Unknown
rss_thehackernews
ยท
rss_35c81bfe28a3d835ee4b96256d09bc88
Toxic Combinations: When Cross-App Permissions Stack into Risk
Published Apr 22, 2026
On January 31, 2026, researchers disclosed that Moltbook, a social network built for AI agents, had left its database wide open, exposing 35,000 email addresses and 1.5 million agent API tokens across 770,000 active agents.
The more worrying part sat inside the private messages. Some of those conversations held plaintext third-party credentials, including OpenAI API keys shared between agents,
Affected AI Products
ai agent
openai