Chain Reaction: How One Stolen Token Tore Through Five Ecosystems
Why Your Static Credentials Are a Ticking Time Bomb The TeamPCP campaign, one of the largest credential theft campaigns of 2026, began with a compromise in Trivy. A security tool trusted to scan for vulnerabilities and leaked secrets was weaponized against the very environments it was meant to protect. Instead ... Read More
AI Agents Don’t Need Better Secrets. They Need Identity.
Last week, Wiz disclosed a major security exposure involving Moltbook, an AI agent social network. A misconfigured database exposed 1.5 million API keys, each one capable of fully impersonating an agent on the platform. Anyone with a leaked key could post content, send messages, or modify data as that agent ... Read More

