Tag: api key management
2 articles

LiteLLM Gateways Expose Cloud Credentials to Risk with Default Admin Key
Thousands of LiteLLM gateways are leaving cloud credentials vulnerable due to a shocking security flaw: nearly 300 online gateways accepted a default admin key, granting hackers unrestricted access to sensitive data and cloud accounts. This easily exploitable weakness puts countless organizations at risk of devastating breaches.

Google API Keys Remain Usable for 23 Minutes After Deletion
Deleting a Google API key doesn't mean it's immediately useless to hackers - in fact, our experiments show it can remain active for up to 23 minutes, allowing attackers to continue misusing it even after you've tried to revoke access.