Security · 1h ago
Credential Exfiltration Hits Four Stack Layers as Agentic Web Goes Live
The same week the Agentic Resource Discovery spec was finalized, four credential incidents struck different stack layers: ServiceNow exposed APIs for 64 days, 74,000 Fortinet credentials leaked, Mastra AI npm packages were backdoored, and malicious JetBrains plugins harvested API keys. Each incident involved real, long-lived credentials accessible at the compromised layer.
Meridian48 take
The timing underscores a fundamental design flaw: credentials remain long-lived and accessible across the stack, and no protocol spec addresses this at the invocation boundary.
credential-exfiltrationsupply-chain-security