# Inside the World Cup Bot Fraud and CISA GitHub Leak

Canonical: https://brew.new/browse/templates/email/pt1_k97sqwxeabfjea700wzqhe3k7h8e5q4t

Brand: approov.io
Category: newsletter

![Preview of Inside the World Cup Bot Fraud and CISA GitHub Leak](https://cdn.brew.new/email-preview-8ccbd1396d605f0a-tracking_r57n2d4mqdjp176yvdd58h17m98dvspz-1789000773826.png)

## Email content

View in browser

Approov-newsletter-banner-image

June 2026

From developer pipelines to live mobile apps, threat actors are using automation to exploit trust. In this issue, we look at why relying on unvetted tools, client-side secrets, or traditional perimeters is a direct path to a breach.

Malicious JetBrains Plugins Steal AI API Keys

For modern developers, IDE plugins are standard infrastructure. However, a recent supply chain campaign on the JetBrains Marketplace turned these tools into active threats.

The Threat: JetBrains confirmed that 15 malicious plugins (masquerading as legitimate AI assistants using names associated with DeepSeek and other LLMs) were designed to steal developer credentials. Over 70,000 installations occurred across compromised publisher accounts.

How it Worked:

Developers pasted their OpenAI or DeepSeek API keys into the plugin settings panel to activate the utility.

The plugin silently exfiltrated the raw API token directly to an attacker-controlled server.

The attackers even ran a service where paying victims were fed keys harvested from other compromised developers.

Full Threat Analysis: JetBrains Marketplace Ecosystem Security Update

Why Credentials Do Not Belong in Your Mobile App

Mobile apps are the front door to digital services, but storing high-value secrets directly inside mobile code remains a critical security mistake.

The Vulnerability: Unlike secure corporate servers, mobile apps run on devices you do not own or control. Once downloaded, any embedded secrets—including backend API keys, third-party credentials, and encryption keys—are entirely out of your hands. Using basic static or dynamic analysis, attackers can easily reverse engineer the binary or inspect runtime memory to extract active tokens.

Once attackers extract these keys, they bypass your mobile app completely. They use the stolen credentials to interact directly with your backend APIs, leading to automated fraud, soaring infrastructure costs, and compliance failures.

Key Takeaway: Code obfuscation only hides the problem. With AI-assisted tools now automating credential discovery, hiding secrets client-side is a losing strategy. True security requires a "Zero Secrets" architecture where the app is cryptographically verified at runtime before any sensitive backend access is granted.

Download the Zero Secrets White Paper

CISA Contractor Leaks AWS GovCloud Keys on GitHub

When the agency responsible for federal cyber defense leaves the keys in the door, it serves as a stark reminder that credential hygiene is failing at the highest levels.

The Incident: A CISA contractor inadvertently exposed highly privileged AWS GovCloud keys, plaintext database passwords, and internal infrastructure maps within a public GitHub repository.

While the repository was taken down quickly, a major security gap remained. Security researchers discovered that an incredibly high-value GitHub App private key (granting administrative write access to CISA's entire enterprise organization) remained live and active for two full days after the public report dropped. An attacker possessing that key could have tampered with code deployments across the agency.

Key Takeaway: Secrets remediation cannot rely on manual tracking. When a public repository leak happens, the risk doesn't end when you delete the repo; it only ends when every single compromised token is programmatically revoked.

Read the Full Investigation on Krebs on Security

Why Mobile Sportsbook Apps Are Prime Targets for Fraud

High transaction volumes, live-market urgency, and direct financial pipelines make mobile sports betting apps an ideal target for automated fraud.

The Strategy: Attackers target the data tokens, mobile endpoints, and APIs underpinning the app. By deploying automated AI agents, threat actors monitor real-time betting lines and micro-markets (like live in-play betting). They capture fractional odds movements and exploit anomalies faster than any human can react. Furthermore, reverse-engineered apps are used to build fake platforms that mimic the genuine interface while siphoning user sessions and personal identity details.

Key Takeaway: You cannot assume a request is safe just because it originates from a downloaded app. Security teams must remove hardcoded secrets from the binary entirely and transition to dynamic validation to protect the underlying transaction environment.

See Our Breakdown of Mobile Sports App Vulnerabilities

Approov Limited

Scotiabank House, 6 South Charlotte Street, Edinburgh, Midlothian EH2 4AW, United Kingdom | +44 0131 655 1500

US HQ: 165 University Avenue, Suite 200, Palo Alto, CA 94301, USA | +1 (650) 322-5300

Unsubscribe Manage Preferences

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97sqwxeabfjea700wzqhe3k7h8e5q4t)

[Browse email designs](https://brew.new/browse/templates)
