Researchers found thousands of exposed API keys across 10 million webpages, including AWS, Stripe, and OpenAI credentials left vulnerable in public code.
Claude extension flaw allowed zero click attacks, letting hackers inject commands and access sensitive user data.