Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Akuvox X910 Claims Red Dot Award 2026: the World’s First AI-powe...
Exein establishes APAC headquarters and Taipei office
DNS‑record analysis shows uneven DMARC enforcement among FIFA World Cu...
Highlights of Asia’s 2026 premier integrated security event
Study: Cyber resilience in APAC foundational but not future-ready
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      How AI is supercharging insider threats

      How AI is supercharging insider threats

      Wednesday, April 15, 2026, 12:29 PM Asia/Singapore | Features
    • Featured

      Q-Day is coming. Are you ready?

      Q-Day is coming. Are you ready?

      Tuesday, April 14, 2026, 12:40 PM Asia/Singapore | Features
    • Featured

      How lean defence teams turn endpoint insights into measurable risk reduction

      How lean defence teams turn endpoint insights into measurable risk reduction

      Monday, April 13, 2026, 3:15 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • Awards 2025
  • Directory
  • E-Learning

Select Page

NewsTips

AI companies leaking sensitive information on GitHub

By CybersecAsia editors | Wednesday, November 12, 2025, 5:06 PM Asia/Singapore

AI companies leaking sensitive information on GitHub

With rapid AI innovation outpacing basic cybersecurity practices, non-human agents and automated processes are creating machine identities at scale, leading to inadvertent leakage of API  keys, tokens and credentials.

A new study by Wiz has revealed that nearly two-thirds of leading private AI companies have leaked sensitive information such as API keys, tokens, and credentials on GitHub. 

The research suggested that rapid innovation in AI is outpacing basic cybersecurity practices. Among the most commonly leaked credentials were API keys from ElevenLabs and HuggingFace, some of the most used AI tools today, and these leaks may allow threat actors access to private training data or organizational information.

According to Shane Barney, CISO, Keeper Security, the Wiz report highlights the growing challenge of managing machine-based credentials at scale, and demonstrates why visibility and control are important. 

“The discovery of exposed API keys, tokens and other programmatic secrets across leading AI companies shows how quickly machine-to-machine connections can expand as development and automation accelerate. Each of these credentials represents an access pathway that, if left unsecured, can expose sensitive systems or data,” he commented.

Machine identities, critical to today’s business operations, are growing at an exponential rate as organizations adopt AI and cloud-native development, and the number of non-human accounts and automated processes continues to rise. However, they often exist outside traditional identity and access management frameworks. 

“When visibility into those credentials is limited, risk spreads quietly across systems that are otherwise well protected,” said Barney. 

What to do

Barney advised: “Reducing that risk requires sustained visibility and control, as well as a centralized enterprise-level approach to managing secrets. Continuous monitoring for exposed secrets, automated credential rotation and least-privilege access policies help contain exposure without slowing innovation. Treating machine-based credentials with the same rigor applied to human users strengthens both resilience and operational trust.”

Additionally, he said: “Implementing Privileged Access Management (PAM) in conjunction with secrets management extends that visibility and control even further. PAM enforces strict access boundaries and accountability for elevated permissions, while secrets management ensures that credentials used by systems and applications are securely stored, rotated and monitored.” 

Together, these controls create a unified framework for managing both human and non-human identities, reducing credential sprawl and limiting the potential impact of an exposure.

“The Wiz findings serve as a reminder that as technology grows more intelligent and interconnected, security must keep equal pace,” concluded Barney. “The fundamentals still apply: know what identities exist, understand what they can access and ensure those privileges are tightly governed.” 

Share:

PreviousHow do cyberattacks influence business and financial planning in large organizations?
NextMeeting the business resilience challenges of digital transformation

Related Posts

Don’t get caught offside with illegal streaming 

Don’t get caught offside with illegal streaming 

Thursday, July 4, 2024

Vendor of private healthcare group in Singapore suffers data breach

Vendor of private healthcare group in Singapore suffers data breach

Thursday, October 28, 2021

The AI Plus Factor in OT Cyber Defence

The AI Plus Factor in OT Cyber Defence

Friday, October 18, 2024

Know the seven symptoms of cyberattacks

Know the seven symptoms of cyberattacks

Friday, September 2, 2022

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • 2024 Insider Threat Report: Trends, Challenges, and Solutions

    2024 Insider Threat Report: Trends, Challenges, and Solutions

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper
  • AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    AI-Powered Cyber Ops: Redefining Cloud Security for 2025

    The future of cybersecurity is a perfect storm: AI-driven attacks, cloud expansion, and the convergence …Download Whitepaper
  • Data Management in the Age of Cloud and AI

    Data Management in the Age of Cloud and AI

    In today’s Asia Pacific business environment, organizations are leaning on hybrid multi-cloud infrastructures and advanced …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more
  • What AI worries keep members of the Association of Certified Fraud Examiners sleepless?

    What AI worries keep members of the Association of Certified Fraud Examiners sleepless?

    This case study examines how many anti-fraud professionals reported feeling underprepared to counter rising AI-driven …Read more

Bottom sidebar

Other News

  • Akuvox X910 Claims Red Dot Award 2026: the World’s First AI-powered Parcel Detection Smart Intercom Revolutionizes Luxury Home Access

    Saturday, April 18, 2026
    XIAMEN, China, April 17, 2026 …Read More »
  • Exein establishes APAC headquarters and Taipei office

    Saturday, April 18, 2026
    Partnering with Taiwan’s ecosystem to …Read More »
  • Tsingke Unveils ‘Zero-Contact’ Gene Synthesis to Safeguard Core Genetic Sequences

    Wednesday, April 15, 2026
    BEIJING, April 15, 2026 /PRNewswire/ …Read More »
  • NEC Asia Pacific to Showcase Trusted Public Safety and Digital Identity Innovations at Milipol TechX 2026

    Wednesday, April 15, 2026
    SINGAPORE, April 14, 2026 /PRNewswire/ …Read More »
  • Sprinto Expands to Australia with New Data Center to Power Localized, Audit-Ready Compliance

    Wednesday, April 15, 2026
    Sprinto combines local infrastructure with …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.