Developer spotted hostname and credential string lurking in autocomplete

A developer working for Pageloot, a company specializing in QR code services, publicly exposed credentials for a staging environment by storing them in a Google Doc accessible to anyone with the link. The exposure was discovered when an internal Pageloot developer, while debugging an unrelated issue, typed the company's domain into Google Search. Google's autocomplete feature then suggested a search query that included one of Pageloot's staging hostnames followed by what appeared to be a credential string. This led to the discovery of the publicly indexed Google Docs URL containing the sensitive information.
Siim Kostabi, co-founder of Pageloot, confirmed that the incident involved an external contractor hired to assist with API integrations. The contractor sought a method to access credentials across multiple devices used for the project and opted to store them in a Google Doc, which was inadvertently configured for public access.
Upon discovering the exposed credentials, Pageloot immediately revoked the contractor's access and rotated all compromised credentials. The company also implemented a new policy prohibiting the storage of passwords in collaboration tools such as Google Docs, Slack, and Notion.
Kostabi emphasized that while the exposed credentials were for a staging server, such information still holds significant value if misused. He highlighted the importance of robust access control and proper security hygiene to prevent such incidents.
In a separate but related incident, Kostabi recounted a situation involving a Pageloot customer, a mid-sized retailer. This customer experienced their QR codes redirecting users to a competitor's website. Investigation revealed that a disgruntled former employee's credentials had not been revoked post-departure. The ex-employee subsequently used this unrevoked access to maliciously redirect the retailer's URLs, resulting in customer loss.
Kostabi noted that both the Google Docs exposure and the ex-employee incident underscore the necessity of stringent access management, including thorough offboarding procedures and regular access reviews. He stressed that treating shared documents as private vaults is a critical security oversight.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a