ZeroHour

Search: “instinct”

2 stories in the last 3d

Hardcoded MCP credentials found in public GitHub files

Hush Security found 12% of 82,000 public GitHub MCP config files contained hardcoded API keys, bearer tokens, and database passwords.

Hush Security's 'The State of MCP Configuration: The Identity Security Gaps' report analyzed roughly 82,000 MCP configuration files in public GitHub repositories, finding that 12% of credential slots contained hardcoded credential literals. Researchers used provider-specific token patterns and Shannon entropy to identify likely secrets, predominantly vendor API keys, bearer tokens, and database passwords. Of 7,681 credential-bearing configurations whose history was examined, 243 had secrets removed from the current file but still recoverable from earlier Git commits. Many exposed credentials were high-impact: 53% of classified credentials granted organization-, account-, workspace-, or database-wide access, and 80% with a defined expiration policy did not expire by default.

Most Fraudulent Hires Receive Credentials Before Detection

HYPR report finds 42% of fraudulent hires pass screening and receive corporate credentials, averaging 5.73 days of unmonitored network access before detection.

A HYPR study of 500 US HR executives found 42% of fraudulent candidates pass pre-hire screening and get hired, with only 3% detected on their hire day and 20% remaining undetected up to three weeks. This gives fraudulent hires an average of 5.73 days of unmonitored corporate network access, and 98% of surveyed executives said they had experienced candidate fraud firsthand. The report follows a September 9 CISA update to its Insider Threat Mitigation Guide warning that malicious actors use AI tools to obtain remote IT jobs, a tactic long used by North Korean actors for data theft and extortion.

Infosecurity Magazine · 2d agoPhishing & fraud