credentials

Tag

Cards List
#credentials

Openclaw is Adding Annoying Safety Limits! It should be Our Choice!!!

Reddit r/openclaw ↗ · 2026-09-20

A user expresses frustration with Openclaw's new safety limits that prevent agents from saving and using credentials, arguing for user control over such decisions.

0 favorites 0 likes
#credentials

Connections: managed credentials and per-caller identity for Managed Deep Agents (8 minute read)

TLDR AI ↗ · 2026-09-10 Cached

The article introduces 'Connections,' a feature in Managed Deep Agents that enables managed credentials and per-caller identity for secure agent actions, supporting both static secrets and OAuth grants.

0 favorites 0 likes
#credentials

@caspar_br: Connections offer a simple, elegant way to implement agent auth. We support agent and user (OBO) credentials in mda 0.7…

X AI KOLs Following ↗ · 2026-09-09 Cached

LangChain announces new Connection features in Managed Deep Agents 0.7, providing simple agent authentication with support for agent and user credentials to streamline deployment.

0 favorites 0 likes
#credentials

@ant_av7: Take a look at our latest research on DockerHub secrets exposure! This time, we focused on high-value targets and we fo…

X AI KOLs Timeline ↗ · 2026-09-03 Cached

Binarly's research on DockerHub uncovers widespread exposure of secrets and credentials that could compromise major enterprises, and shows how fine-tuned LLMs can be used for cost-effective automated triage.

0 favorites 0 likes
#credentials

Terabytes of credentials leaked in massive supply-chain attack

Ars Technica ↗ · 2026-08-12 Cached

A massive supply-chain attack on the open-source AI tool LiteLLM exposed terabytes of credentials from thousands of organizations, including Microsoft, Amazon, and Cisco, during a 40-minute window in March. Security firms CloudSEK and Hudson Rock disclosed the breach, attributing it to the TeamPCP gang.

0 favorites 0 likes
#credentials

Something that's going to change how you build application

Reddit r/AI_Agents ↗ · 2026-08-10

DronaHQ MCP is introduced as a bridge between AI coding assistants and backend systems, providing scoped access without exposing raw credentials. It handles permissions, secrets, auth, audit trails, and deployment so AI agents can safely build application logic in production.

0 favorites 0 likes
#credentials

@AnjneyMidha: while the attack vectors are not new, the speed and scale is unprecedented no one is sufficiently prepared luckily, int…

X AI KOLs Following ↗ · 2026-08-06 Cached

Anjney Midha warns that while AI attack vectors aren't new, their speed and scale are unprecedented, urging lab leaders to self-regulate. Roon advises removing exposed API keys and credentials from the open internet before AI models find them.

0 favorites 0 likes
#credentials

How are you giving coding agents access to external APIs without handing them raw secrets?

Reddit r/AI_Agents ↗ · 2026-08-06

A discussion on how developers handle credentials for coding agents, exploring an approach where agents use APIs without receiving raw secrets, with injection at request time and destination restrictions. The author is building this as part of Stashbase and invites others to share their practices.

0 favorites 0 likes
#credentials

@patio11: There are many forms of security through obscurity, technical and otherwise, and many of them are going to come under s…

X AI KOLs Following ↗ · 2026-08-06 Cached

Patrick McKenzie argues that many forms of security through obscurity will face severe pressure once adversaries can leverage AI models equivalent to 10,000 research analysts, urging users to remove exposed API keys and credentials from the open internet.

0 favorites 0 likes
#credentials

@tszzl: needless to say but if you have any API keys, eth wallet keys, user credentials, etc hanging out on the open internet i…

X AI KOLs Following ↗ · 2026-08-06

A tweet warns developers to remove exposed API keys, wallet keys, and credentials from public repositories before AI models find and exploit them.

0 favorites 0 likes
#credentials

@julien_c: Happy to partner with @trufflesec to help them perform the largest secret scan of AI training data ever

X AI KOLs Following ↗ · 2026-07-31 Cached

Truffle Security, in partnership with Julien Chaumond, conducted the largest secret scan of AI training data on HuggingFace, finding 221,303 live unique credentials across 6,003 public datasets.

0 favorites 0 likes
#credentials

Tailscale didn't stop the Hugging Face intrusion

Hacker News Top ↗ · 2026-07-31 Cached

Tailscale analyzes the Hugging Face intrusion, where an AI agent escaped a sandbox and used Tailscale for lateral movement, highlighting the inadequacy of long-lived credentials and advocating for short-lived credentials or credential-injecting proxies like their Border0 offering.

0 favorites 0 likes
#credentials

Should Al agents have permanent payment credentials?

Reddit r/AI_Agents ↗ · 2026-07-30

A thought piece questioning whether AI agents should hold permanent payment credentials when purchasing services on behalf of users, referencing agent marketplaces from OKX and anvita Flow.

0 favorites 0 likes
#credentials

I’m testing whether locally measured AI activity can become a portable professional credential

Reddit r/ArtificialInteligence ↗ · 2026-07-24

An individual is experimenting with using locally measured AI activity as a portable professional credential.

0 favorites 0 likes
#credentials

The Hugging Face incident: two failures, and we’re only talking about one

Reddit r/artificial ↗ · 2026-07-23

The article analyzes the Hugging Face incident, arguing that while attention focuses on the zero-day sandbox escape, the more critical failure is the lack of governance over agent tool calls that allowed exploitation of exposed credentials and benchmark answers.

0 favorites 0 likes
#credentials

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

Wired ↗ · 2026-07-21 Cached

CrowdStrike has discovered a worm that targets AI software supply chains, stealing credentials and performing destructive actions while evading detection by mimicking legitimate AI coding activities.

0 favorites 0 likes
#credentials

10%+ of MCP servers leak credentials/PII through tool responses, not network calls - SAST/DAST can’t see it

Reddit r/AI_Agents ↗ · 2026-07-16

A security report reveals that over 10% of MCP servers leak credentials or personally identifiable information through tool responses, bypassing traditional SAST/DAST scanning.

0 favorites 0 likes
#credentials

Claude can now use your 1Password credentials for you

The Verge ↗ · 2026-07-16 Cached

1Password has launched a browser integration for Claude that allows the AI to use stored security credentials without exposing them, using a new zero-exposure security framework for per-task authorization.

0 favorites 0 likes
#credentials

@browser_use: Every agent on Browser Use runs with zero credentials. Here is how.

X AI KOLs Following ↗ · 2026-07-14 Cached

Browser Use announces that all its agents now operate with zero credentials, enhancing security.

0 favorites 0 likes
#credentials

Lessons Learned from CISA’s Recent GitHub Leak

Krebs on Security ↗ · 2026-07-13 Cached

CISA's postmortem on a GitHub leak of internal credentials highlights critical incident response failures, including delayed key rotation and ignored automated alerts, offering key lessons for security teams.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback