Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys
Summary
Research by watchTowr Labs has revealed that sensitive organizations are inadvertently exposing thousands of passwords and API keys by using online code formatting tools like JSONformatter and CodeBeautify. This highlights a significant cybersecurity risk, particularly for sectors such as government and critical infrastructure, where the leakage of credentials could lead to severe breaches.
Original Article Summary
New research has found that organizations in various sensitive sectors, including governments, telecoms, and critical infrastructure, are pasting passwords and credentials into online tools like JSONformatter and CodeBeautify that are used to format and validate code. Cybersecurity company watchTowr Labs said it captured a dataset of over 80,000 files on these sites, uncovering thousands of
Impact
Not specified
In the Wild
Unknown
Timeline
Newly disclosed
Remediation
Organizations should avoid using online tools for sensitive data and implement strict data handling policies to prevent credential leakage.