This day 02:03 06:03 10:03 14:04 18:04 22:04
Info  2026-08-24 14:04Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-08-24 — Exposed secrets, expired domains

Two distinct credential-exposure vectors dominate today: 28,000 servers with abandoned .git folders are leaking live AWS and Stripe keys, and a South Korean government-backed startup platform bundled its encryption key directly into an API. Separately, Infoblox reports a $7 million buying spree of expired domains—attackers are weaponising their inherited reputation, backlinks, and residual traffic for phishing and malware delivery. Microsoft also confirmed that August Patch Tuesday updates break printing and PDF export in WPF apps.

Top items

Themes

Secrets keep leaking through admin negligence. Today's .git folder exposure (28K servers) and the South Korean API key incident both stem from the same root cause: credentials left where attackers can find them. This echoes the leaked AWS keys story from August 21. The fix is the same—separate keys from data, scan web roots, and rotate.

Expired infrastructure as an attack surface. The $7M expired-domain campaign and the "Zombie Card" relay attack (first reported August 20) both exploit abandoned but still-functional systems. Attackers are systematically harvesting residual trust from expired domains and expired payment cards—both require no zero-day, just opportunism.

Microsoft's patch month brings operational pain alongside security fixes. Between broken WPF printing/PDF export and the ongoing Windows gaming/RGB crashes (first reported August 21), August's updates are generating enough collateral damage to warrant staged rollout policies.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db