• bitcoinBitcoin (BTC) $ 90,471.00
  • ethereumEthereum (ETH) $ 3,086.28
  • tetherTether (USDT) $ 0.998763
  • xrpXRP (XRP) $ 2.09
  • bnbBNB (BNB) $ 905.52
  • solanaSolana (SOL) $ 136.01
  • usd-coinUSDC (USDC) $ 1.00
  • tronTRON (TRX) $ 0.302509
  • staked-etherLido Staked Ether (STETH) $ 3,085.25
  • dogecoinDogecoin (DOGE) $ 0.138943
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.00
  • cardanoCardano (ADA) $ 0.388141
  • bitcoin-cashBitcoin Cash (BCH) $ 644.28
  • wrapped-stethWrapped stETH (WSTETH) $ 3,776.47
  • whitebitWhiteBIT Coin (WBT) $ 55.04
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,354.43
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 90,292.00
  • wrapped-eethWrapped eETH (WEETH) $ 3,348.15
  • usdsUSDS (USDS) $ 0.999659
  • chainlinkChainlink (LINK) $ 13.14
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998618
  • moneroMonero (XMR) $ 476.39
  • leo-tokenLEO Token (LEO) $ 9.05
  • wethWETH (WETH) $ 3,084.77
  • stellarStellar (XLM) $ 0.225942
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 90,492.00
  • suiSui (SUI) $ 1.79
  • ethena-usdeEthena USDe (USDE) $ 0.999200
  • litecoinLitecoin (LTC) $ 81.15
  • zcashZcash (ZEC) $ 375.54
  • avalanche-2Avalanche (AVAX) $ 13.69
  • hyperliquidHyperliquid (HYPE) $ 24.07
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • hedera-hashgraphHedera (HBAR) $ 0.117340
  • canton-networkCanton (CC) $ 0.130250
  • usdt0USDT0 (USDT0) $ 0.998703
  • daiDai (DAI) $ 0.998803
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.166559
  • susdssUSDS (SUSDS) $ 1.09
  • the-open-networkToncoin (TON) $ 1.74
  • crypto-com-chainCronos (CRO) $ 0.100831
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • uniswapUniswap (UNI) $ 5.48
  • polkadotPolkadot (DOT) $ 2.09
  • usd1-wlfiUSD1 (USD1) $ 0.999605
  • mantleMantle (MNT) $ 0.978550
  • rainRain (RAIN) $ 0.009024
  • memecoreMemeCore (M) $ 1.74
  • bittensorBittensor (TAO) $ 279.15
  • aaveAave (AAVE) $ 164.86
  • pepePepe (PEPE) $ 0.000006
  • bitget-tokenBitget Token (BGB) $ 3.50
  • tether-goldTether Gold (XAUT) $ 4,500.26
  • okbOKB (OKB) $ 109.99
  • nearNEAR Protocol (NEAR) $ 1.69
  • falcon-financeFalcon USD (USDF) $ 0.996123
  • jito-staked-solJito Staked SOL (JITOSOL) $ 170.47
  • ethereum-classicEthereum Classic (ETC) $ 12.52
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.179185
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,083.42
  • ethenaEthena (ENA) $ 0.226889
  • pi-networkPi Network (PI) $ 0.208299
  • internet-computerInternet Computer (ICP) $ 3.18
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pax-goldPAX Gold (PAXG) $ 4,515.91
  • aster-2Aster (ASTER) $ 0.717116
  • htx-daoHTX DAO (HTX) $ 0.000002
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.73
  • worldcoin-wldWorldcoin (WLD) $ 0.571111
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • global-dollarGlobal Dollar (USDG) $ 0.999682
  • binance-staked-solBinance Staked SOL (BNSOL) $ 148.51
  • kucoin-sharesKuCoin (KCS) $ 10.80
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • ripple-usdRipple USD (RLUSD) $ 0.999572
  • aptosAptos (APT) $ 1.81
  • pump-funPump.fun (PUMP) $ 0.002298
  • skySky (SKY) $ 0.058883
  • wbnbWrapped BNB (WBNB) $ 905.21
  • bfusdBFUSD (BFUSD) $ 0.998536
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999707
  • hash-2Provenance Blockchain (HASH) $ 0.023993
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,561.60
  • ondo-financeOndo (ONDO) $ 0.399442
  • cosmosCosmos Hub (ATOM) $ 2.57
  • kaspaKaspa (KAS) $ 0.046241
  • render-tokenRender (RENDER) $ 2.28
  • arbitrumArbitrum (ARB) $ 0.206687
  • algorandAlgorand (ALGO) $ 0.133523
  • gatechain-tokenGate (GT) $ 10.22
  • midnight-3Midnight (NIGHT) $ 0.069428
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,274.03
  • filecoinFilecoin (FIL) $ 1.48
  • quant-networkQuant (QNT) $ 74.11
  • official-trumpOfficial Trump (TRUMP) $ 5.39
  • bridged-wrapped-lido-staked-ether-scrollBridged Wrapped Lido Staked Ether (Scroll) (WSTETH) $ 3,763.20
  • ignition-fbtcFunction FBTC (FBTC) $ 93,168.00
  • vechainVeChain (VET) $ 0.011668
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 90,689.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 90,261.00
  • nexoNEXO (NEXO) $ 0.968006
  • myx-financeMYX Finance (MYX) $ 4.93
  • xdce-crowd-saleXDC Network (XDC) $ 0.048431
  • flare-networksFlare (FLR) $ 0.011168
  • bonkBonk (BONK) $ 0.000010
  • usddUSDD (USDD) $ 0.998497
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • usdtbUSDtb (USDTB) $ 0.999567
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,341.75
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,272.75
  • ousgOUSG (OUSG) $ 113.92
  • sei-networkSei (SEI) $ 0.120128
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.95
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999671
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.011887
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999702
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 90,259.00
  • blockstackStacks (STX) $ 0.396087
  • morphoMorpho (MORPHO) $ 1.29
  • clbtcclBTC (CLBTC) $ 90,541.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.05
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,293.52
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.04
  • story-2Story (IP) $ 2.00
  • beldexBeldex (BDX) $ 0.088646
  • jupiter-exchange-solanaJupiter (JUP) $ 0.208760
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 158.00
  • usdaiUSDai (USDAI) $ 1.00
  • lighterLighter (LIT) $ 2.59
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • wrapped-flareWrapped Flare (WFLR) $ 0.011164
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.280074
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,084.74
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,267.06
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999472
  • tezosTezos (XTZ) $ 0.581273
  • optimismOptimism (OP) $ 0.317178
  • curve-dao-tokenCurve DAO (CRV) $ 0.406439
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • usual-usdUsual USD (USD0) $ 0.997667
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.29
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,084.77
  • c8ntinuumc8ntinuum (CTM) $ 0.125739
  • tbtctBTC (TBTC) $ 90,456.00
  • spx6900SPX6900 (SPX) $ 0.577770
  • lido-daoLido DAO (LDO) $ 0.630941
  • injective-protocolInjective (INJ) $ 5.20
  • chilizChiliz (CHZ) $ 0.050650
  • flokiFLOKI (FLOKI) $ 0.000051
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998210
  • ghoGHO (GHO) $ 0.997960
  • true-usdTrueUSD (TUSD) $ 0.997206
  • gtethGTETH (GTETH) $ 3,083.94
  • aerodrome-financeAerodrome Finance (AERO) $ 0.536009
  • ether-fiEther.fi (ETHFI) $ 0.732063
  • celestiaCelestia (TIA) $ 0.545957
  • fasttokenFasttoken (FTN) $ 1.08
  • dashDash (DASH) $ 37.24
  • msolMarinade Staked SOL (MSOL) $ 183.70
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • syrupMaple Finance (SYRUP) $ 0.394037
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,330.88
  • the-graphThe Graph (GRT) $ 0.041672
  • stader-ethxStader ETHx (ETHX) $ 3,325.35
  • newton-projectAB (AB) $ 0.004469
  • iotaIOTA (IOTA) $ 0.101042
  • jasmycoinJasmyCoin (JASMY) $ 0.008645
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,454.88
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.210679
  • bittorrentBitTorrent (BTT) $ 0.00000042
  • sbtc-2sBTC (SBTC) $ 91,192.00
  • starknetStarknet (STRK) $ 0.081650
  • justJUST (JST) $ 0.041026
  • usdbUSDB (USDB) $ 0.995877
  • staked-aaveStaked Aave (STKAAVE) $ 163.90
  • doublezeroDoubleZero (2Z) $ 0.115167
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.40
  • sun-tokenSun Token (SUN) $ 0.020622
  • conflux-tokenConflux (CFX) $ 0.076544
  • pyth-networkPyth Network (PYTH) $ 0.067267
  • bitcoin-svBitcoin SV (BSV) $ 19.31
  • pippinpippin (PIPPIN) $ 0.384480
  • dogwifcoindogwifhat (WIF) $ 0.378100
  • kaiaKaia (KAIA) $ 0.064109
  • fartcoinFartcoin (FARTCOIN) $ 0.371406
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.886775
  • apenftAINFT (NFT) $ 0.00000037
  • gnosisGnosis (GNO) $ 137.79
  • cap-usdCap USD (CUSD) $ 1.00
  • wrapped-stx-velarWrapped STX (Velar) (WSTX) $ 0.359901
  • crvusdcrvUSD (CRVUSD) $ 0.999516
  • euro-coinEURC (EURC) $ 1.16
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.138812
  • olympusOlympus (OHM) $ 21.66
  • telcoinTelcoin (TEL) $ 0.003707
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 90,443.00
  • pendlePendle (PENDLE) $ 2.07
  • kinesis-goldKinesis Gold (KAU) $ 144.51

Over 80,000 sensitive password and key files leaked online

0 31

Over 80,000 sensitive password and key files leaked online

Cybersecurity firm watchTowr has uncovered a trove of leaked passwords, access keys, and sensitive configuration files that were unintentionally exposed from popular online formatting tools, JSON formatter, and CodeBeautify.

watchTowr Labs said it collected a dataset containing more than 80,000 files from sites used to format and validate code. Within those files, researchers found usernames, passwords, repository authentication keys, Active Directory credentials, database connection strings, FTP credentials, cloud environment access keys, LDAP configuration details, helpdesk API keys, and even recordings of SSH sessions.

“We’ve been rifling through platforms that developers use to quickly format their input – like JSONFormatter and CodeBeautify. And yes, you are correct – it went exactly as badly as you might expect,” watchTowr’s blog post published on Tuesday.

Online utilities such as JSONFormatter and CodeBeautify are meant to beautify or validate data formats, where devs paste snippets of code or configuration files into them to troubleshoot formatting issues. But according to researchers, many employees are unknowingly pasting entire files that contain live secrets from production systems.

JSON and CodeBeautify leak data from government, banks, and healthcare

According to the security firm, the leaked data flaw has yet to affect three platforms, including GitHub repositories, Postman workspaces, and DockerHub containers. However, it found five years of historical content from JSONFormatter and one year of historical content from CodeBeautify, totaling more than 5 gigabytes of enriched and annotated JSON material.

“The popularity is so great that the sole developer behind these tools is fairly inspired – with a typical visit to any tool homepage triggering 500+ web requests pretty quickly to generate what we assume is some sweet, sweet affiliate marketing revenue,” the cybersecurity group explained.

watchTowr Labs said organizations from industries like national infrastructure, government agencies, major financial institutions, insurance companies, technology providers, retail firms, aerospace organizations, telecoms, hospitals, universities, travel businesses, and even cybersecurity vendors have all had their private information exposed.

“These tools are extremely popular, appearing near the top of search results for terms like ‘JSON beautify’ and ‘best place to paste secrets’ (probably, unproven), used by organizations and administrators in both enterprise environments and for personal projects,” Security researcher Jake Knott wrote in the blog post.

watchTowr Labs listed several categories of sensitive data found within the exposed files like Active Directory credentials, code repository authentication keys, database access details, LDAP configuration information, cloud environment keys, FTP login credentials, CI/CD pipeline keys, private keys, and full API requests and responses with sensitive parameters.

Investigators also mentioned Jenkins secrets, encrypted configuration files belonging to a cybersecurity firm, Know Your Customer information from banks, and AWS credentials belonging to a major financial exchange that were connected to Splunk systems.

watchTowr: Malicious actors are scraping the leaks

According to watchTowr Labs’ damage analysis, many of the leaked keys have been collected and tested by unknown parties. In an experiment, researchers uploaded fake AWS access keys to one of the formatting platforms, and in just under two days, malicious actors attempted to abuse the credentials.

“Mostly because someone is already exploiting it, and this is all really, really stupid,” Knott continued, “we don’t need more AI-driven agentic agent platforms; we need fewer critical organizations pasting credentials into random websites.”

JSONFormatter and CodeBeautify temporarily disabled their save functionality in September, when the security flaw was brought to their attention. JSONFormatter it was “working on to make it better,” while CodeBeautify said it was implementing new “enhanced NSFW (Not Safe For Work) content prevention measures.”

Security issue in HashiCorp’s Vault Terraform Provider

Away from the leaked credentials, the San Francisco-based IBM company HashiCorp found a vulnerability that could allow attackers to bypass authentication in its Vault Terraform Provider. The firm provides developers, businesses, and security organizations with cloud-computing infrastructure and protection services.

Per the software company’s findings shared on Tuesday, the Vault Terraform flaw affects versions v4.2.0 through v5.4.0 from an insecure default configuration in the LDAP authentication method.

The issue arises because the “deny_null_bind” parameter is set to false instead of true when the provider configures Vault’s LDAP authentication backend. The parameter determines if the Vault rejects a wrong password or unauthenticated binds.

If the connected LDAP server allows anonymous binds, attackers can authenticate and access accounts without any valid credentials.

Source

Leave A Reply

Your email address will not be published.