Researchers scan 10 million websites and uncover thousands of exposed API keys quietly granting access to cloud systems and critical infrastructure




  • Thousands of exposed API keys quietly grant access to critical systems
  • Public webpages contain credentials that unlock cloud and payment services
  • Developers unknowingly leave sensitive API tokens embedded in live websites

Security researchers from Stanford University, UC Davis, and TU Delft say sensitive API credentials are sitting openly on thousands of public webpages, with very little protection.

According to a preprint version of the study on arXiv, the researchers analyzed 10 million webpages and identified 1,748 valid credentials exposed across nearly 10,000 pages.


https://cdn.mos.cms.futurecdn.net/A3s8er5A2DaVJdvGrdjYGJ-1920-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img