Bottom line: Hardcoded credentials in public GitHub files pose a significant security risk to organizations using Azure Kubernetes Service (AKS) and other AI-powered coding tools.
What's happening: Researchers from Hush Security analyzed around 82,000 GitHub configuration files for Microsoft Cloud Platform (MCP) and found hardcoded API keys, access tokens, and other credentials in 15% of them, including those from popular tools like Azure Kubernetes Service (AKS) and Visual Studio Code.
What to do: To mitigate this risk, security leaders should implement a centralized authentication and authorization system for AKS, and require developers to use secure, encrypted storage for MCP configuration files, such as Azure Key Vault.