Find notable cyber news and cases, enriched with sources, timelines, and signals.

IPhone AI chatbot traffic leak of API keys, replayable tokens, and open relays

Technical Analysis
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

LLMKeyLens testing found 444 iPhone AI chatbot apps leaking paid AI access, exposing API keys, replayable tokens, and open relays that let others bill model usage to the developer account. The technical pattern creates direct risk of LLMjacking and hidden prompt exposure across multiple AI providers, including OpenAI. The problem remained widespread after disclosure, with only 28% of notified developers fixing it within three months.

Related Happenings

OpenAI ChatGPT Atlas BioShocking fix

Advisory/Mitigation
H score34 First: 01.07.2026 00:50 Last: 01.07.2026 00:50 Sources 1

About this happening: OpenAI delivered a working fix for BioShocking in ChatGPT Atlas, closing a prompt-injection path that could push an AI browser toward unsafe real-world actions and c...

JetBrains Marketplace malicious plugins exfiltrating AI provider keys

Malware Activity
H score12 First: 17.06.2026 12:38 Last: 17.06.2026 12:38 Sources 1

About this happening: A JetBrains Marketplace malware operation has pushed 15 malicious plugins that pose as AI coding assistants and steal AI provider API keys from developers. The plugins...

LLMShare ChatGPT share-link malware lure campaign

Campaign
H score47 First: 29.05.2026 21:21 Last: 29.05.2026 21:21 Sources 1

About this happening: The LLMShare campaign is using Google ads and a legitimate chatgpt.com shared page to route people searching for ChatGPT into a fake OpenAI outage lure that pu...

AI-driven attack surge against customer-facing mobile apps in 2026

Trend
H score43 First: 19.05.2026 15:00 Last: 19.05.2026 15:00 Sources 1

About this happening: Customer-facing mobile apps faced a sharp rise in attacks in 2026, with 87% of monitored apps hit versus 55% in 2022. The trend matters because agentic AI is l...

Widespread exposure and misconfiguration in self-hosted AI infrastructure

Trend
H score76 First: 05.05.2026 13:30 Last: 05.05.2026 13:30 Sources 1

About this happening: A large-scale measurement found self-hosted AI infrastructure was being deployed with widespread exposure and no authentication, creating a broad risk of data theft, workf...

Timeline

  1. 30.06.2026 16:49 2 articles · 15d ago

    IPhone AI chatbot traffic leak of API keys, replayable tokens, and open relays

    Initial Disclosure

    Traffic captures from 444 iPhone AI chatbot apps revealed plaintext keys, replayable tokens, and unauthenticated AI relays that exposed paid model access in transit. The same inspection also uncovered hidden system prompts in some requests, extending the leak beyond credentials.

    Show sources