Threat Intelligence

Flaw in Major AI Providers' APIs Exposed Hidden Reasoning Data, Including Secrets

The Hacker News · 12 Aug 2026
Key Takeaway If your business uses AI APIs from major providers, review any advisories from those vendors and rotate API keys or credentials that may have been exposed through this flaw.

Security researchers have disclosed a vulnerability affecting how OpenAI, Anthropic, and Google handle hidden AI 'reasoning' data passed between API calls. This reasoning data is normally encrypted and not meant to be readable outside the original session, but researchers found that a reasoning block created in one session could be replayed into another session and, in testing, weaker AI models were able to decode reasoning content from more advanced models.

More concerning, the researchers found that session logs containing this reasoning data sometimes included sensitive secrets such as API keys and passwords. This means that a flaw intended to only affect internal AI processing steps could potentially expose real, exploitable business credentials if logs or reasoning objects were accessed by unauthorised parties.

While the affected companies have been building AI services used by countless businesses worldwide, this incident is a reminder that even major AI providers can have security gaps in how they protect data behind the scenes. Businesses relying on third-party AI APIs should stay alert for vendor security advisories and patches related to this issue.

AI security API vulnerability data exposure OpenAI Anthropic Google
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.