

    Editors Picks

    Iran war day 119: Israel hits Lebanon as IAEA says it will return to Iran | US-Israel war on Iran News

    June 26, 2026

    Will Howard gets bad news amid Steelers’ development of Drew Allar

    June 26, 2026

    Beyond Navy comment period, give us data about WA nuclear subs

    June 26, 2026

    Pride Month Reminder: LGBTQ+ Employees Aren’t All the Same

    June 26, 2026
    Categories
    • Arts & Entertainment
    • Business
    • International
    • Latest News
    • Lifestyle
    • Opinions
    • Politics
    • Science
    • Sports
    • Technology
    • Top Stories
    • Trending News
    • World Economy
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2024 Nationalnewsbrief.com All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.