Tag: api abuse
6 articles

Japan's Web Data Leaks Surge Amid API Abuse and Metabase Attacks
Japan is facing a surge in web data leaks, with 81 incidents reported from July onwards, and experts point to a wave of API abuse and targeted exploitation of a Metabase flaw as the main culprits. In just a few months, personal data from millions of accounts has been stolen, including sensitive info like driver's license images.

OpenAI Agents Expose Unauthorized Wikipedia Edits and API Abuse
Wikimedia's Chief Product and Technology Officer, Selena Deckelmann, revealed that OpenAI's AI agents have been making unauthorized edits to Wikipedia, sparking concerns over API abuse and automated activity on the platform. This comes as Wikimedia handles a massive scale of traffic, with 67 million articles and 15 billion page views per month, and 65% of its resource-heavy traffic coming from bots.

Gitea Servers Exposed to Ongoing Code Execution Attacks
Thousands of Gitea servers remain vulnerable to code execution attacks, with 8393 Internet-exposed IPs still susceptible to CVE-2026-60004, a code injection bug that lets attackers execute arbitrary shell commands. This flaw can be easily exploited by anyone with write access to a repository, which is especially concerning since Gitea enables self-registration by default.

Gitea Flaw Exploited to Deploy Miner-Like Payload
Hackers are actively exploiting a critical flaw in Gitea to deploy malicious payloads, including miner-like attacks, by abusing the diffpatch endpoint to install and execute Git hooks. This vulnerability allows attackers with repository write access to inject code and run shell commands, prompting a warning from the US Cybersecurity and Infrastructure Security Agency (CISA).

Gitea Flaw Lets Writers Run Shell Commands via Git Hook
A newly discovered vulnerability in Gitea, rated 9.8 in severity, allows ordinary repository writers to execute shell commands as the Gitea service account by exploiting a remote code execution bug via a cleverly planted Git hook. This critical flaw, tracked as CVE-2026-60004, puts Gitea users at risk of a devastating attack.

GitHub Accounts Used to Map Corporate Orgs in Stealthy Campaigns
Cyber attackers are using sneaky tactics, leveraging old or compromised GitHub accounts, to secretly map out corporate organizations and steal sensitive data. They're exploiting loopholes with automated tools and stolen tokens to quietly gather intel from GitHub APIs.