Researchers scan 10 million websites and uncover thousands of exposed API keys quietly allowing access to cloud systems and critical infrastructure


  • Thousands of exposed API keys quietly allow access to critical systems
  • Public web pages contain credentials that unlock cloud and payment services
  • Developers unknowingly leave sensitive API tokens embedded in live websites

Security researchers from Stanford University, UC Davis and TU Delft say sensitive API credentials are out in the open on thousands of public web pages with very little protection.

According to a preprint version of the study on arXiv, the researchers analyzed 10 million web pages and identified 1,748 valid credentials displayed on nearly 10,000 pages.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top