User “Discodtehe” on the discord for the r/ChatGPT subreddit is accused of stealing and selling OpenAI API tokens — keys to accessing OpenAI’s tools. They allegedly scrape these tokens from code on the Replit website and offer access to others. One valuable OpenAI account, worth up to $150,000 in usage, was offered for free. OpenAI urged users to safeguard their API keys and assured it conducts automated scans to revoke uncovered keys.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.