Recent data breaches have exposed sensitive information from multiple applications. The Flat Earth Sun, Moon & Zodiac app, operated by 'Flat Earth Dave', reported a breach affecting 33,294 unique email addresses, with data including plain text passwords and users' latitude and longitude coordinates. Notably, 73% of the affected accounts were already listed in the Have I Been Pwned database. Additionally, the Color Dating app experienced a breach in 2018, impacting 220,503 unique email addresses, with compromised data including names, bios, photos, and bcrypt password hashes; 59% of these accounts were also found in the Have I Been Pwned database. Furthermore, a report from Truffle Security revealed that nearly 12,000 hardcoded API keys and passwords were discovered in the Common Crawl dataset, which is utilized to train large language models. These exposed secrets include keys from services like AWS and MailChimp, raising concerns about security vulnerabilities in AI training datasets.
Roughly 12,000 hardcoded live API keys and passwords were found on Common Crawl, a large dataset used to train LLMs such as DeepSeek, @trufflesec reported. #cybersecurity #infosec #ITsecurity #AI #LLM https://t.co/9T9Uoecvh5
Research from Truffle Security has revealed that nearly 12,000 valid API keys and passwords were found in the Common Crawl dataset, used to train large language models (LLMs). These sensitive secrets, including AWS and MailChimp API keys, were hardcoded into HTML and… https://t.co/tyehMuIml1
Nearly 12,000 API keys and passwords found in AI training dataset https://t.co/rG64g1HPNC