Permiso documented how hosted AI models can be hijacked for “dark roleplaying,” underscoring that externally accessible model services can be manipulated for harmful or policy-evading use cases. The issue adds an abuse-management requirement to AI deployments alongside conventional application and cloud security controls.
Separately, Wiz found hundreds of validated, still-active secrets in public code repositories during a month-long scan, with AI-service credentials disproportionately represented. Jupyter notebooks and AI-agent configuration files such as mcp.json frequently exposed keys through hardcoded values, outputs, diagnostics, and error messages; 56% of company-impacting secrets were in employees’ personal repositories. Organizations should expand secret scanning to AI providers, scan Git history and CI/CD pipelines, block commits containing notebook outputs, and revoke or rotate exposed credentials.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
The researchers reported that a secret they disclosed to the Microsoft Security Response Center was rated Critical and could have enabled exposure of sensitive HR data.
A month-long scan of thousands of public code repositories found hundreds of validated exposed secrets, many still active. AI-service credentials represented three of the five most common validated secret types, and Jupyter Notebook files were the most leak-prone file type.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.