PM's Advisor's Alleged Chat Leaks Online; Security Expert Explains How to Prevent It
Translated & summarized from Globes by baba
Alleged text messages from Prime Minister's advisor Yonatan Urikh were leaked online Sunday, with their authenticity unconfirmed. The leak may be linked to an AI monitoring tool Urikh built, which was exposed due to a security vulnerability. A security expert explained that improperly connecting AI tools to public repositories can lead to leaks of sensitive login information. He advised keeping login keys confidential and ensuring code repositories are private to prevent unauthorized access.
The story in 5 lines · by baba
- Alleged text messages from Prime Minister's advisor Yonatan Urikh were leaked online Sunday.
- The leak may be connected to an AI network monitoring tool Urikh built.
- A security vulnerability in the AI tool led to its exposure.
- An expert warned that connecting AI tools to public repositories risks exposing sensitive data.
- Preventative measures include keeping login keys secret and setting code repositories to private.
Alleged text messages from Prime Minister's advisor Yonatan Urikh were leaked online Sunday, with some appearing on a website created to expose them. Screenshots of the purported conversations also surfaced on social media. The authenticity of these messages has not been confirmed. The leak may be connected to a previous Haaretz newspaper report detailing how Urikh used the AI engine Claude to build a network monitoring tool that tracked mentions of names and events, sending summaries to him. This tool was exposed after a security vulnerability was discovered within it.
Gil Messing, Head of Staff and Director of Global Communications at Check Point, explained that a common mistake when developing AI tools is connecting them to public internet repositories like GitHub without sufficient attention, theoretically allowing anyone to access the tool and its contents. He noted that AI tools can help write code quickly but may inadvertently store sensitive information, such as "entry keys" or login files for applications like WhatsApp, if these are linked to the tool. If such a repository is publicly accessible, anyone could potentially find these keys and gain access to accounts.
Messing advised on preventing such leaks by keeping login keys confidential and never sharing code containing passwords or connection files for any application on public code-sharing sites. He also stressed the importance of ensuring new code repositories are set to private, not public, and that simple tools exist to scan code and verify privacy settings. Finally, he recommended separating code from personal details, ensuring sensitive login information remains only on a personal computer and is not uploaded to any shared online platform.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Left 1Centre 4Right 1Haredi 2Other 5
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
