50,000 Stripe Secrets Leaked in Public Code

2026-08-19T08:51:35Z05ffd57d10f08b23ec5c5bb312bdb99fe86efcec5105d4dbe07f813d3074b435
CVE-2025-62593CVE-2026-19478CVE-2026-33824API keysApple macOSCISA KEVDDoSEvooo1BotGitHub ActionsGitLabGraphQLLinux malwareLiteLLMMicrosoft SharePointMirai botnetRaySSH brute forceVMware vCenterWindows IKEactively exploited vulnerabilitiescloud securitydata breachexposed secretssupply-chain attackunauthenticated remote access

What happened

SecurityAffairs reports a broad set of cybersecurity incidents and vulnerabilities, including more than 50,000 exposed Stripe API keys, a critical unauthenticated GitLab GraphQL vulnerability (CVE-2026-19478), actively exploited vulnerabilities added to CISA's KEV catalog, the Evooo1Bot Mirai-based Linux botnet, a LiteLLM software supply-chain attack, and multiple data breaches affecting millions of customers. The collection also covers attacks against AI surveillance systems and prompt-injection abuse.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
05ffd57d10f08b23ec5c5bb312bdb99fe86efcec5105d4dbe07f813d3074b435
Enrichment time
2026-08-19T08:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 50,000 Stripe Secrets Leaked in Public Code · Baitaphish