[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fi67K2FpdTg1XjZi3hvpwXUDG60bPpTWiEmxDohaUodU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"473c2f4e-bb9f-43c4-b901-30f8546cf550","ai-reasoning-apis-leaked-secrets-via-replayable-encrypted-objects","4a9c072f-c74c-45d9-a5f5-8dfea93197b2","AI Reasoning APIs Leaked Secrets via Replayable Encrypted Objects","A design flaw in the reasoning APIs of OpenAI, Anthropic, and Google allowed encrypted reasoning objects to be replayed across different sessions or fed to weaker AI models, inadvertently exposing sensitive data such as API keys and passwords. The root issue was insufficient session binding and context isolation — encrypted objects were treated as portable and reusable rather than tightly scoped to their originating session. This matters because it demonstrates that encryption alone is not a sufficient security control; proper session integrity, token binding, and output sanitization are equally critical. The flaw also opens the door to model distillation attacks and hidden prompt injection, representing a novel class of AI-specific threats that traditional security frameworks have not yet fully addressed.","**Immediate actions:**\n- Audit all AI API integrations to ensure session tokens and reasoning objects are strictly scoped to their originating session and cannot be replayed.\n- Rotate any API keys or credentials that may have been exposed through AI session logs or reasoning outputs.\n- Implement output filtering on AI API responses to detect and redact secrets, credentials, or PII before they are returned to clients.\n\n**Long-term improvements:**\n- Establish cryptographic session binding for all AI reasoning objects so that encrypted outputs are non-transferable across sessions or model tiers.\n- Develop and enforce an AI API security policy that includes threat modeling for model distillation, prompt injection, and data leakage scenarios.\n- Integrate AI-specific security testing (e.g., adversarial prompting, replay attack simulations) into your regular penetration testing and red team exercises.\n\n**Detection measures:**\n- Enable detailed logging of AI API requests and responses, monitoring for anomalous cross-session token reuse or unusually structured inputs that may indicate replay attacks.\n- Set up alerts for any AI API calls that return content matching patterns for credentials, keys, or sensitive data formats.\n- Monitor for signs of model distillation by tracking unusual volumes of structured query-response pairs being extracted via your AI API endpoints.",[12,13,14,15,16,17,18,19,20,21,22],"NIST SP 800-53 AC-12 (Session Termination)","NIST SP 800-53 SC-23 (Session Authenticity)","NIST SP 800-53 SI-10 (Information Input Validation)","NIST SP 800-53 IA-11 (Re-Authentication)","CIS Control 3: Data Protection","CIS Control 16: Application Software Security","OWASP API Security Top 10 - API2: Broken Authentication","OWASP API Security Top 10 - API8: Security Misconfiguration","OWASP ML Security Top 10 - ML05: Model Inversion Attack","GDPR Article 32 (Security of Processing)","NIST AI RMF - Govern 1.7 (AI Risk Policies)","published","2026-08-12T14:21:27.490829+00:00","2026-08-12T14:21:27.218+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fopenai-anthropic-google-api-flaw-let.html","openai-anthropic-google-api-flaw-let-weaker-ai-models-decode-stronger-models-rea-685f5a","OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]