50,000 Stripe Secrets Leaked in Public Code
2026-08-19T08:51:35Z•05ffd57d10f08b23ec5c5bb312bdb99fe86efcec5105d4dbe07f813d3074b435
CVE-2025-62593CVE-2026-19478CVE-2026-33824API keysApple macOSCISA KEVDDoSEvooo1BotGitHub ActionsGitLabGraphQLLinux malwareLiteLLMMicrosoft SharePointMirai botnetRaySSH brute forceVMware vCenterWindows IKEactively exploited vulnerabilitiescloud securitydata breachexposed secretssupply-chain attackunauthenticated remote access
What happened
SecurityAffairs reports a broad set of cybersecurity incidents and vulnerabilities, including more than 50,000 exposed Stripe API keys, a critical unauthenticated GitLab GraphQL vulnerability (CVE-2026-19478), actively exploited vulnerabilities added to CISA's KEV catalog, the Evooo1Bot Mirai-based Linux botnet, a LiteLLM software supply-chain attack, and multiple data breaches affecting millions of customers. The collection also covers attacks against AI surveillance systems and prompt-injection abuse.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 05ffd57d10f08b23ec5c5bb312bdb99fe86efcec5105d4dbe07f813d3074b435
- Enrichment time
- 2026-08-19T08:51:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.