Security boffin claims airport group left API keys in client-side JavaScript for four years

https://image.theregister.com/5273664.jpg?imageId=5273664&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Researcher believes overprivileged Iterable creds exposed 8.8M customer records – and could have enabled mass deletion

Security researcher Scott Helme says his analysis supports FulcrumSec's claim that Manchester Airports Group (MAG) exposed privileged API keys in client-side JavaScript.

Helme says he reached that conclusion after using information provided by the cyber extortion group to reconstruct how data belonging to roughly 8.8 million MAG customers was allegedly stolen last month.

The crooks behind the attack described MAG's security failure as "tragi-comical." They claimed MAG exposed overprivileged API keys for Iterable, a marketing automation platform, in front-end JavaScript served by the websites of MAG's three airports: Manchester, Stansted, and East Midlands.

Helme used the Internet Archive's Wayback Machine to retrieve older versions of the JavaScript and found that the three keys first appeared across the airport websites in June and July 2022. The same values remained exposed until August 2026, he said.

...

Copyright of this story solely belongs to www.theregister.com. To see the full text click HERE

Read more