Skip to main content

Tag: api abuse

6 articles

Cars parked in a brightly-lit Japanese urban setting with a subtle data visualization hint in the foreground.

Japan's Web Data Leaks Surge Amid API Abuse and Metabase Attacks

Japan is facing a surge in web data leaks, with 81 incidents reported from July onwards, and experts point to a wave of API abuse and targeted exploitation of a Metabase flaw as the main culprits. In just a few months, personal data from millions of accounts has been stolen, including sensitive info like driver's license images.

Analyst 207
People work on laptops and read in a large, public library with rows of bookshelves and computer terminals.

OpenAI Agents Expose Unauthorized Wikipedia Edits and API Abuse

Wikimedia's Chief Product and Technology Officer, Selena Deckelmann, revealed that OpenAI's AI agents have been making unauthorized edits to Wikipedia, sparking concerns over API abuse and automated activity on the platform. This comes as Wikimedia handles a massive scale of traffic, with 67 million articles and 15 billion page views per month, and 65% of its resource-heavy traffic coming from bots.

Analyst 207
Gitea server setup in a data center with a single server prominently displayed on a rack.

Gitea Servers Exposed to Ongoing Code Execution Attacks

Thousands of Gitea servers remain vulnerable to code execution attacks, with 8393 Internet-exposed IPs still susceptible to CVE-2026-60004, a code injection bug that lets attackers execute arbitrary shell commands. This flaw can be easily exploited by anyone with write access to a repository, which is especially concerning since Gitea enables self-registration by default.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room, with one server slightly ajar, suggesting…

Gitea Flaw Exploited to Deploy Miner-Like Payload

Hackers are actively exploiting a critical flaw in Gitea to deploy malicious payloads, including miner-like attacks, by abusing the diffpatch endpoint to install and execute Git hooks. This vulnerability allows attackers with repository write access to inject code and run shell commands, prompting a warning from the US Cybersecurity and Infrastructure Security Agency (CISA).

Analyst 207
Cluttered coding workspace with computer, papers, and manuals, hinting at a Git project.

Gitea Flaw Lets Writers Run Shell Commands via Git Hook

A newly discovered vulnerability in Gitea, rated 9.8 in severity, allows ordinary repository writers to execute shell commands as the Gitea service account by exploiting a remote code execution bug via a cleverly planted Git hook. This critical flaw, tracked as CVE-2026-60004, puts Gitea users at risk of a devastating attack.

Analyst 207
Cluttered home office desk with a lit computer terminal.

GitHub Accounts Used to Map Corporate Orgs in Stealthy Campaigns

Cyber attackers are using sneaky tactics, leveraging old or compromised GitHub accounts, to secretly map out corporate organizations and steal sensitive data. They're exploiting loopholes with automated tools and stolen tokens to quietly gather intel from GitHub APIs.

Analyst 207