Daily Guardian UAEDaily Guardian UAE
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
What's On

Aster DM Healthcare to invest in International Modern Hospital as part of its AED 1bn+ UAE Healthcare investment programme over the next 5 years 

September 15, 2026

From Emirates to the World: Oud of London Expands Its Global Journey

September 15, 2026

GEMS School of Research & Innovation launches specialist

September 15, 2026

The Gulf Region Solidifies Its Position as a Strategic Anchor of Global Luxury Growth

September 15, 2026

Advanced Technology Pioneers Competition Opens for Applications, Putting Real UAE Industry Challenges into the Hands of Emerging Talent

September 15, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian UAE
Subscribe
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
Daily Guardian UAEDaily Guardian UAE
Home » A simple coding mistake is exposing API keys across thousands of websites
Technology

A simple coding mistake is exposing API keys across thousands of websites

By dailyguardian.aeMarch 27, 20262 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

After analyzing 10 million webpages, researchers have found thousands of websites accidentally exposing sensitive API credentials, including keys linked to major services like Amazon Web Services, Stripe, and OpenAI.

This is a serious issue because APIs act as the backbone of the apps we use today. They allow websites to connect to services like payments, cloud storage, and AI tools, but they rely on digital keys to stay secure. Once exposed, API keys can allow anyone to interact with those services with malicious intent.

Sensitive API keys exposed across thousands of sites

According to TechXplore, the researchers identified 1,748 unique API credentials across nearly 10,000 webpages, tied to 14 major service providers. These leaks were not limited to obscure sites, with some appearing on platforms run by global banks and major software developers.

Around 84% of these leaks came from JavaScript files, which are easily accessible through a browser. This means the credentials were effectively sitting in publicly visible code.

Even more concerning is how long these keys remained exposed. Some were visible for up to 12 months, while a few rare cases showed credentials staying public for several years without detection.

So, what’s causing these leaks?

The study makes it clear that the problem does not lie with service providers like Amazon, Stripe, or OpenAI. Instead, the issue stems from how developers handle API keys.

In many cases, developers accidentally include private API credentials in the front-end code of a website, leaving it visible to anyone who knows where to look.

How to stop API keys from being exposed?

To prevent future leaks, the researchers suggest a few practical steps. Developers should scan the live version of their websites, and not just private code, to catch exposed keys.

graphic image of cybersecurity

With the rise of vibecoding, companies need stricter rules for automated website-building tools that handle sensitive data during deployment. This is also why platforms like Lovable have started adding safe browsing tools to protect users from poorly vibecoded websites.

Meanwhile, service providers need to improve detection systems to flag exposed keys the moment they appear online. Although responsible disclosure helped reduce some of these leaks, the scale of the issue remains significant.

Recent reports have also shown how simply visiting a website can expose your device to serious risks, highlighting how fragile web security can be for everyday internet users.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Lenovo AeroBlade imagines a laptop as thin as a foldable phone, thanks to solid-state cooling

Lenovo puts Nvidia RTX Spark into its new Yoga Pro laptops for local AI at IFA 2026

Motorola’s new Edge 70 Plus packs a 200MP camera and a massive battery

We got GTA VI limited-edition DualSense controllers before GTA VI

Anker unveils smarter chargers and power banks built to fight heat and battery degradation

Anker’s new Soundcore Sleep earbuds can mask snoring and even track your heart rate

TCL P80 series finally marries eye-friendly NXTPAPER tech with an AMOLED panel

Anker’s new MindBase wants to be the brain of your entire home security system

I found 5 cleaning deals worth sweeping up this Labor Day

Editors Picks

From Emirates to the World: Oud of London Expands Its Global Journey

September 15, 2026

GEMS School of Research & Innovation launches specialist

September 15, 2026

The Gulf Region Solidifies Its Position as a Strategic Anchor of Global Luxury Growth

September 15, 2026

Advanced Technology Pioneers Competition Opens for Applications, Putting Real UAE Industry Challenges into the Hands of Emerging Talent

September 15, 2026

Subscribe to News

Get the latest UAE news and updates directly to your inbox.

Latest Posts

الذهب في أسبوع الحسم.. هل يؤجّل الفيدرالي حلم الـ5,000 دولار؟

September 15, 2026

Al Masraf and Moody’s Sign Strategic Agreement to Strengthen Risk Intelligence and Credit Capabilities

September 15, 2026

Dealing.com Redefines Online Investing with a Simpler, Smarter AI-Powered Experience

September 15, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian UAE. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.