VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews ยท rss_35c81bfe28a3d835ee4b96256d09bc88

Toxic Combinations: When Cross-App Permissions Stack into Risk

Published Apr 22, 2026
On January 31, 2026, researchers disclosed that Moltbook, a social network built for AI agents, had left its database wide open, exposing 35,000 email addresses and 1.5 million agent API tokens across 770,000 active agents. The more worrying part sat inside the private messages. Some of those conversations held plaintext third-party credentials, including OpenAI API keys shared between agents,

Affected AI Products

ai agent openai