Tag

Data Exposure

All articles tagged with #data exposure

Public Google API keys unlock Gemini AI data risk
technology3 days ago

Public Google API keys unlock Gemini AI data risk

Researchers found nearly 3,000 Google API keys publicly exposed in client-side code that could authenticate to Google's Gemini AI and access private data. Google says it has implemented protections to block leaked keys from Gemini and will notify developers, who should audit and rotate keys. The exposure was uncovered by TruffleSecurity via the November 2025 Common Crawl dataset, highlighting potential abuse where attackers could incur API charges by making Gemini calls.

Misconfigured Moltbot dashboards leak credentials and invite takeovers
cybersecurity1 month ago

Misconfigured Moltbot dashboards leak credentials and invite takeovers

Misconfigured Moltbot (formerly Clawdbot) control panels exposed hundreds of internet-facing dashboards, leaking API keys, private chats and other credentials. With autonomous agent capabilities, attackers could impersonate operators, inject messages, and even run commands with elevated privileges. The root cause was localhost-trust and reverse-proxy defaults; the project has rebranded Clawdbot to Moltbot (Molty) while keeping the same core functionality.

OwnCloud Vulnerabilities Expose Admin Passwords and Allow Unauthorized File Modifications
technology2 years ago

OwnCloud Vulnerabilities Expose Admin Passwords and Allow Unauthorized File Modifications

ownCloud has disclosed three critical vulnerabilities, including sensitive data exposure, in its open source file-sharing software. The most severe vulnerability allows attackers to access admin passwords, mail server credentials, and license keys. Another vulnerability enables unauthorized access, modification, or deletion of files without authentication. The third vulnerability bypasses subdomain validation, allowing attackers to redirect callbacks to a domain controlled by them. ownCloud has released patches and recommends applying fixes, including disabling the "Allow Subdomains" option. The company serves over 600 enterprise customers and millions of users across various sectors.

OpenAI's ChatGPT suffers significant bug causing leak of chat histories.
technology2 years ago

OpenAI's ChatGPT suffers significant bug causing leak of chat histories.

OpenAI has confirmed that a software bug caused ChatGPT to leak the conversation histories of some random users earlier this week. The company has released a patch, but users' chat histories for Monday, March 20, may have been lost. It remains unclear whether the bug exposed anyone's sensitive personal information. OpenAI plans to provide more details through a "technical postmortem."