Google API Keys Remain Active After Deletion

2026-05-21T20:51:37Zc2233bd054479cda470d1c5b1e74b37335d9609a192f0d92430db5ca1b697cbe
CVE-2026-42897ai-agentsai-bomapi-keysaptbrand-hijackingcisco-sd-wancloud-securitycvss-10.0data-theftdomain-frontingexchange-zero-daygithub-breachidentity-managementincident-responselinux-backdoormacos-malwaremobile-fraudot-securityransomwareroboticsruby-gemssecret-exposuresupply-chaintelco-security

What happened

This Dark Reading feed highlights a surge of high-impact incidents and trending security themes: a Google API key deletion flaw allowing keys to remain active for ~23 minutes; GitHub confirming a breach with ~4,000 internal repos stolen (attributed to TeamPCP); an active Microsoft Exchange zero-day (CVE-2026-42897) targeting OWA mailboxes; a CVSS 10.0 Cisco SD‑WAN vulnerability being exploited in the wild; a critical unauthenticated command-injection flaw in an OT robot OS; targeted Chinese APT campaigns (Showboat, FamousSparrow) using Linux backdoors against telcos and energy firms; the Under

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
c2233bd054479cda470d1c5b1e74b37335d9609a192f0d92430db5ca1b697cbe
Enrichment time
2026-05-21T20:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.