Skip to main content

Tag: api key management

2 articles

Dimly lit server room with rows of computer servers and networking equipment, and a blurred laptop screen in the foreground.

LiteLLM Gateways Expose Cloud Credentials to Risk with Default Admin Key

Thousands of LiteLLM gateways are leaving cloud credentials vulnerable due to a shocking security flaw: nearly 300 online gateways accepted a default admin key, granting hackers unrestricted access to sensitive data and cloud accounts. This easily exploitable weakness puts countless organizations at risk of devastating breaches.

Analyst 207
Unoccupied workstation with laptop and technical equipment in a brightly-lit server room.

Google API Keys Remain Usable for 23 Minutes After Deletion

Deleting a Google API key doesn't mean it's immediately useless to hackers - in fact, our experiments show it can remain active for up to 23 minutes, allowing attackers to continue misusing it even after you've tried to revoke access.

Analyst 207