BackAPI Key

API Key

Alibaba Cloud
2026-08-25 09:22:37

Alibaba Cloud Token Plan Connects to Qwen, Extending Shared Usage Credits to Work Assistant

Alibaba Cloud’s Token Plan has officially been connected to the Qwen app and PC client, allowing users to use the same subscription quota inside Qwen’s Work Assistant after binding a dedicated API key. Once connected, users can spend their existing plan credits on more complex tasks, including operating a computer and browser, calling Skills, and creating Office documents, apps, and websites. The update extends a single pool of model usage from developer-focused tools into Qwen itself, rather than limiting it to coding and agent environments. Token Plan already supported tools such as Codex, Claude Code, Cursor, Qoder, and OpenClaw, and those credits can now also be shared with Qwen Work Assistant. Supported models include Qwen3.8-Max, with different models and tools drawing down usage under a unified Credits-based deduction system.

140
Alibaba Cloud Token Plan Connects to Qwen, Extending Shared Usage Credits to Work Assistant
Stripe
2026-08-24 09:41:50

Security Affairs Reports Massive Leak of Stripe Merchant API Keys

ChainCatcher, citing Security Affairs, reported that Ransomnews researchers documented a large-scale leak of Stripe merchant API keys. The exposed keys were found in public code repositories, GitHub Actions logs, and misconfigured web servers. Researchers identified more than 50,000 unique keys, and sample testing found that a substantial portion was still active. The report said attackers could use the keys to commit fraud within hours. According to the report, a data set posted on a data-trading forum on Aug. 18, 2026 contained valid Stripe API keys for 659 merchant accounts, along with about 35 GB of customer and payment data. Ransomnews analyzed the data offline and reported it to Stripe before publication. The report said Stripe itself was not breached and that the leaked keys belonged to merchants, not Stripe. Researchers said that once a valid key was found, it took as little as 17 hours to access customer lists, create fraudulent payment links, and run a $1 test charge. The report also said valid keys could be used to list customers and stored payment methods, create charges and payment intents, issue refunds to attacker-controlled accounts, change webhook endpoints to intercept payment notifications, and access connected accounts when Stripe Connect was enabled.

320
Security Affairs Reports Massive Leak of Stripe Merchant API Keys