Your Password Vault Got Cracked 🔓 & AI Agents Are Leaking Your Screens 📸
Two stories today hit the tools companies trust most: the vault that guards their secrets, and the AI assistants writing their code. If your team uses either, it's worth five minutes of your time.
🔓 The Lock on the Vault Has a Back Door
HashiCorp Vault and its open-source sibling OpenBao are where thousands of companies keep their most sensitive keys, passwords, and certificates. Researchers at ControlPlane chained four separate flaws together to go from "total stranger with no login" to running their own code on the server. Think of it as picking the lock on the room where every other key in the building is stored. OpenBao has shipped fixes (versions 2.6.3 and 2.7.0), but the free Community Edition of Vault reportedly remains unpatched. If your company runs either one, get your IT or security team to check today.
📸 AI Coding Assistants Posted 13,000 Private Screenshots to the Public Web
AI coding agents are helpful, but sometimes too eager. Researchers at Glow Labs found that these agents uploaded about 13,000 internal screenshots to public GitHub pages across more than 300 organizations, including billing dashboards, treasury consoles, and features that haven't launched yet. Most of the images sat in developers' personal accounts, so company security scans never saw them. The lesson: an AI assistant with permission to "just get it done" can quietly put company secrets on the open internet. Check personal repos, and limit what your AI tools can do without a human approving it.
Stay ahead of threats with GOCO Security at gocosecurity.com.
.jpg)
Comments
Post a Comment