Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
North Korea-linked phishing campaign targets developers through malici...
Zero-day exploit disclosed hours after massive Patch Tuesday release
Bringing cybercriminals to justice in APAC
Cyber resilience – a national security imperative
Critical VPN vulnerability actively exploited to bypass authentication...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Bringing cybercriminals to justice in APAC

      Bringing cybercriminals to justice in APAC

      Thursday, June 11, 2026, 10:30 AM Asia/Singapore | Features
    • Featured

      Cyber resilience – a national security imperative

      Cyber resilience – a national security imperative

      Wednesday, June 10, 2026, 3:09 PM Asia/Singapore | Features
    • Featured

      Asia Pacific’s unique cyberthreats

      Asia Pacific’s unique cyberthreats

      Monday, June 8, 2026, 5:04 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

AI‑agent social network exposes millions of credentials and emails

By CybersecAsia editors | Wednesday, February 4, 2026, 12:05 PM Asia/Singapore

AI‑agent social network exposes millions of credentials and emails

Multiple cohorts of threat researchers flag insecure database and new attack vectors in a bot‑only online community.

A new “social network for AI agents” called Moltbook has become a focal point for cybersecurity warnings after researchers uncovered a major data‑exposure flaw that put millions of credentials and thousands of human email addresses at risk.

The Reddit‑style site, advertised as a space where AI bots can chat among themselves while humans only observe, was found to be leaking private agent‑to‑agent messages, API keys, and personal information due to a poorly secured back‑end database.

Cybersecurity firm Wiz has reported that the platform’s Supabase‑backed database was effectively open to the Internet, allowing unauthenticated users to read and even modify data, including live posts and sensitive tokens. The exposure had included more than 1.5m API keys, over 35,000 email addresses, and private messages that sometimes contained full raw credentials for third‑party services such as OpenAI.

The firm’s researchers reported they could change posts on Moltbook at will, raising concerns that an attacker could insert malicious content or impersonate agents, since the platform lacked robust verification that an “agent” was actually AI‑driven rather than a human‑run script.

Wiz cofounder Ami Luttwak had described the issue as a textbook example of the risks of so‑called “vibe coding” where basic security hygiene such as access controls and secrets management could be neglected.

Dawn of new attack surfaces?

Elsewhere, security experts have warned that Moltbook’s architecture creates a new attack surface for prompt‑injection and cross‑agent manipulation. Because agents periodically fetch and process content from the site, a single malicious post or comment could trigger widespread misbehavior across thousands of bots, including data leaks, unauthorized external communications, or even coordinated actions against external systems. Similarly:

  • Offensive‑security specialists have highlighted that Moltbook’s unsandboxed execution model and persistent memory features compound these risks, enabling delayed‑execution attacks and making it harder to trace or contain breaches once they occur.
  • Privacy and AI‑safety analysts are arguing that, beyond the immediate data‑exposure bug, Moltbook exemplifies how autonomous‑agent networks can rapidly scale regulatory and governance gaps. The platform’s design allows agents to share information derived from human‑owned systems — such as work patterns, locations, or behavioral data — without clear consent or audit trails, turning an “AI‑only” forum into an inadvertent channel for personal‑data processing.

Finally, several AI‑safety researchers and industry leaders have publicly urged caution, warning that if such agent‑centric networks proliferate without strong security and oversight, they could become fertile ground for coordinated cyber‑attacks, credential‑harvesting campaigns, and even early forms of rogue, self‑organizing AI collectives.

Share:

PreviousVIVOTEK Enhances VORTEX with Generative AI and Safety Detection
NextICAC Commissioner attends APEC anti-corruption meetings in Guangzhou to foster collaborations in the Asia Pacific region

Related Posts

Ten 2025 cyber predictions hinging on major 2024 cyber incidents          

Ten 2025 cyber predictions hinging on major 2024 cyber incidents          

Friday, January 3, 2025

How complacent are South-east Asian executives about cybersecurity?

How complacent are South-east Asian executives about cybersecurity?

Tuesday, August 9, 2022

What Q2 2024 phishing trends were detected in one email defense solution?

What Q2 2024 phishing trends were detected in one email defense solution?

Thursday, November 28, 2024

Fortinet’s regional security conferences to focus on security-driven network strategies

Fortinet’s regional security conferences to focus on security-driven network strategies

Thursday, August 22, 2019

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • 2024 Insider Threat Report: Trends, Challenges, and Solutions

    2024 Insider Threat Report: Trends, Challenges, and Solutions

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    The future of cybersecurity is a perfect storm: AI-driven attacks, cloud expansion, and the convergence …Download Whitepaper
  • Data Management in the Age of Cloud and AI

    Data Management in the Age of Cloud and AI

    In today’s Asia Pacific business environment, organizations are leaning on hybrid multi-cloud infrastructures and advanced …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Cohesity Gains Access to Anthropic’s Claude Mythos Preview Through Project Glasswing

    Tuesday, June 9, 2026
    Strengthening the Cohesity Data Cloud …Read More »
  • Cohesity Gains Access to Anthropic’s Claude Mythos Preview Through Project Glasswing

    Tuesday, June 9, 2026
    Strengthening the Cohesity Data Cloud …Read More »
  • Uhale Adopts Quokka’s Q-mast to Strengthen Application Security Testing

    Tuesday, June 9, 2026
    Integration of automated security testing …Read More »
  • Uhale Adopts Quokka’s Q-mast to Strengthen Application Security Testing

    Tuesday, June 9, 2026
    Integration of automated security testing …Read More »
  • SU Group Awarded Next-Generation Cross-Border Security and High-Speed Vehicle Clearance System Installation

    Thursday, June 4, 2026
    HONG KONG, June 4, 2026 …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.