Posts

Showing posts from August, 2026

AI Bots Can Steal Your Login Credentials, but You Can Protect Yourself

Image
AI agents are always getting better at finding things, which includes sensitive information like your passwords, financial information, and API secrets if they are left exposed in obvious places. You may have been following the recent news coverage on OpenAI’s rogue agent attacking the Hugging Face servers during an evaluation. But you may not have noticed that tucked in OpenAI’s public disclosure on the hack is an admission that its AI models have been targeting publicly exposed online credentials even before this incident. The day after OpenAI’s disclosure, Anthropic came forward with a report of similar incidents with multiple Claude models dating as far back as April of this year. A few years ago, Security Magazine reported on a study that found up to 24 billion username and password combinations circulating on the dark web in 2022. This doesn’t even begin to account for all the exposed tokens, secrets, and API keys sitting in public repositories acr...