Thousands of Websites Expose Security Credentials: Accidental Leak Alert

Sure! Here’s the rewritten content, optimized for SEO while maintaining the HTML structure:

Leaked API Keys

API Key Leaks: A Major Threat to Business Security

Vertigo3d/Getty Images

Critical security credentials, including API keys, are mistakenly exposed on thousands of websites, putting organizations—ranging from small startups to large banks and healthcare providers—at significant risk.

These leaks could grant unauthorized users access to sensitive data, like RSA private keys, enabling attackers to impersonate servers, decrypt private communications, and potentially seize complete control over a company’s digital infrastructure. “This is a pressing issue impacting entities of all sizes,” states Nurula Demir from Stanford University, California.

Demir and colleagues conducted an analysis of 10 million web pages to identify the extent of exposed API credentials. API keys facilitate seamless communication between different software systems and serve as access tokens for cloud platforms, payment processing, and messaging services.

Through their web scans, the researchers validated 1,748 exposed credentials from 14 leading service providers, including Amazon Web Services, Stripe, GitHub, and OpenAI, found across approximately 10,000 compromised websites.

The accountability for these vulnerabilities lies not with the service providers, but with the developers and operators who misconfigured their websites. While the specific companies affected were not named, they reportedly include “global systemically important financial institutions,” firmware developers, and major hosting platforms.

“We have alerted all entities concerning identified exposures,” said DeMille. Approximately half of the organizations remedied their exposed API keys within two weeks; however, some did not respond.

On average, leaked credentials remain accessible for 12 months, with some lasting as long as five years. The majority (around 84%) of compromised credentials were located within the JavaScript environment, likely due to developers improperly using bundler tools for code packaging.

The remaining 16% originated from third-party resources, where misconfigured external plugins or scripts inadvertently exposed sensitive credentials online.

“None of these developers intended for their systems to be insecure,” explains Katie Paxton-Fear from Manchester Metropolitan University, UK. Issues arose due to programming intricacies, leading to accidental exposure. “They followed best practices, but vulnerabilities emerged during the development process,” she adds.

Leaking API keys is a “significant concern in modern software development,” notes Nick Nikiforakis from Stony Brook University, New York. “API keys replace user credentials, granting authorization without direct authentication. However, their misconfiguration can lead to serious security threats.”

DeMille emphasizes shared responsibility in addressing these vulnerabilities. “Developers must exercise caution in using API credentials,” he advises, alongside ensuring proper configuration of their development environments. He further suggests website-building tool creators should design systems to automatically hide private keys by default, rather than relying on developers to manage these protections manually, and that hosting companies should proactively monitor for exposed keys and disable them immediately.

Topic:

This version improves keyword density and enhances clarity while keeping HTML formatting intact.

Source: www.newscientist.com

The White House to Replace Covid Resources Page with Lab Leak Website

Visitors to Covid.gov, a federal website previously dedicated to Covid Resources, were met with a significant change on Friday.

The page now redirects to the White House Website, which proposes that Covid originated in a laboratory in Wuhan, China before spreading to humans. This “lab leak theory” gained traction early in the pandemic and has since gained popularity among some right-wing media and conservative politicians.

Whitehouse.gov

Prior to this change, covid.gov served as a platform to provide information on Covid vaccines, treatments, tests, and long-term effects. The website assisted users in locating pharmacies and community health centers for Covid-related services including testing, medical consultations, and medications.

Its companion site, Covidtests.gov, allowed individuals to order free Covid tests for home delivery. Both sites now redirect to the White House Lab Leak website.

White House spokesperson Kaelan Dole emphasized transparency, innovation, and protection in a statement, citing the Trump administration’s commitment to these values in contrast to previous administrations.

The new website draws heavily from a House of Representatives report released in December. This report suggested that Covid likely originated from a laboratory or research-related accident, based on a two-year investigation by a Republican-led subcommittee on the coronavirus pandemic.

Established in 2020 under Democratic control, the subcommittee initially scrutinized the Trump administration’s pandemic response. After Republicans gained a House majority in early 2023, the focus shifted towards investigating the lab leak theory and the efficacy of vaccine and mask mandates.

A separate December report from House Democrats contradicted the Republican findings, stating it did not definitively determine the virus’s origins or how it crossed to humans. The report acknowledged the possibility of lab leaks but also suggested natural transmission from animals as a potential source.

Both the Republican report and the White House website accuse Dr. Anthony Fauci, former director of the National Institute of Allergy and Infectious Diseases, of suppressing the lab leak theory. However, Democrats view these attacks as unfounded and politically motivated.

Several independent scientists argue against the lab leak theory, favoring natural zoonotic spillover events as the likely origin of the virus. These findings align with a survey of 168 scientists conducted by a nonpartisan think tank last year.

Similarly, a 2023 article in the New England Journal of Medicine concluded that the most scientifically supported scenario for the virus’s emergence is natural spillover from animals. The article highlighted the political entanglement of the issue and the likelihood that the true origin may remain elusive.

In 2023, a declassified report by the Director of National Intelligence acknowledged the plausibility of both lab leaks and natural animal origins. While the CIA expressed “low confidence” in favor of a lab leak in January, the conclusion remains uncertain.

The closure of covid.gov by the Trump administration coincides with significant budget cuts to Covid-related programs, including an $11.4 billion reduction in CDC funding and the discontinuation of NIH Covid research grants. This includes a $577 million initiative for developing oral antiviral drugs against potential pandemic pathogens.

The administration justified these cuts by asserting that “the pandemic is over,” according to a closing letter reviewed by NBC News.

Source: www.nbcnews.com

Test Your Knowledge: Can You Recognize Your Group Chat After the Signal Leak?

Hey, do you want to send it to your group chat? Likewise, are you sure about 1,000%?

Just check it. It was a strange week in the history of group chats, so it’s a seemingly intimate textual conversation that goes back and forth between friends, family and apparently national security officials.

On Monday, Atlantic Editor-in-Chief Jeffrey Goldberg. I wrote it That he was accidentally added to group chat with encrypted messaging app signals. He announced plans for the attack on the base of Houthi in Yemen, followed when other national security officials came up with plans for the attack after the celebration emoji.

Just as lawmakers on both sides of the aisle condemned the security breaches, Americans were seen as perceived and distrustful with their own unruly group chat.

“It’s clearly a very relevant screw-in,” Goldberg said. Interview With Tim Miller of Bluwork on Tuesday. “We all texted the wrong people,” he added.

However, these careless texts do not contain high-stakes national security information that is usually shared outside of secure government channels.

The incident could be “the most shocking stupid group chat error in history,” said Tommy Beiotter, a liberal podcaster and former National Security Council spokesman. X’s Video. In the same post, he confessed that he was in an email thread that once mistakenly included singer Lyle Lovett in place of his colleague John Lovett. Approximately 30 emails had been sent before anyone noticed.

Group chat has quietly become a staple of modern communication since 2008, when Apple enabled text messaging with multiple recipients. Private group chats award a kind of juicy intimacy to a book club member, a neighbor’s mom, work friends, or a large family who exchanges hundreds of messages per day.

Feeds tend to be less self-conscious than posts on social media. In 2022, a guest essay from the New York Times declared the group chat “leave the last place online for real conversations.”

Even people with no security clearance are aware of what they share with the pleasant familiarity of group chats. Clayton Fletcher, 48, is part of the WhatsApp group, where he and about 35 other comedians roast each other and tackle new ingredients. He is wary high when a new phone number appears. It didn’t appear to happen when Goldberg was added to the signal chat.

“The wisdom of a comedian’s age is to know your audience,” Fletcher said. “In the modern world, I think it’s like knowing who’s in group chat.”

The intimacy of group chats is often elaborate when it spills into the public eye. In 2021, an anonymous leaker shared a group message from Sen. Ted Cruz’s wife, Heidi Cruz, where she planned a trip to Cancun, but millions of members of the senators had no electricity. (Heidi Cruz clearly didn’t understand that group chats didn’t know loyalty,” Jezebel said. read. )

In 2023, the New York Times published a text between the Fox News hosts, which were completely different from the official statement on the 2020 election results. And last year, Daily Beast reported Former House member George Santos texted the humiliation to a group chat that includes members of a New York Republican delegation.

“Sorry, new phone, who’s diss?” Representative Andrew Garbarino I responded.

Our group chats may include people who extend to our professionals and personal lives and who have strong and loose social connections to which we have. It could make them a “minefield” for error, said LM Chilton, author of the upcoming thriller “Everyone in the Group Chat Dies.”

The signal group chat incident was colloquial and especially uncomfortable due to just the tone of Amon Friends (including emojis). And while it may be easy to blame the technology for violations, it was a mistake by national security adviser Michael Waltz to make it accessible to journalists to group chats.

“At the end of the day, it was an artificial mistake and it was with us from the dawn of time,” Chilton said.

New York writer Matt Buquere, 35, found a bit of a dark humor in the way that members of the Signal Group introduced themselves one by one.

Everyone has been added to a group chat where they do not belong to completely. However, he suggested not to stand out unless he was certain he could trust the rest of the group.

“If you have a lot of numbers you don’t know, you should limit group chat participation to thumbs up or ‘haha’ reactions. There’s nothing else,” he said.

Source: www.nytimes.com

Helium leak detected and delays SpaceX Polaris launch

A SpaceX spacecraft set to carry four civilians on a mission into space is facing a delay due to a helium leak, pushing the launch to later this week.

The crew includes billionaire entrepreneur Jared Isaacman, retired Air Force Lt. Col. Scott Kidd, and SpaceX engineers Sarah Gillis and Anna Menon. They were all geared up for a mission that would mark the first spacewalk by a civilian crew.

The mission, known as Polaris Dawn, was initially slated for an early Tuesday launch from NASA’s Kennedy Space Center in Florida. However, SpaceX published a statement on X indicating that the helium leak discovery will likely push the launch to Wednesday at the earliest.

“Teams are currently investigating a ground-side helium leak in the quick-disconnect umbilical in detail,” the company reported. “Falcon and Dragon remain in good condition, with crews ready for their multi-day journey to low Earth orbit.”

The helium leak setback comes as a disappointment for SpaceX, which has been responsible for transporting NASA astronauts to the International Space Station since 2020. In 2021, SpaceX launched its first private citizen into orbit – a mission that was also funded and participated in by Isaacman to raise funds for St. Jude Children’s Research Hospital.

The highlight of the upcoming mission, the spacewalk, is expected to occur on the third day. Two crew members will be tethered out of the Crew Dragon spacecraft, with all astronauts equipped in newly designed space suits as the capsule undergoes depressurization to create a vacuum.

Traditionally, only astronauts from government space agencies have ventured into space for tasks such as building or upgrading orbital space stations, satellite repairs, or scientific experiments.

The Crew Dragon capsule is set to reach an altitude of 870 miles above Earth’s surface – surpassing the orbital altitude of the International Space Station by three times. This height will allow the capsule to navigate through the inner region of the Van Allen radiation belts, a zone with high-energy radiation particles trapped in Earth’s magnetosphere.

The Polaris Dawn flight aims to study the effects of space radiation on astronauts and spacecraft, valuable research that could assist SpaceX in planning future missions to the Moon and Mars where astronauts will need to navigate both inside and outside of the Van Allen radiation belts.

Polaris Dawn is just one of three spaceflights that Isaacman is co-sponsoring and organizing with SpaceX. Details regarding the cost of the mission and the objectives of the other upcoming missions remain undisclosed for now.

Source: www.nbcnews.com

Leak Indicates Israel Attempted to Prevent US Lawsuit Involving Pegasus Spyware | Israel

The Israeli government has blocked a costly U.S. lawsuit that could reveal secrets about a hacking tool called Pegasus. Documents suggest the Israeli authorities seized Pegasus spyware documentation from NSO Group to prevent the disclosure of sensitive information.

Pegasus is used to infect smartphones with hidden software that can extract data and spy on users. NSO Group’s customers include both authoritarian regimes and democracies, raising concerns about human rights abuses.

NSO has been fighting a lawsuit alleging WhatsApp vulnerabilities were exploited, compromising users in multiple countries. Israel’s close ties with NSO and the impact of the seizures on the legal battle have raised questions about the country’s involvement.

Media organizations are trying to uncover the details of the seizures and Israel’s interference in the case, shedding light on the complex relationship between NSO, Israel, and the legal system.

The documents obtained reveal the extent of Israel’s efforts to protect NSO from disclosing sensitive information demanded by the U.S. court, impacting the ongoing legal proceedings.

Israel’s covert actions have complicated WhatsApp’s attempts to obtain crucial information from NSO, highlighting the challenges faced in the legal battle.

The leaked files and emails provide insight into the behind-the-scenes activities and the attempts to prevent the exposure of sensitive information related to the Pegasus spyware.

“Strange Procedure”

Israel’s intervention in the lawsuit has raised concerns about the transparency of the legal process and the protection of national interests.


Do you have information about this story? Email stephanie.kirchgaessner@theguardian.com or send a message (from a non-work phone) using Signal or WhatsApp to +1 646 886 8761.

The legal battle between WhatsApp and NSO has revealed underlying complexities and challenges posed by the lawsuit, reflecting the broader implications of the case.

NSO’s actions and Israel’s involvement have significantly influenced the course of the lawsuit, raising questions about transparency and accountability in the legal process.

Additional reporting by Phineas Rueckert and Karine Pfenniger of Forbidden Stories.

Source: www.theguardian.com

Google to reveal oil and gas methane leak detected from space

Google and the Environmental Defense Fund on Wednesday announced a partnership to uncover the sources of climate-warming emissions from oil and gas operations that will be detected from space by a new satellite.

MethaneSAT is scheduled to launch next month and is one of several satellites being deployed to monitor methane emissions around the world to identify the main sources of the invisible but powerful greenhouse gas. There is one. The partnership is led by EDF, the New Zealand Space Agency, Harvard University and others.

Data from the satellite will be available later this year, and Google Cloud will provide the computing power to process the information.

Google also announced that it will use artificial intelligence to map oil and gas infrastructure by identifying components such as oil tanks. MethaneSAT emissions data is overlaid with Google Maps to help you understand which types of oil and gas equipment are most likely to leak.

This information will be made available through Google Earth Engine, a geospatial analytics platform, later this year. Earth Engine is free to researchers, nonprofit organizations, and news organizations.

The satellite image above shows a map of points, correctly identified as oil well pads. Google used satellite and aerial imagery to apply AI to detect infrastructure components. Well pads are shown in yellow, oil pump jacks in red, and storage tanks in blue.
Google

“For energy companies, researchers, and the public sector, it's generally helpful to predict methane emissions in the most sensitive components,” Yael Maguire, Google's vice president of geographic sustainability, said on a call with reporters. “We believe this information is extremely valuable for mitigation efforts.”

The launch comes as governments crack down on short-lived sources of greenhouse gases and more than 50 major state-owned and independent oil and gas operators, from ExxonMobil to Saudi Aramco, pledge to reduce methane leakage to near zero at the COP28 climate change summit. This was done amid a promise to reduce the number of By the end of this decade.

The United States is one of the largest emitters of methane and has proposed enforcement measures to stop leaks from oil and gas operations. A new rule by the U.S. Environmental Protection Agency will allow the public to report large methane leaks to federal regulators if they have access to methane detection technology.

Source: www.nbcnews.com