Turn emails into revenue with Brew. No credit card, free credits to try.
approov.io · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
View in browser
Approov-newsletter-banner-image
June 2026
From developer pipelines to live mobile apps, threat actors are using automation to exploit trust. In this issue, we look at why relying on unvetted tools, client-side secrets, or traditional perimeters is a direct path to a breach.
Malicious JetBrains Plugins Steal AI API Keys
For modern developers, IDE plugins are standard infrastructure. However, a recent supply chain campaign on the JetBrains Marketplace turned these tools into active threats.
The Threat: JetBrains confirmed that 15 malicious plugins (masquerading as legitimate AI assistants using names associated with DeepSeek and other LLMs) were designed to steal developer credentials. Over 70,000 installations occurred across compromised publisher accounts.
How it Worked:
Developers pasted their OpenAI or DeepSeek API keys into the plugin settings panel to activate the utility.
The plugin silently exfiltrated the raw API token directly to an attacker-controlled server.
The attackers even ran a service where paying victims were fed keys harvested from other compromised developers.
Full Threat Analysis: JetBrains Marketplace Ecosystem Security Update
Why Credentials Do Not Belong in Your Mobile App
Mobile apps are the front door to digital services, but storing high-value secrets directly inside mobile code remains a critical security mistake.
The Vulnerability: Unlike secure corporate servers, mobile apps run on devices you do not own or control. Once downloaded, any embedded secrets—including backend API keys, third-party credentials, and encryption keys—are entirely out of your hands. Using basic static or dynamic analysis, attackers can easily reverse engineer the binary or inspect runtime memory to extract active tokens.
Once attackers extract these keys, they bypass your mobile app completely. They use the stolen credentials to interact directly with your backend APIs, leading to automated fraud, soaring infrastructure costs, and compliance failures.
Key Takeaway: Code obfuscation only hides the problem. With AI-assisted tools now automating credential discovery, hiding secrets client-side is a losing strategy. True security requires a "Zero Secrets" architecture where the app is cryptographically verified at runtime before any sensitive backend access is granted.
Download the Zero Secrets White Paper
CISA Contractor Leaks AWS GovCloud Keys on GitHub
When the agency responsible for federal cyber defense leaves the keys in the door, it serves as a stark reminder that credential hygiene is failing at the highest levels.
The Incident: A CISA contractor inadvertently exposed highly privileged AWS GovCloud keys, plaintext database passwords, and internal infrastructure maps within a public GitHub repository.
While the repository was taken down quickly, a major security gap remained. Security researchers discovered that an incredibly high-value GitHub App private key (granting administrative write access to CISA's entire enterprise organization) remained live and active for two full days after the public report dropped. An attacker possessing that key could have tampered with code deployments across the agency.
Key Takeaway: Secrets remediation cannot rely on manual tracking. When a public repository leak happens, the risk doesn't end when you delete the repo; it only ends when every single compromised token is programmatically revoked.
Read the Full Investigation on Krebs on Security
Why Mobile Sportsbook Apps Are Prime Targets for Fraud
High transaction volumes, live-market urgency, and direct financial pipelines make mobile sports betting apps an ideal target for automated fraud.
The Strategy: Attackers target the data tokens, mobile endpoints, and APIs underpinning the app. By deploying automated AI agents, threat actors monitor real-time betting lines and micro-markets (like live in-play betting). They capture fractional odds movements and exploit anomalies faster than any human can react. Furthermore, reverse-engineered apps are used to build fake platforms that mimic the genuine interface while siphoning user sessions and personal identity details.
Key Takeaway: You cannot assume a request is safe just because it originates from a downloaded app. Security teams must remove hardcoded secrets from the binary entirely and transition to dynamic validation to protect the underlying transaction environment.
See Our Breakdown of Mobile Sports App Vulnerabilities
Approov Limited
Scotiabank House, 6 South Charlotte Street, Edinburgh, Midlothian EH2 4AW, United Kingdom | +44 0131 655 1500
US HQ: 165 University Avenue, Suite 200, Palo Alto, CA 94301, USA | +1 (650) 322-5300
Unsubscribe Manage Preferences