Google API Keys Remain Active After Deletion
2026-05-21T20:51:37Z•c2233bd054479cda470d1c5b1e74b37335d9609a192f0d92430db5ca1b697cbe
CVE-2026-42897ai-agentsai-bomapi-keysaptbrand-hijackingcisco-sd-wancloud-securitycvss-10.0data-theftdomain-frontingexchange-zero-daygithub-breachidentity-managementincident-responselinux-backdoormacos-malwaremobile-fraudot-securityransomwareroboticsruby-gemssecret-exposuresupply-chaintelco-security
What happened
This Dark Reading feed highlights a surge of high-impact incidents and trending security themes: a Google API key deletion flaw allowing keys to remain active for ~23 minutes; GitHub confirming a breach with ~4,000 internal repos stolen (attributed to TeamPCP); an active Microsoft Exchange zero-day (CVE-2026-42897) targeting OWA mailboxes; a CVSS 10.0 Cisco SD‑WAN vulnerability being exploited in the wild; a critical unauthenticated command-injection flaw in an OT robot OS; targeted Chinese APT campaigns (Showboat, FamousSparrow) using Linux backdoors against telcos and energy firms; the Under
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- c2233bd054479cda470d1c5b1e74b37335d9609a192f0d92430db5ca1b697cbe
- Enrichment time
- 2026-05-21T20:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.