Intruder Reveals 42,000 Exposed Tokens in Web Applications

Intruder Reveals 42,000 Exposed Tokens in Web Applications

First seen 10 Jan 2026, 11:51 UTC Securitybrief.AuSecuritybrief 20.3

Article Content

Browse articles
ThreatCluster

Cybersecurity company Intruder has detected over 42,000 leaked tokens in JavaScript bundles of single-page applications. The London-based firm scanned 5 million applications using a new spidering-based method, uncovering sensitive development and collaboration credentials. This discovery highlights a significant issue with exposed secrets in web apps.