A security researcher has identified that an airport group allegedly exposed API keys embedded in client-side JavaScript code for approximately four years, according to a report in The Register. The exposure potentially compromised sensitive authentication credentials that could allow unauthorized access to backend systems and services. The incident highlights ongoing security vulnerabilities related to improper credential management in web applications.