{
  "id": 6412294,
  "title": "Security boffin claims airport group left API keys in client-side JavaScript for four years",
  "url": "https://urgent.news/2026/09/09/security-boffin-claims-airport-group-left-api-keys-in-client-side",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-09T11:14:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/cyber-crime/2026/09/09/security-boffin-claims-airport-group-left-api-keys-in-client-side-javascript-for-four-years/5295192"
  },
  "original_language": "en",
  "account": "Security researcher Scott Helme has found that Manchester Airports Group (MAG) left privileged API keys exposed in client-side JavaScript for four years. The keys, belonging to Iterable, a marketing automation platform, were exposed in front-end JavaScript served by MAG's websites for Manchester, Stansted, and East Midlands airports. Helme discovered the keys by using the Internet Archive's Wayback Machine to examine older versions of the JavaScript. The keys were first introduced in June and July 2022 and remained exposed until August 2026. Anyone who accessed the page source during this period could have obtained the keys. Helme noted that the API keys were used to authorize server-side API operations, which should have occurred through MAG's servers instead. The keys had overprivileged access to core Iterable endpoints, allowing anyone who obtained them to access sensitive data and perform actions like deleting customer records and rewriting profiles. MAG described the incident as sophisticated and claimed it was a hack, not a lapse. However, Helme believes that any hacker with access to the publicly available data could have exploited the vulnerability.",
  "summary": "Researcher believes overprivileged Iterable creds exposed 8.8M customer records – and could have enabled mass deletion",
  "key_points": [
    "Manchester Airports Group left API keys in client-side JavaScript for four years.",
    "Keys allowed unauthorized access to sensitive data and core Iterable endpoints."
  ],
  "editors_take": "This incident highlights a lapse in security practices, enabling any visitor to MAG's airport websites to potentially access sensitive data and perform unauthorized actions over a four-year period.",
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Security boffin claims airport group left API keys in client-side JavaScript for four years",
        "url": "https://urgent.news/2026/09/09/security-boffin-claims-airport-group-left-api-keys-in-client-side-6415897",
        "published": "2026-09-09T11:14:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}