Security boffin claims airport group left API keys in client-side JavaScript for four yearshttps://www.theregister.com/cyber-crime/2026/09/09/security-boffin-claims-airport-group-left-api-keys-in-client-side-javascript-for-four-years/5295192
Researcher believes overprivileged Iterable creds exposed 8.8M customer records β and could have enabled mass deletion
